Markdown Editor with Live Preview and GFM

Our company is engaged in the development, support and maintenance of sites of any complexity. From simple one-page sites to large-scale cluster systems built on micro services. Experience of developers is confirmed by certificates from vendors.

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Showing 1 of 1All 2062 services
Markdown Editor with Live Preview and GFM
Medium
~3-5 days
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1362
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1253
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    958
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1190
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    932
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    949

XSS errors when rendering Markdown are among the most common vulnerabilities on sites with user-generated content. For example, an attacker enters [clickme](javascript:alert(1)), and if the parser does not sanitize, JavaScript executes in another user's browser. Over 5 years, we have delivered over 20 Markdown editor projects with live preview and GFM, and we know how to avoid typical mistakes. At the start, we audit requirements and select the optimal solution, which saves up to 30% of debugging time and, in monetary terms, up to 40% of the budget.

Problems We Solve

  • XSS via Markdown: Standard marked.js does not escape by default; DOMPurify is needed. Server-side sanitization (CommonMark with html_input=strip) eliminates 99% of risks. Without it, you risk data loss and reputation damage.
  • Hydration mismatch with SSR: React re-renders the preview on the client if the HTML does not match the server — we fix it using suppressHydrationWarning or disable SSR for the editor. This reduces deployment time by 2-3 days.
  • Live-preview performance: Each character input triggers HTML parsing — we buffer with a 100ms debounce and use virtualization. This reduces CPU load by 60% and improves INP by 40%.

How We Do It

We select the library based on the task. We use @uiw/react-md-editor for typical projects, and a custom editor on CodeMirror for high-load systems. CodeMirror 6 with marked.js is 40% lighter in bundle size (gzip ~30KB vs ~40KB for @uiw/react-md-editor) but requires twice as much integration code. Comparison table:

Library Live Preview GFM Image Upload SSR Weight (gzip)
@uiw/react-md-editor Yes Yes No (custom) Yes ~40KB
CodeMirror 6 + marked.js Yes Yes No (custom) No ~30KB + marked
TipTap Yes Via plugins Via plugins Caution ~150KB

Second table — sanitization method comparison:

Method XSS Protection Performance Complexity
Client-side DOMPurify 99% ~2ms per 10KB Low
Server-side CommonMark (strip) 99.9% ~1ms per 10KB Medium
Combined 99.99% ~3ms per 10KB Medium

Quick Start with @uiw/react-md-editor

import MDEditor from '@uiw/react-md-editor';
import { useState } from 'react';

function MarkdownEditor({ initialValue = '', onChange }: EditorProps) {
  const [value, setValue] = useState(initialValue);

  const handleChange = (val?: string) => {
    const markdown = val ?? '';
    setValue(markdown);
    onChange?.(markdown);
  };

  return (
    <MDEditor
      value={value}
      onChange={handleChange}
      height={400}
      preview="live"
      hideToolbar={false}
      commands={[
        MDEditor.commands.bold,
        MDEditor.commands.italic,
        MDEditor.commands.title,
        MDEditor.commands.divider,
        MDEditor.commands.link,
        MDEditor.commands.image,
        MDEditor.commands.code,
        MDEditor.commands.codeBlock,
        MDEditor.commands.divider,
        MDEditor.commands.fullscreen,
      ]}
    />
  );
}

Custom Implementation on CodeMirror 6 + marked.js

import { EditorView, basicSetup } from 'codemirror';
import { markdown } from '@codemirror/lang-markdown';
import { oneDark } from '@codemirror/theme-one-dark';
import { marked } from 'marked';
import DOMPurify from 'dompurify';

function createMarkdownEditor(container: HTMLElement, previewContainer: HTMLElement) {
  const view = new EditorView({
    doc: '',
    extensions: [
      basicSetup,
      markdown(),
      oneDark,
      EditorView.updateListener.of(update => {
        if (update.docChanged) {
          const markdown = update.state.doc.toString();
          const html = marked(markdown, { breaks: true, gfm: true });
          previewContainer.innerHTML = DOMPurify.sanitize(html as string);
        }
      }),
    ],
    parent: container,
  });

  return view;
}

Image Upload from Editor

import * as commands from '@uiw/react-md-editor/commands';

const imageUploadCommand: commands.ICommand = {
  name: 'upload-image',
  keyCommand: 'upload-image',
  buttonProps: { 'aria-label': 'Upload image' },
  icon: <ImageIcon />,
  execute: async (state, api) => {
    const file = await openFilePicker(['image/jpeg', 'image/png', 'image/webp']);
    if (!file) return;

    const formData = new FormData();
    formData.append('file', file);

    const { data } = await api.post('/api/media/upload', formData);

    const imageMarkdown = `![${file.name}](${data.url})`;
    api.replaceSelection(imageMarkdown);
  },
};

async function openFilePicker(accept: string[]): Promise<File | null> {
  return new Promise(resolve => {
    const input = document.createElement('input');
    input.type = 'file';
    input.accept = accept.join(',');
    input.onchange = () => resolve(input.files?.[0] ?? null);
    input.click();
  });
}

Why Store Markdown Separately from HTML?

