Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can use PHP Markdown without Composer’s autoloader, but that does not make it code-free: the PHP Markdown library is still an added parser. If “no dependencies” means no Composer installation or autoloader, its documented direct-include route may fit. If you mean no third-party code or no separately installed runtime component, PHP Markdown, League CommonMark, and PHP’s CommonMark extension do not all meet that stricter requirement.

What “no dependencies” means for a PHP Markdown parser

Markdown is a plain-text markup syntax; a Markdown parser is software that converts that syntax into HTML. “PHP Markdown” can also refer to a specific PHP port of the original Markdown program, which includes the Markdown and MarkdownExtra parser classes.

Before choosing an implementation, identify which constraint matters:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • No Composer: You want to install or include the parser without Composer.
  • No autoloader: You want to load the needed PHP files directly rather than rely on class autoloading.
  • No added PHP package: You want to use only code already available in your application or runtime.
  • No extra PHP extension: You can use PHP libraries but cannot install a runtime extension.

These are different requirements. A library can avoid Composer’s autoloader while still being third-party code; an extension is a separately installed runtime component.

Use PHP Markdown without an autoloader

The PHP Markdown project documents both Composer installation and direct inclusion of its .inc.php files for environments where class autoloading is unavailable. The current library package requires PHP 7.4 or later. Follow the project’s README for the appropriate entry point and include it in your application; the direct-include option is not the same as writing a parser using only PHP’s built-in features. PHP Markdown project README.

PHP Markdown provides the Markdown and MarkdownExtra classes. Choose between them based on the syntax your content needs, and verify that choice against the project’s documentation. Do not confuse this library with the older plugin/library hybrid: the project says that older hybrid is no longer maintained.

How the PHP options differ

Option What it supports Requirements and installation Does it avoid added dependencies?
PHP Markdown Markdown and Markdown Extra PHP 7.4 or later; Composer or direct inclusion of .inc.php files Can avoid Composer and an autoloader, but remains an added PHP library
league/commonmark CommonMark and GitHub-Flavored Markdown; the GFM converter adds tables, task lists, strikethrough, autolinks, and disallowed raw HTML PHP 7.4 or later and mbstring; Composer is the documented installation route No; it is a Composer package and requires mbstring
PHP CommonMark extension Parsing and rendering through an extension API Installed separately through PECL No; it adds a runtime extension
Handwritten parser Only the syntax you implement and test No installation requirement for a third-party parser, but you must write and maintain the parser Potentially, but a small custom parser should not be assumed to handle full Markdown or specification edge cases

The League project documents its requirements, installation, dialect support, and professional support options in its README. PHP’s manual describes the CommonMark extension’s parsing and rendering API and directs users to PECL for installation: CommonMark extension documentation and installation instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Handle untrusted Markdown as a security boundary

Parsing Markdown is not the same as sanitizing HTML. League CommonMark allows raw HTML and unsafe link protocols by default for specification compliance. If users can submit Markdown, configure the parser deliberately rather than treating its output as safe to publish.

  • Set html_input to escape or strip to control raw HTML.
  • Set allow_unsafe_links to false to block unsafe link protocols.
  • Set max_nesting_level to 100 for untrusted input, as the security guide recommends.
  • Consider limiting max_delimiters_per_line. This limit does not cover link and image brackets, so impose suitable input and line-length limits too.

See the project’s security guidance for configuration details. Additional filtering may be appropriate in some applications, but filters also need careful configuration and testing.

Choose according to the constraint you actually have

  • Choose PHP Markdown if you need its Markdown or Markdown Extra behavior and need to include files without an autoloader.
  • Choose League CommonMark if you need CommonMark or GFM support and can use Composer and install or enable mbstring.
  • Choose the PHP CommonMark extension only if a separately installed PECL extension is acceptable.
  • Write a limited parser only when you can clearly define the supported syntax and test it against that scope; do not present it as a complete Markdown implementation by default.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.