Format:
Quick Reference: Common HTML Entities
<Less Than
<>Greater Than
>&Ampersand
&"Double Quote
"'Single Quote
'©Copyright
©HTMLエスケープの手順
- 1「エンコード(エスケープ)」または「デコード(解除)」を選択します。
- 2HTMLタグや特殊記号を含むテキストを入力欄に貼り付けます。
- 3安全にエスケープされた文字列をテンプレートやコードにコピーします。
クロスサイトスクリプティング(XSS)防御の基本
ユーザー入力をそのままHTMLに出力すると悪意あるスクリプトが実行される恐れがあります。特殊文字をエスケープすることはWebセキュリティの鉄則です。
Architecture & Privacy
- XSS Sanitization helper: Escapes reserved characters <, >, &, ", ' to neutralize injection payloads.
- Code point safe iteration: Iterates using Array.from(input) to avoid breaking surrogate pairs on multi-byte characters.
- Bidirectional decoding: Safely parses named, decimal, and hexadecimal entities simultaneously.