Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build a link previewer as a server-side fetch-and-parse pipeline: validate the submitted URL, fetch the page under strict network and resource limits, extract Open Graph metadata with HTML fallbacks, then render a card that clearly shows the destination. Add oEmbed only when you need provider-rendered content such as a player. Because your server fetches user-controlled destinations, SSRF defenses are part of the feature—not an optional hardening step.

What a link previewer should return

A previewer, also called a link unfurler, turns a submitted URL into a compact card. Define its output before writing the fetcher. Keep the original request separate from metadata found on the page: a remote page can suggest a canonical URL, but that does not change what the user submitted.

Field Purpose
requested_url The exact URL submitted by the user, retained for destination display and auditing.
final_url The final validated URL reached after any permitted redirects.
display_domain A human-readable destination host, derived from the submitted URL rather than untrusted page text.
title, description Card text extracted from page metadata, with safe fallbacks.
image_url, image_alt Optional preview image and its descriptive alternative text.
site_name, content_type Optional page-provided site label and fetched response type.
fetch_status A controlled status such as success, rejected, timeout, unsupported content, or extraction_failed.

Keep extracted strings as data, not prebuilt HTML. Escape text and validate URLs for the specific output context when rendering the card.

How the fetch-and-parse pipeline works

  1. Accept and normalize input. Parse the submitted value with a URL parser. Accept only schemes your feature intends to support, normally HTTP and HTTPS. Reject malformed values, embedded credentials, and disallowed ports.
  2. Validate the destination. Resolve DNS and examine every IPv4 and IPv6 address the connection could use. For a public-web preview feature, block loopback, private, link-local, multicast, and cloud metadata destinations at connection time. Revalidate each redirect destination and resolved address; do not rely on a string regex or a denylist alone.
  3. Fetch with limits. Set connection and total timeouts, a response-size ceiling, redirect limits or disable redirects, and accepted content types. Limit concurrent work and request rates. Isolate the fetcher from internal services with network segmentation or egress policy. OWASP’s SSRF Prevention Cheat Sheet explains the risks of server-side requests to attacker-influenced destinations.
  4. Extract page metadata. Prefer Open Graph fields, then fall back to standard HTML title and description metadata. Resolve a relative image against a carefully selected base URL and validate its destination before using it.
  5. Optionally request oEmbed. Discover a provider endpoint only when richer provider content is useful. Validate the endpoint and response, and never treat returned HTML as trusted application markup.
  6. Cache and render. Cache normalized results for a bounded lifetime, with a refresh or invalidation path. Render a useful fallback if fetching fails or metadata is missing. Keep the actual destination host visible.

There is no universal correct timeout, body-size cap, cache lifetime, or rate limit. Set them from your latency budget, traffic, provider behavior, and threat model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which metadata to extract

Open Graph first

Open Graph is a practical basis for a static preview card. Read og:title, og:description, og:image, og:url, and og:site_name when present. The protocol also defines image properties including og:image:secure_url, og:image:type, og:image:width, og:image:height, and og:image:alt. Treat image alt as a description of the image, not a caption. See the Open Graph protocol.

If a page omits Open Graph values, use the HTML <title> and description metadata as fallbacks. Keep fallback order deterministic, trim excessive whitespace, and impose sensible output-length limits so one page cannot produce an unusable card.

Resolve URLs deliberately

Relative image paths need a base URL. A defensible default is the final validated page URL after redirects, provided redirect validation succeeded. Validate the resulting image URL separately: fetching or rendering an image can create another request to an attacker-controlled host. If your product does not need to fetch images itself, render only a validated HTTP(S) image URL and consider a proxy with its own destination controls.

Store og:url as page metadata if useful, but do not replace the submitted destination with it. A page can claim a different canonical URL; the preview should not conceal where the user is actually going.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
HTML and CSS: Design and Build Websites
  • HTML CSS Design and Build Web Sites
  • Comes with secure packaging
  • It can be a gift option

When to add oEmbed

Open Graph describes a page; oEmbed lets a provider return a richer representation, such as a video player. The oEmbed resource describes photo, video, rich, and link response types. Use ordinary metadata extraction for static cards, and add oEmbed for providers where interactive or provider-rendered content materially improves the result.

Discovery can be provided through HTML <link> elements or HTTP Link headers. Validate the discovered endpoint, response content type, dimensions, and URLs. Escape ordinary returned values. The oEmbed specification warns about consumer-page access risks and recommends displaying provider HTML in an iframe hosted on another domain. Do not inject provider HTML directly into your application document. See the oEmbed specification and its security considerations.

SSRF defenses are a design requirement

A link preview endpoint makes network requests on behalf of a user. That makes it a potential Server-Side Request Forgery (SSRF) primitive: an attacker may try to make it reach internal services, local interfaces, or cloud metadata endpoints instead of a public web page.

  • Allow only intended schemes, usually HTTP and HTTPS; reject credentials and malformed or ambiguous URLs.
  • Apply a deliberate port policy. Do not assume that a public-looking hostname makes every port safe.
  • Resolve and inspect IPv4 and IPv6 destinations, then enforce the decision at connection time to reduce DNS rebinding or pinning bypasses.
  • Re-check every redirect, or disable redirects. A safe initial URL can redirect to a prohibited address.
  • Block loopback, private, link-local, multicast, and cloud metadata addresses for a public-web feature.
  • Use network-layer egress restrictions and isolate the fetcher from internal application infrastructure.
  • Apply bounded response size, timeouts, concurrency, and rate controls to limit resource exhaustion.

