Small enough to inspect.
A converter should be easy to use and easy to understand. This one uses plain HTML, CSS, and JavaScript with no runtime packages.
Read what runs in your browser
- Interface and interactions — inputs, local file reading, clipboard, and downloads.
- Encoding and hashing functions — RFC 4648 codecs, MD5, and browser Web Crypto for SHA-256.
- Base64 presets — protocol rules and references shared by the interface and codecs.
- Browser worker — runs conversion away from the interface thread.
- Stylesheet — the responsive layout, with system fonts.
Network and storage
There are no fetch calls, conversion endpoints, database bindings, analytics, browser-storage writes, or third-party runtime dependencies. The hosting configuration sends a Content Security Policy with connect-src 'none'. Conversion content is never placed in a URL.
Limits and validation
Raw input and decoded output are limited to 10 MiB. Encoded text is limited to 20 MiB (plus a small wrapping allowance). Text previews stop at 65,536 characters; copy and download use the full result. Decoders reject invalid alphabets, lengths, padding, and nonzero unused trailing bits. Standard and URL-safe presets decode strictly. Custom rules can allow whitespace or omitted padding. MIME ignores non-alphabet characters with a visible report; PEM accepts alternate line lengths and whitespace with a visible report. Neither mode relaxes padding or unused-bit validation. PEM checks the envelope only, not certificate or key structures.
Asset fingerprints
These SHA-256 fingerprints identify the assets in this build. They help compare copies, but a hash served by the same site is not independent proof of trust.
app.js
7ea3c1651ea1293100e48765c31097bf4dded5397576d32cbd8280be0dc6401ecodecs.js
76777b3377b79602221d8702b3d1a2d298558d5a14a7b22e25dab24e3d5d63b2profiles.js
382dfc669e42b6df3975448425f77fc9263b651288c945e9e579055e05fddca6worker.js
5362d283789feb81dece7672ec7d98d12a6aaba9a0b00f3f1b8b5491c64b01d6style.css
7f2793c02270692857ebb146054ce6be923dc3b48e96f83d80d83f8d518221a9Run a local copy
Save these assets and a tool page, preserve their /assets/ paths, and serve the folder with a local static HTTP server. The full project includes a build script, tests, and Cloudflare configuration. The application needs no server-side conversion service.