~/frontend-tools/html-entity-encoder
HTML Entity Encoder and Decoder
Escape text so it can be shown safely inside HTML, or turn entities like & and — back into readable characters. Choose to escape only the special characters or every non-ASCII character too.
Using the HTML Entity Encoder / Decoder
Why escape HTML
Characters such as < and & have special meaning in HTML. To show them as text, for example in a code sample or a comment, they must be written as entities, otherwise the browser treats them as markup. Escaping user-supplied text is also a basic defence against cross-site scripting.
The five essentials
Inside normal content and attributes, escaping &, <, >, double quotes and single quotes is enough. That is the default mode, and it keeps every other character readable.
Encoding non-ASCII
Pages served as UTF-8 can include any character directly, so encoding accents or emoji is rarely needed. It can still help for systems that mangle non-ASCII text, such as some email tools and legacy databases. Named entities like © are used where they exist; others become numeric references.
Decoding
Decoding turns any named or numeric entity back into its character using the browser's own HTML parser, so even rare entities are understood. Tags in the input are treated as text, never run.
Frequently asked questions
Is this enough to prevent XSS?
Escaping output is an important part of it, but frameworks and server templates should do it automatically. Context matters too: URLs and JavaScript strings need different escaping.
What is the difference between &#169; and &copy;?
Both display ©. The first is a numeric reference, the second a named entity.
Does decoding run any scripts in my input?
No. The text is decoded without being rendered or executed.