Text typed into the Letterhead Generator cannot inject SVG markup. Every string a user enters — the company name, tagline, address lines, phone, email, and website — is XML-escaped before it is placed into an SVG text node, so characters such as <, >, &, ", and ' become safe entities rather than new elements, attributes, or script handlers. A value like North & Pine stays visible as ordinary text, while a script-looking input such as </text><script>alert(1)</script> is neutralized to escaped characters that the SVG parser treats as inert content. The tool never copies any user value into an event handler, a <style> block, an external <image>, a <foreignObject>, a hyperlink, or any executable script. Because the preview pane shows the exact SVG string that the download saves, the escaping is end-to-end visible: the file you download is the file you reviewed. This narrow contract — bounded text, one validated color, one deterministic SVG, and identical preview and download — is the core safety guarantee. Below is exactly how the tool enforces it and how to use it.

How SVG Markup Injection Works and Why It Matters
When a tool turns user text into SVG without escaping, an attacker — or even an accidental paste from a clipboard — can break out of the text node and add elements that execute scripts, load remote resources, or alter layout. The risk is real because SVG is a live XML format: a parser that encounters a closing tag inside a text value will treat what follows as markup rather than as visible characters.
Common injection vectors include:
- Unescaped angle brackets that close a <text> element and open a new one, such as </text><script>...</script>.
- Unescaped ampersands that allow numeric character references like <script>.
- Unescaped quotes inside attribute values if text is ever placed into an attribute.
- JavaScript URLs or on* event handlers if the tool places user text inside a link or attribute.
- HTML inside <foreignObject> if the tool mixes HTML with SVG.
- <style> blocks or remote CSS that pull in external fonts or scripts.
Any of these turns a harmless letterhead generator into a vehicle for stored content that runs in the viewer's browser. The fix is not to filter bad strings after the fact — the fix is to escape every string before insertion, restrict where strings can go, and keep the output template as constrained as possible.
How the Letterhead Generator Blocks Markup Injection
The Letterhead Generator's defense rests on three layers: input validation, escape-on-insert, and a constrained output template.
First, every input is trimmed and bounded. The company name is required and capped at 80 characters. The tagline, phone, email, website, and each address line have explicit character limits. The address accepts at most three non-empty lines — a fourth non-empty line is rejected rather than silently hidden, so what you see in the preview always matches the actual content. Disallowed control characters are rejected. The accent color must be a complete six-digit #RRGGBB value; the browser color input normally supplies that format, and the logic layer validates it again before the SVG is generated.
Second, every user string is XML-escaped before it enters the SVG. Ampersands become &, less-than becomes <, greater-than becomes >, double quotes become ", and apostrophes become '. After escaping, the string is placed only into ordinary SVG <text> nodes — never into an attribute, never into a URL, and never into a script context.
Third, the output template is constrained. The SVG has a single root element with a fixed 816 by 1056 viewBox and matching width and height. The template includes a horizontal header rule and a footer divider in the chosen accent color, right-aligned contact lines in a fixed order (address, phone, email, website), and a footer that repeats the company and website when available. Other foreground and background values are fixed neutral design colors so the output stays readable; the tool does not calculate brand contrast compliance or claim that one chosen accent satisfies an organization's accessibility policy. No user value is copied into event handlers, <style> blocks, <foreignObject>, external <image> references, hyperlinks, or executable scripts. Blank optional fields do not reserve fake content. Tests assert exact escaping and require one root SVG element, so a regression in the escape function would fail the build before shipping.
| Common injection vector | How the Letterhead Generator handles it |
|---|---|
| Closing a text node with </text> and adding a new element | Angle brackets in user strings are escaped to < and > before insertion |
| Numeric entity references like <script> | Ampersands in user strings are escaped to & |
| Quotes that break out of an attribute | User strings are never placed inside an SVG attribute |
| onclick, onload, and other event handlers | User strings are never copied into event handler attributes |
| JavaScript URLs inside xlink:href or href | User strings are never placed inside a link or image reference |
| HTML inside <foreignObject> | The template contains no <foreignObject> elements |
| Remote scripts or fonts inside <style> or CSS | User strings are never copied into a <style> block |
The combination is what removes the risk. Escaping alone is not enough if the template still allows user text into an attribute or a style block. A constrained template alone is not enough if the escape function ever forgets a character. The tool commits to both, plus an identical preview and download, which makes the safety property auditable in the browser by anyone who reads the file.
