HTML Entity Encoder

Escape <, >, &, and quotes for safe HTML display.

Reverse
Input
TEXT input
Output
Result
Options

Converts accents and emoji to numeric references. Rarely needed on UTF-8 pages.

About this tool


Five characters have special meaning in HTML, and any text containing them will be parsed as markup rather than shown literally. Escaping replaces them with entity references so a browser renders the characters themselves.

This is the mechanism behind preventing cross-site scripting. When untrusted text is escaped before insertion into a page, a payload like <script> becomes visible text instead of an executing element. Escaping is not a substitute for a proper templating layer, but it is the underlying operation every such layer performs.

How to use it

  1. Paste or upload your textDrop a file onto the input pane, use the file picker, or paste the text directly.
  2. Adjust the options if neededThe defaults suit most input; open Options to change the behaviour.
  3. EncodePress Encode, or use Ctrl+Enter (Cmd+Enter on macOS).
  4. Copy or downloadCopy the result, or download it as a .html file.

Worked examples


Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.

Markup rendered as text

Input

<script>alert("hi")</script>

Output

&lt;script&gt;alert(&quot;hi&quot;)&lt;/script&gt;

The browser now displays the tag rather than executing it.

An attribute-breaking payload

Input

" onmouseover="alert(1)

Output

&quot; onmouseover=&quot;alert(1)

With the quotes escaped, the text cannot close an attribute and inject a handler.

What to watch for


The details that decide whether a conversion is correct, and where information can be lost without any error being raised.

The five characters that must be escaped
The ampersand becomes &amp;, less-than becomes &lt;, greater-than becomes &gt;, the double quote becomes &quot; and the apostrophe becomes &#39;. The ampersand has to be escaped first, or escaping the others would produce broken double-escapes.
Why the apostrophe uses a numeric reference
The named form &apos; is valid in HTML5 and XML but was never part of HTML 4, so older parsers and some XML consumers do not recognise it. The numeric reference &#39; means exactly the same character and is universally understood, so that is what this tool emits.
Quotes matter because of attributes
Escaping only angle brackets is enough for text between tags, but not for an attribute value. If a value is inserted into an attribute without escaping quotes, a payload can close the attribute and add its own, the classic " onmouseover=" injection. Escaping quotes closes that vector.
Optional non-ASCII encoding
Accented characters and emoji need no escaping on a UTF-8 page, which every modern page is. The "encode non-ASCII" option converts them to numeric references anyway, which is occasionally required for legacy systems, email templates, or files that must be pure ASCII. It makes output considerably longer.

Limitations


  • Escaping is correct for HTML text and attribute contexts, but not for JavaScript, CSS or URL contexts, which need their own rules.
  • Processing happens in your browser, so very large inputs are bounded by available memory. Files above roughly 10 MB are handled but will feel slower, and multi-hundred-megabyte files are better suited to a command-line tool.

Questions


Is escaping enough to prevent XSS?
It is the right operation for inserting text into HTML, but context matters. Text inside a <script> block, a URL attribute, or a CSS context each need different handling. Use your framework's escaping, which is context-aware, and treat this tool as a way to inspect and understand the transformation.
Do I need to escape accented characters?
No, not on a UTF-8 page. Only the five structural characters require escaping. The non-ASCII option exists for legacy systems that need pure ASCII output.
Why &#39; rather than &apos;?
Because &apos; is not recognised in HTML 4 and some XML tools. The numeric reference is equivalent and works everywhere.