A fixed hostname allowlist may be unsuitable when users can preview arbitrary public websites. In that case, use layered destination controls and network isolation; do not treat a denylist as complete protection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Render safely and avoid misleading cards

All remote metadata is untrusted. Escape titles, descriptions, and labels as text for their output context. Validate URLs before placing them in links or image sources, and restrict their schemes. Keep the submitted host or another clear representation of the actual destination visible next to the preview. A preview is a navigation aid, not a safety verdict: metadata can be chosen to mislead. A 2020 NDSS study documented deceptive link-preview risks in particular platform contexts; it should not be read as a measurement of every current service. See the study.

Implementation checklist

  • Separate the original URL, fetched URL, and metadata-provided canonical URL.
  • Use a URL parser and destination-aware SSRF checks, not a regex-only validator.
  • Enforce safe connection-time IP checks and repeat them for redirects.
  • Limit time, response bytes, redirects, concurrency, and accepted content types.
  • Prefer Open Graph, then fall back to title and description metadata.
  • Validate normalized image URLs independently.
  • Keep oEmbed optional, and sandbox provider HTML on a separate origin.
  • Provide a fallback card that still exposes the destination when extraction fails.
  • Cache results with bounded lifetime and a refresh path.
  • Log status classes and rejection reasons without retaining unnecessary page bodies or secrets; monitor latency, cache hit rate, and extraction failures.

Operational trade-offs: build or use a hosted extractor

Building your own fetcher gives you control over security policy, data handling, fallback rules, cache behavior, and supported providers, but leaves you responsible for the ongoing extraction and security maintenance. A hosted unfurl API can outsource extraction behavior; compare provider coverage, privacy and retention, latency and reliability, cache controls, security boundaries, and ongoing cost. Verify the service’s current behavior and terms directly. OpenGraph.io describes metadata and oEmbed APIs at its site and API page; those pages do not establish affiliate availability or a fit for every application’s requirements.

Or skip the browser setup

For a clean screenshot or PDF of a page as an additional preview asset, ScreenshotNeo provides a website screenshot API and MCP server. It is not a replacement for extracting Open Graph fields or validating URLs in your own unfurl pipeline. Its API accepts a URL in one GET request; see the ScreenshotNeo documentation.

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Web Design with HTML, CSS, JavaScript and jQuery Set
  • Brand: Wiley
  • Set of 2 Volumes
  • A handy two-book set that uniquely combines related technologies Highly visual format and accessible language makes these books highly effective learning tools Perfect for beginning web designers and front-end developers

ScreenshotNeo accepts cookie and consent banners and removes 60+ known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, with response headers indicating the page verdict and billing status. Its MCP server offers take_screenshot, get_page_info, and capture_pdf tools for AI agents and MCP clients. Free includes 1,000 shots per month with no card; paid plans start at $5 for 3,000 shots. Sign up for 1,000 free screenshots a month with no card.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting common failures

The URL is rejected although it looks public

Check the parsed scheme, credentials, port, DNS results, and every redirect target. A hostname can resolve to a prohibited address, and a redirect can change destinations. Return a clear rejection status instead of weakening checks to make the request pass.

The page loads but the card has no title or image

The site may omit metadata, return a JavaScript-only page, block automated requests, or serve different content by user agent. Use title and description fallbacks where available, return a no-metadata status when not, and avoid adding a full browser renderer unless its maintenance and security costs are justified.

The image URL is relative or fails in the card

Resolve it against the validated final page URL, then check scheme and destination. The remote image may be missing, blocked, or dependent on cookies; make the image optional and keep the text card useful without it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The fetch stalls or consumes too many resources

Enforce both connection and total timeouts, cap response bytes, limit redirects, and bound concurrent fetches. Return a timeout or size-limit status and consider a cached result where policy permits.

An embed breaks or creates a security concern

Verify the oEmbed discovery link or header and provider response type. Do not inject returned HTML into your own page; place it in a sandboxed iframe served from a separate origin and filter URL schemes as the specification advises.

Users are confused about where a card leads

Show the host derived from the submitted URL, not only a page title or remote site label. Avoid presenting a successful metadata fetch as evidence that the destination is safe.

Frequently asked questions

Should the preview fetch run in the user’s browser?

A server-side fetch centralizes caching and extraction, but it creates the SSRF boundary described above. A browser-only implementation avoids making your server fetch arbitrary destinations, but may encounter cross-origin restrictions and cannot reliably retrieve metadata from many sites. Choose based on the product’s access model and security requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does a link previewer need a headless browser?

Not for a basic metadata card. Start with bounded HTML fetching and metadata parsing; a browser adds complexity and should be justified by a demonstrated need for client-rendered content.

Is a hosted unfurl API automatically safer?

No. It changes who performs extraction, but you still need to assess what URL and data you send, the service’s retention and security practices, and how its results are validated and rendered in your application.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.