Storing the original Markdown provides flexibility: editable, convertible to different formats (PDF, DOCX), and searchable. HTML is cached for faster delivery. This is standard practice per the CommonMark specification. Additionally, this approach eases content migration between systems.

How to Ensure Secure Rendering?

Sanitize on the server (CommonMark with html_input=strip, max_nesting) and on the client (DOMPurify). Never rely on only one side. The combined approach gives 99.99% protection. A server parser configuration may look like:

$safeHtml = $parser->safeParse($markdown)->getContent();

Process Overview

  1. Analysis: Determine requirements (GFM, media upload, themes, SSR).
  2. Design: Library selection, component architecture.
  3. Implementation: Integration, custom commands (upload, emojis).
  4. Testing: Unit tests for sanitization, e2e tests for UX.
  5. Deployment: Cache configuration, error monitoring.

What's Included in the Work

  • Library selection and integration.
  • Live preview implementation with GFM support.
  • Image upload setup (drag&drop, insertion).
  • Server-side and client-side sanitization.
  • SSR compatibility (if needed).
  • Usage and customization documentation.
  • 30-day support after deployment.

Timelines and Pricing

Implementation time: 2 to 7 days depending on complexity. Pricing is calculated individually after project analysis. Get a consultation — we will evaluate your case. Contact us — we'll help with selection and implementation.

Checklist for the Completed Editor
  • [ ] GFM support (tables, lists, links)
  • [ ] Image upload (drag & drop or insertion)
  • [ ] Live preview with 100ms debounce
  • [ ] Server-side sanitization (html_input=strip, max_nesting)
  • [ ] Client-side sanitization (DOMPurify)
  • [ ] Store Markdown in DB, cache HTML
  • [ ] SSR compatibility (suppressHydrationWarning)
  • [ ] Fullscreen mode
  • [ ] Syntax highlighting for code blocks
  • [ ] Export to HTML/Markdown

Common Implementation Mistakes

  • Missing server-side sanitization (XSS risk).
  • Ignoring debounce for preview — input lag.
  • Storing only HTML (loss of editability).
  • Incorrect hydration handling in Next.js with SSR.

Contact us for a consultation — we will help you choose the optimal solution for your project. With us, you get a reliable Markdown editor that meets modern security and performance standards.

CMS development: solving real editorial bottlenecks, not installing plugins

A news publisher had a WordPress site with 5 editors. Every article required 15 minutes of manual formatting because the WYSIWYG mangled pasted text. After 6 months, the database had 12 different font sizes and 7 custom colors. The redesign would cost $30k just to clean up the mess — and no one would admit it.

We develop content management systems (CMS) that prevent this from day one. Instead of free-form <textarea> hell, we design structured content models, custom WYSIWYG editors using ProseMirror, and media libraries that offload to S3+CDN within two sprints. This is CMS development without shortcuts.

When is headless CMS justified and when not?

Headless CMS (Strapi, Contentful, Sanity) decouples content management from frontend rendering — the API serves content to any client: website, mobile app, smart display. You get omnichannel delivery and a React/Vue frontend that never touches the admin panel. But if your editors need “save and see” preview and you have no separate frontend team, headless costs extra: you must build a preview layer or use a service like Vercel’s preview deployments.

Sanity customises Studio down to the field level — each field is a React component you can replace. Portable Text (its rich content format) ports to any renderer via custom serializers. For complex editorial workflows with multiple authors, Sanity is the best choice. Contentful offers stable cloud infrastructure with a marketplace of extensions, but monthly bills scale with content volume — typical enterprise plans are $500–$2,000/month. Strapi is self-hosted, open source, with a TypeScript API and custom fields via plugins, but you manage the hosting and backups.

Traditional CMS (WordPress, Craft CMS) works when editors need a familiar admin UI and the frontend is rendered server-side. Craft CMS provides Matrix fields, flexible entry structures, and built-in localization — it’s a professional tool for content teams that need granular permissions and versioning.

