HTML Entity Encoder / Decoder

100% Client-Side Private

Escape and unescape special HTML characters to prevent XSS issues

Format:

Quick Reference: Common HTML Entities

<Less Than
&lt;
>Greater Than
&gt;
&Ampersand
&amp;
"Double Quote
&quot;
'Single Quote
&#39;
©Copyright
&copy;

How to escape HTML entities

  1. 1Select "Encode / Escape" or "Decode / Unescape".
  2. 2Paste code snippets or text with special markup characters.
  3. 3Copy the safe HTML entity text for embedding into web templates.

Cross-Site Scripting (XSS) Prevention

Escaping HTML entities ensures user input rendered in browsers cannot execute unintended script tags or compromise web security.

Architecture & Privacy

  • XSS Sanitization helper: Escapes reserved characters <, >, &, ", ' to neutralize injection payloads.
  • Code point safe iteration: Iterates using Array.from(input) to avoid breaking surrogate pairs on multi-byte characters.
  • Bidirectional decoding: Safely parses named, decimal, and hexadecimal entities simultaneously.

Frequently Asked Questions

Related Developer Utilities