import dompurify = require('dompurify'); dompurify.sanitize(''); dompurify.addHook('beforeSanitizeElements', (el, data, config) => undefined); //examples from the DOMPurify README let dirty = '

Totally safe

Totally not safe

'; let str: string; let elem: HTMLElement; let frag: DocumentFragment; // allow only str = dompurify.sanitize(dirty, { ALLOWED_TAGS: ['b'] }); // allow only and with style attributes (for whatever reason) str = dompurify.sanitize(dirty, { ALLOWED_TAGS: ['b', 'q'], ALLOWED_ATTR: ['style'] }); // leave all as it is but forbid