Input Limits and Validation Rules
| Field | Required? | Limit | Rejected when |
|---|---|---|---|
| Company name | Yes | 80 characters | Empty, over the limit, or contains disallowed control characters |
| Tagline | No | Bounded by an explicit character limit | Contains disallowed control characters |
| Address lines | No | At most 3 non-empty lines, each bounded | A fourth non-empty line is submitted, or a line contains control characters |
| Phone | No | Bounded by an explicit character limit | Contains disallowed control characters |
| No | Bounded by an explicit character limit | Contains disallowed control characters | |
| Website | No | Bounded by an explicit character limit | Contains disallowed control characters |
| Accent color | Yes | Six-digit #RRGGBB hexadecimal | Any other format, missing #, or non-hex characters |
These limits are layout and performance boundaries, not official formatting rules. The accent color appears in the horizontal header rule and the footer divider; the rest of the canvas uses fixed neutral design colors. If you need a fuller brand system, an accessibility audit, or a registered logo placement, those are separate steps that happen outside the generator.
Generate Your Letterhead Safely
- Enter the company name and, if you want one, a short tagline. The company name is required and limited to 80 characters.
- Add up to three non-empty address lines and the contact fields you want shown: phone, email, website. Any field left blank is simply omitted from the output rather than reserved with placeholder text.
- Pick a six-digit accent color from the color picker, or paste a complete #RRGGBB value. The browser color input normally provides that format; the logic layer validates it again before the SVG is generated.
- Select Generate letterhead. The preview pane now shows the exact SVG string that the download button will save.
- Inspect every visible detail in the preview: spelling, line wrapping, contact accuracy, accent contrast against the white background, and spacing.
- Select Download SVG to save the file locally. The filename is derived from a sanitized version of your company name.
- Place the SVG into your document workflow — a vector editor, word processor, layout application, or print pipeline — and verify printer scaling, margins, brand permission, and accessibility in that downstream tool.
The preview and the download use the identical SVG string, so the escaping you see in the browser is the escaping that ships in the file. Editing any field clears the previous preview and revokes its temporary object URL, so an old download cannot appear to represent new inputs. The download URL is also revoked after use and when the component unmounts.
After You Download: Verify and Place the File
The Letterhead Generator builds the file in your current browser tab. It does not upload your company information, store it in an account, or send it to a remote rendering service. Once the file is on your computer, however, the limits of the generator stop. The 816 by 1056 viewBox is a fixed logical canvas chosen for this template; physical dimensions depend on the editor, page setup, scaling, and printer you use later. The tool does not check brand permission, validate postal addresses, verify email addresses, audit accessibility, or authenticate the named organization — a polished letterhead does not prove the company exists or has authorized the message.
For that reason, before you send a real letter:
- Spell-check the company name, tagline, address, phone, email, and website.
- Check the accent color contrast against the white background. The generator escapes strings; it does not calculate WCAG ratios.
- Confirm you have permission to use the company name, any logo you add separately, and any registered marks.
- Open the SVG in your target application (Word, InDesign, a browser, a PDF converter) and confirm the header sits where you expect at the page size you plan to print.
- Decide whether the letterhead should appear only on the first page or repeat on every page in your layout tool.
These checks belong to the downstream document workflow, not to the letterhead generator.
What the Letterhead Generator Does Not Do
It is worth being explicit about scope. The Letterhead Generator is not a trademark search, brand approval system, corporate registry, legal stationery service, postal validator, email verifier, accessibility audit, print preflight, or identity authentication tool. It is a utility that validates bounded text and one color, escapes every string for XML, serializes one deterministic SVG, shows that exact string in the preview, creates a local download after a direct action, and distinguishes logical canvas dimensions from physical print claims.
If you need any of the other functions — contrast checking, address validation, brand approval, identity authentication — those are separate problems with separate tools. A clean SVG that meets its narrow contract is not, by itself, a complete corporate identity program.
Bottom Line: Your Text Stays Text
To return to the original question: no, text input cannot inject SVG markup when using the Letterhead Generator. The combination of bounded inputs, complete XML entity escaping, text-only insertion points, a constrained template, and identical preview-and-download strings removes every common injection vector. Your company name, tagline, address, phone, email, and website appear as visible text in the output and nothing else.
A practical way to verify this for yourself: open the Letterhead Generator, paste a value into any field that contains <, >, &, ", or ', and generate. The characters will render as escaped entities in the preview and as inert text in the downloaded file. If you want a deeper walkthrough of how validation, preview, and download are wired together, see Create a Letterhead: Validate, Preview, and Download.
Related reading: Does a Letterhead Prove Company Identity or Authorization?.