# How do I use raw HTML (and get it to preview)?

**URL:** https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838
**Category:** General
**Created:** [February 22, 2025, 12:01pm UTC](https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838 "2025-02-22T12:01:23Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![bagley2014](https://community.silverbullet.md/user_avatar/community.silverbullet.md/bagley2014/32/1047_2.png) [@bagley2014](https://community.silverbullet.md/u/bagley2014)
#### Post date: [February 22, 2025, 12:01pm UTC](https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838/1 "2025-02-22T12:01:23Z")

</div>

I just got silverbullet running and I’ve been stuck on something pretty simple for a while.

I want to make an ordered list that starts at zero, instead of one. To [my knowledge](https://stackoverflow.com/a/15078486/5478150) the only way to do this would be to write it in HTML.

However, silverbullet doesn’t seem to want to render HTML. Is there some way of doing this? Maybe a renderer I’m unaware of? I’ve scoured the docs but haven’t really seen any examples. The only thing I’ve seen that might work would be a `space-script` but that seems like overkill.

---

<div class="post-metadata">

### Author: ![zef](https://community.silverbullet.md/user_avatar/community.silverbullet.md/zef/32/7_2.png) [@zef](https://community.silverbullet.md/u/zef)
#### Post date: [February 22, 2025, 2:09pm UTC](https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838/2 "2025-02-22T14:09:13Z")

</div>

This is not currently possible without either using Space Lua or Space Script. Neither are a great solution. There’s this issue: [Support Live Preview for HTML tags · Issue #702 · silverbulletmd/silverbullet · GitHub](https://github.com/silverbulletmd/silverbullet/issues/702) that would enable embedding plain HTML and rendering it as you ask.

One reason I’ve been holding back on implementing this is the bigger question of a reasonable approach to security.

Markdown is relatively safe. You don’t have to worry that opening a markdown file can do damage and run random scripts. When we allow embedding plain HTML there are more ways to do that. This means that if you’d open pages from untrusted sources, you could be in trouble.

Is that ok?

You could argue: well I’m self hosting SilverBullet, the content is coming from me, and I can be trusted so YOLO. Is that reasonable?

To some degree yes. But we also have [Libraries](https://silverbullet.md/Libraries) and I’d like to do more with them. The pattern may become that people fetch SilverBullet libraries from various sources without scrutinizing them too much. Those libraries may contain random scripts, or random HTML code that is malicious. Is that ok?

The easy solution is to simply say yes: this is your responsibility. Power over pure safety.

I’d be interested in other people’s ideas on this topic.

---

<div class="post-metadata">

### Author: ![bagley2014](https://community.silverbullet.md/user_avatar/community.silverbullet.md/bagley2014/32/1047_2.png) [@bagley2014](https://community.silverbullet.md/u/bagley2014)
#### Post date: [February 22, 2025, 8:06pm UTC](https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838/3 "2025-02-22T20:06:41Z")

</div>

> [@zef](#):
>
> You could argue: well I’m self hosting SilverBullet, the content is coming from me, and I can be trusted so YOLO.

Yeah, I thought on it for a bit, and this is pretty much my stance, at least for my current use case. I’m expecting to vet any third party content before running it.

I wouldn’t mind if the functionality was gated behind enabling something in the config. Maybe a whitelist of HTML elements? Maybe an `ENABLE_UNSAFE_FEATURES` flag? If the Library author tells you you need to enable that flag, at least that’s a clear indicator that you should look at their code first.

---

<div class="post-metadata">

### Author: ![zef](https://community.silverbullet.md/user_avatar/community.silverbullet.md/zef/32/7_2.png) [@zef](https://community.silverbullet.md/u/zef)
#### Post date: [February 23, 2025, 6:19am UTC](https://community.silverbullet.md/t/how-do-i-use-raw-html-and-get-it-to-preview/1838/4 "2025-02-23T06:19:23Z")

</div>

On this topic: [On Security](https://community.silverbullet.md/t/on-security/1840)
