Toolcedar

HTML Entity Encoder

Encode text into HTML entities or decode entities back to characters. Escapes the five characters that break markup, safely in your browser.

How to use the HTML Entity Encoder

  1. Choose a direction. Encode plain text into entities, or decode entities back.
  2. Paste your text. The conversion runs as you type.
  3. Copy the result. Copy the output straight into your template or document.

Frequently asked questions

Which characters actually need escaping?
Five: ampersand, less-than, greater-than, double quote and single quote. The first three break the markup itself, and the two quote characters break out of attribute values, which is how most injection bugs start.
Is escaping HTML enough to prevent XSS?
Only in element text and quoted attributes. Inside a script block, a style block, or a URL attribute the rules are different, and entity escaping there provides no protection at all.
What is the difference between named and numeric entities?
Named entities such as ampersand-a-m-p are readable, while numeric ones reference a code point directly. Numeric entities always work; named ones depend on the name existing in the parser you are targeting.
Does decoding here use innerHTML?
No. Decoding by assigning to innerHTML is a common shortcut that can execute markup as a side effect. This decodes with an explicit table and numeric parsing instead, so nothing is ever interpreted.

Last updated