Named and numeric references
Input
<b>bold</b> & — — —Output
<b>bold</b> & — — —All three dash forms decode to the same em dash character.
Decoding converts entity references back into the characters they stand for, which is what you need when text has been escaped one time too many, scraped content, a database field that was escaped on write as well as on read, or an email template showing &amp; to users.
This decoder deliberately does not use the DOM to do the work. The common shortcut of assigning to innerHTML and reading back textContent will execute markup in the process, which is a real vulnerability. A lookup table plus numeric reference parsing is both safer and works identically in a worker.
Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.
Input
<b>bold</b> & — — —Output
<b>bold</b> & — — —All three dash forms decode to the same em dash character.
Input
&lt;div&gt;Output
<div>One pass removes one layer. Decode again to get <div>.
The details that decide whether a conversion is correct, and where information can be lost without any error being raised.