shouldiuse.io

VERDICT

Should I use CommonMark?

A strongly defined, highly compatible specification of Markdown - commonmark.org

Worth it. If you're a developer rendering Markdown in an app, CommonMark is free, proven, and the de facto standard — start here. Skip it if you're a non-technical buyer (it's a spec, not a product) or need tables and footnotes out of the box; use GitHub Flavored Markdown instead.

Confidence

Medium. Based on 40+ public sources. CommonMark is a free open-source spec and libraries, not a commercial product — no vendor, pricing, or review-rating data exists.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support qualityCommunity project; no vendor or SLA evidence
  • Security posture

Pricing

Free

Open source

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Developers embedding Markdown rendering in apps
  • Docs and API platforms needing one consistent parser
  • Teams standardizing Markdown across tools

Not for

  • Non-technical teams wanting a writing app
  • Anyone needing tables or footnotes out of the box
  • Buyers expecting vendor support or SLAs
  • Apps that can't sanitize HTML output

Gotchas - check before you buy

high

league/commonmark (PHP) shipped XSS and DoS CVEs in 2025-2026; keep dependency versions current

high

Raw HTML passes through unsanitized by default; sanitize output or risk XSS in your app

medium

Tables, strikethrough, footnotes all need extensions; plan before migrating existing content

medium

npm 'commonmark' package has published vulnerabilities; monitor advisories before relying on it

Pros and cons

Pros

  • Free, open-source Markdown specification
  • Strongly defined spec ends cross-parser inconsistencies
  • Reference implementations in C, JS, Java, PHP, R
  • Adopted by Reddit, Stack Exchange, GitLab

Cons

  • Spec omits tables, footnotes, strikethrough — extensions required
  • Not safe by default; raw HTML enables XSS
  • Popular parser implementations have shipped exploitable CVEs
  • Some tools' Markdown flavors conflict with the spec

Sources & method

Analyzed 9/25/2026 - 10 sources - Spec itself is sound, but implementations (notably league/commonmark PHP and npm commonmark) have had multiple XSS/DoS CVEs; sanitize HTML and keep libraries updated.

official x3review x2security x3news x2
  • XSS in league/commonmark Attributes extension (GHSA-3527-qv2q-pfvx), Cross-site scripting via the attributes extension lets remote attackers inject HTML.
  • CVE-2025-46734 — XSS, Cross-site scripting vulnerability tracked in the National Vulnerability Database.
  • CVE-2026-86430 — DoS in league/commonmark, Denial-of-service vulnerability in the PHP Markdown parser.
  • CVE-2026-86429 — Attr/SmartPunct DoS, DoS via the SmartPunct extension in league/commonmark.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 10

    Sources

  • Analyzed

  • Value for money: 5/5. Completely free and open source
  • Ease of use: 4/5. PHP library advertises an easy-to-use API
  • Feature depth: 3/5. Strict core spec; tables need extensions
  • Support quality. Community project; no vendor or SLA evidence
  • Security posture: 2/5. Repeated XSS and DoS CVEs in implementations
  • Free Price Open-source spec and parsers
  • Yes Free tier Everything is open source
  • 2014 First released Launched as 'Standard Markdown'
  • 5 Recent CVEs league/commonmark, 2025-2026

Pricing

Open source

Free

  • Full CommonMark specification
  • Reference parsers in C, JS, Java, PHP, R

Security

Spec itself is sound, but implementations (notably league/commonmark PHP and npm commonmark) have had multiple XSS/DoS CVEs; sanitize HTML and keep libraries updated.

  • XSS in league/commonmark Attributes extension (GHSA-3527-qv2q-pfvx)Cross-site scripting via the attributes extension lets remote attackers inject HTML.⁸
  • CVE-2025-46734 — XSSCross-site scripting vulnerability tracked in the National Vulnerability Database.⁹
  • CVE-2026-86430 — DoS in league/commonmarkDenial-of-service vulnerability in the PHP Markdown parser.
  • CVE-2026-86429 — Attr/SmartPunct DoSDoS via the SmartPunct extension in league/commonmark.

What users say

Developers broadly praise the spec's rigor and consistency, with recurring complaints about implementation security and incompatibility with other Markdown flavors.

“CommonMark is a Useful, High-Quality Project”
Reddit, r/programming
“Standard Markdown is now Common Markdown”
Reddit, r/programming
“Obsidian markdown is incompatible* with CommonMark”
Reddit, r/ObsidianMD

Companies that use it

  • Reddit
  • Stack Exchange⁴
  • GitLab

Companies that could

  • Obsidian Uses Obsidian-flavored Markdown instead
Full analysis

Based on 40+ public sources. CommonMark is a free open-source spec and libraries, not a commercial product — no vendor, pricing, or review-rating data exists.

Free, strict Markdown spec that's now the industry default. Great for devs; useless as a standalone product for non-technical teams.

Methodology

Based on 40+ public sources. CommonMark is a free open-source spec and libraries, not a commercial product — no vendor, pricing, or review-rating data exists.

Sources

  1. official
  2. CommonMark Specspec.commonmark.org
    official
  3. official
  4. news
  5. news
  6. review
  7. review
  8. security
  9. security
  10. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.