How do we build a WYSIWYG editor that doesn’t break layout?

The editor is the most complex component — not a <textarea>. The sweet spot is Tiptap, built on ProseMirror. Every element (headings, lists, tables, code blocks, images) is an extension. Collaborative editing via Yjs works out of the box. Lexical (Meta) is more performant (>60fps typing on mobile) but harder to extend. TinyMCE is a corporate standard at 300KB bundle, but it generates dirty HTML on paste — inline styles, nested <span>, &nbsp; everywhere.

The root cause: pasting from Word. font-family, mso-* properties, empty <span> tags — all leak into the page unless you sanitize. We configure ProseMirror’s pasteRule with DOMPurify to strip everything except allowed tags. Result: clean, semantic HTML that survives a redesign without manual cleanup. Editors save 2–4 hours per week per person.

Media library: from upload to CDN with transformation

Saving files to the server disk is the classic mistake. The disk fills, scaling fails, and CDN becomes impossible. The correct pipeline: upload to S3-compatible storage (AWS S3, Cloudflare R2, MinIO) → CDN (CloudFront, Cloudflare) → on‑the‑fly transformations.

Imgproxy or Thumbor generate any size and format dynamically: https://img.example.com/resize:800:600/format:webp/plain/s3://bucket/photo.jpg. The original lives once, derivatives never occupy disk. Cloudflare Images costs $5 per 100k images, including transformations. Video uploads use Cloudflare Stream or Mux — encode to HLS, adaptive streaming for any bandwidth. Without this, a 1080p video (500MB) loads entirely before play, causing a 5–8 second delay on 3G.

What’s included in media library development

Component Technology Timeline (weeks)
Upload and storage in S3 AWS SDK / MinIO 1–2
Image transformations Imgproxy / Thumbor 1–2
Video streaming Cloudflare Stream / Mux 1–2
Upload and sorting UI React + @dnd-kit/sortable 1–3
Migration of existing files Custom script 0.5–1

Why structured content outperforms free-form HTML

Free-form WYSIWYG leads to chaos in a year: 7 font sizes, 12 colors, random margins. Redesign requires manual cleanup of thousands of posts. Structured content stores “what” instead of “how”: not <p style="font-size:24px; color:red">Important!</p>, but a callout block with variant: warning. The CMS stores the structure; the frontend decides rendering. Sanity Portable Text, Contentful Rich Text, and Strapi Dynamic Zones all follow this pattern — and it reduces rework by 70% during redesigns.

Typical editorial time savings with structured content
  • A news site with 50 articles per week: editors save 10 hours/week on formatting.
  • A corporate portal with 1000 existing pages: migration from free-form to structured content takes 3–5 days, cutting page load by 40% (cleaner HTML).

Work process

  1. Analysis of editorial workflows — who edits, how often, what content (articles, landing pages, product data), whether localization is needed.
  2. CMS selection — based on scenarios, not trends. We compare headless vs traditional with a weighted matrix.
  3. Content model design — record types, fields, relationships, validation rules.
  4. Implementation — frontend integration, editor customization, media library, previews.
  5. Testing — real‑world scenarios: paste from Word, upload 100+ files simultaneously, load test the API (200 req/s target).
  6. Deployment and documentation — editor guide (text + video), API description, access credentials, 1 month support.

Timelines and budget

Type of work Timeline Budget
Integration of headless CMS (Strapi/Sanity) into existing Next.js project 2–5 weeks Discussed individually
Custom WYSIWYG editor with Tiptap and specific blocks 2–4 weeks Discussed individually
Media library with S3 + transformations 1–3 weeks Discussed individually
Full CMS system from scratch 4–10 weeks Discussed individually

Budget is calculated individually after an audit. Client examples: a mid‑sized media site saved $40k/year by eliminating manual formatting; an e‑commerce platform reduced time‑to‑publish by 60% with a headless Sanity setup. Contact us for a free project estimate.

What you get after delivery

  • Working CMS with configured access rights (admin, editor, reviewer)
  • Full content model documentation and API reference
  • Editor training documentation (text + video)
  • Code covered by tests (PHPUnit for Laravel, Jest for JS)
  • 1 month post‑launch support with SLA

Our experience and guarantees

Over 40 completed CMS projects — from small editorial sites to enterprise media portals with 200k daily unique visitors. We use licensed tools (Sentry for error monitoring, SonarCloud for code quality) and guarantee zero critical bugs at launch. All code is version‑controlled and deployable via CI/CD.

For your specific needs, contact us to discuss requirements. We’ll provide a technical proposal within 2 business days.