SolutionsCase StudiesAI ToolsResourcesAboutContact
Get Your Free AI Automation Audit Book a Free 30-Minute Strategy Call
Playground~/frontend Open editor

~/frontend-tools/html-entity-encoder

HTML Entity Encoder and Decoder

ToolRuns in your browserNothing is uploadedFree · no sign-up

Escape text so it can be shown safely inside HTML, or turn entities like & and — back into readable characters. Choose to escape only the special characters or every non-ASCII character too.

Mode

Using the HTML Entity Encoder / Decoder

Why escape HTML

Characters such as < and & have special meaning in HTML. To show them as text, for example in a code sample or a comment, they must be written as entities, otherwise the browser treats them as markup. Escaping user-supplied text is also a basic defence against cross-site scripting.

The five essentials

Inside normal content and attributes, escaping &, <, >, double quotes and single quotes is enough. That is the default mode, and it keeps every other character readable.

Encoding non-ASCII

Pages served as UTF-8 can include any character directly, so encoding accents or emoji is rarely needed. It can still help for systems that mangle non-ASCII text, such as some email tools and legacy databases. Named entities like &copy; are used where they exist; others become numeric references.

Decoding

Decoding turns any named or numeric entity back into its character using the browser's own HTML parser, so even rare entities are understood. Tags in the input are treated as text, never run.

Frequently asked questions

Is this enough to prevent XSS?

Escaping output is an important part of it, but frameworks and server templates should do it automatically. Context matters too: URLs and JavaScript strings need different escaping.

What is the difference between &amp;#169; and &amp;copy;?

Both display ©. The first is a numeric reference, the second a named entity.

Does decoding run any scripts in my input?

No. The text is decoded without being rendered or executed.