Markup rendered as text
Input
<script>alert("hi")</script>Output
<script>alert("hi")</script>The browser now displays the tag rather than executing it.
Five characters have special meaning in HTML, and any text containing them will be parsed as markup rather than shown literally. Escaping replaces them with entity references so a browser renders the characters themselves.
This is the mechanism behind preventing cross-site scripting. When untrusted text is escaped before insertion into a page, a payload like <script> becomes visible text instead of an executing element. Escaping is not a substitute for a proper templating layer, but it is the underlying operation every such layer performs.
Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.
Input
<script>alert("hi")</script>Output
<script>alert("hi")</script>The browser now displays the tag rather than executing it.
Input
" onmouseover="alert(1)Output
" onmouseover="alert(1)With the quotes escaped, the text cannot close an attribute and inject a handler.
The details that decide whether a conversion is correct, and where information can be lost without any error being raised.