HTML Entity Encoder / Decoder

Escape HTML-significant characters or decode entities back to plain text.

100% Local Processing

About the HTML Entity Encoder / Decoder

Convert HTML-significant characters such as ampersands, angle brackets, and quotes into entities, or decode named, decimal, and hexadecimal entities back to plain text. The output remains text and is never injected as markup. Entity encoding is useful when displaying text inside an HTML context, but it is not a universal XSS sanitizer: safe escaping depends on the output context and the rest of your application.

How to encode or decode entities

  1. Choose Encode or Decode.
  2. Paste plain text or entities into the input.
  3. Copy the output while keeping it in the HTML context where it is intended.

Examples and worked results

Escape markup characters

Input
<div class="test">Tom & Jerry</div>
Result
&lt;div class=&quot;test&quot;&gt;Tom &amp; Jerry&lt;/div&gt;

HTML entities are context-specific escaping

Encode changes the small set of markup-significant characters into named or numeric entities. Decode accepts named and numeric forms through a detached browser element, but the decoded value stays plain text and is never inserted as HTML.

Common use cases

  • Displaying example markup in documentation
  • Preparing text for an HTML source context
  • Inspecting named, decimal, and hexadecimal entities

Important notes and limitations

  • Entity encoding is not a universal XSS sanitizer. Output-context-aware escaping and other application controls are still required.

Practical tips

  • Use URL encoding for URL components; HTML entities and percent encoding solve different problems.

Frequently Asked Questions

Which characters are encoded?

The encoder converts ampersand, less-than, greater-than, double quote, and apostrophe to common safe entities.

Does decoding execute HTML?

No. Decoded output is kept as plain text and is not inserted into the page as markup.

Is HTML entity encoding a complete XSS defence?

No. Escaping must match the output context and be combined with appropriate application security controls.

Is this the same as URL encoding?

No. HTML entities are for HTML text or attribute contexts; URL percent encoding is for URL components.