Skip to main content

HTML Escape / Unescape

Escape HTML special characters to entities and convert them back, in your browser. Covers the five characters that matter for XSS safety and display.

Convert the characters that HTML treats as markup into their entity form, and convert entities back into readable text. The escape direction handles the five characters that matter in practice; the unescape direction also accepts the common alternative spellings for the apostrophe.

HTML Escape / Unescape
The result appears here...
&→&
<→&lt;
>→&gt;
"→&quot;
'→&#39;

// HTML Escape / Unescape: Features

The five characters that need escaping

Escaping converts an ampersand to &amp;amp;, a less-than sign to &amp;lt;, a greater-than sign to &amp;gt;, a double quote to &amp;quot; and an apostrophe to &amp;#39;. Those five cover every context where a character would otherwise be read as markup or would break out of an attribute. The ampersand has to be converted first, which the tool does in a single pass so that an already-escaped entity is not escaped twice by accident.

Why this matters beyond display

The visible problem is that unescaped markup disappears: a code sample containing a div tag renders as an actual div rather than as text. The serious problem is that user-supplied content containing a script tag becomes executable, which is cross-site scripting. Escaping on output is the standard defence, and every mainstream template engine does it by default. This tool is for the cases in between: checking what a value becomes, preparing a code sample, or working out why a particular string rendered the way it did.

Escaping is contextual

HTML entity escaping is correct for text content and for attribute values, and it is not sufficient anywhere else. A value interpolated into a script block needs JavaScript escaping, a value placed in a style block needs CSS escaping, and a value used as a URL needs percent encoding, which the URL Encoder handles. Putting untrusted input into an event handler attribute or a javascript: URL is unsafe no matter how it is escaped, because the context itself is executable.

Unescaping, and the several spellings of an apostrophe

Going the other way, the tool recognises &amp;amp;, &amp;lt;, &amp;gt;, &amp;quot; and three different forms of the apostrophe: &amp;#39;, &amp;#x27; and &amp;apos;. Different libraries emit different ones, which is why text that has passed through several systems often contains a mixture. Entities it does not recognise are left untouched rather than mangled, so you can see exactly what remains.

Working with data taken from a bug report

The conversion is a string replacement running in your browser. The text you paste is never sent anywhere, stored or logged, so you can safely work with template fragments from an internal application, snippets of a customer's data you are debugging, or a payload from a security report. Closing the tab discards it.

// HTML Escape / Unescape: FAQ

Which characters does escaping convert?

Five: the ampersand, less-than, greater-than, double quote and apostrophe. These are the characters that HTML parsers treat specially, whether in text content or inside an attribute value. Other characters, including accented letters, CJK text and emoji, are left as they are, because a UTF-8 page renders them correctly without entities.

Why must the ampersand be escaped first?

Because every other entity starts with one. If a less-than sign were converted to &amp;lt; before ampersands were handled, the ampersand in that new entity would then be converted too, producing &amp;amp;lt; which displays as the literal text &amp;lt; rather than as a less-than sign. The tool does all five in a single pass, which avoids the problem entirely.

Does escaping protect against XSS?

Escaping on output is the core of the defence, but it is only correct for HTML text and attribute contexts. A value inserted into a script block, a style block, a URL or an event handler attribute needs the escaping appropriate to that context, and some of those positions cannot be made safe with untrusted input at all. Use your framework's contextual escaping rather than escaping by hand, and treat this tool as a way to inspect and understand values.

Should I escape my page's Japanese or accented text?

No. Entities such as &amp;aacute; exist for historical reasons, from an era when pages could not reliably carry non-ASCII bytes. A page served as UTF-8, which is the modern default, displays those characters directly. Converting them to entities makes the source harder to read and the file larger for no benefit.

What is the difference between &amp;#39; and &amp;apos;?

They produce the same apostrophe but have different histories. &amp;apos; is defined in XML and XHTML and was not part of HTML 4, so very old browsers did not understand it; &amp;#39; is a numeric reference that has always worked everywhere. &amp;#x27; is the same value written in hexadecimal. Most escaping libraries emit &amp;#39; for maximum compatibility, and this tool accepts all three when unescaping.

Why does my escaped text still show as markup?

Usually because it is being inserted with something that parses HTML, such as innerHTML, after it was escaped, or because the value was unescaped again somewhere in the chain. Double-check where the string enters the page: escaping and then assigning to textContent is safe and correct, while escaping and then assigning to innerHTML can undo your work if the value passes through another decoding step.

Can it handle a whole HTML document?

Yes, though consider whether that is what you want. Escaping an entire document turns it into text that displays as source code, which is exactly right for a tutorial or a code sample and wrong if you meant to render it. To preview markup as a page instead, use the HTML preview tool in the Japanese edition.

What happens to entities it does not recognise?

They are left exactly as they are. Unescaping only touches the specific entities it knows, so something like &amp;nbsp; or &amp;copy; passes through unchanged and is easy to spot in the output. Nothing is silently altered.

Does it escape or unescape automatically?

No, the direction is explicit. That is deliberate: guessing leads to the double-conversion bugs that make escaped text unreadable. Choose the mode, and use SWAP to move the result back into the input if you want to confirm that a value round-trips.

Is the HTML I paste sent to a server?

No. The conversion runs as JavaScript in your browser and the text you paste is never transmitted, stored or logged. Template fragments, application output and data from a bug report can all be pasted here safely.

// How to Use HTML Escape / Unescape

  1. Paste the HTML to escape

    Put the HTML or the escaped text into the input box. A snippet, a whole document or a single attribute value all work, and the conversion happens as you type.

  2. Escape or unescape

    Use ESCAPE to turn markup characters into entities, or UNESCAPE to turn entities back into readable characters. The reference panel below lists the conversions the tool performs.

  3. Copy the escaped HTML

    Copy the output with one click and paste it into your template, documentation or bug report. SWAP moves the output into the input and flips the direction, which is a quick way to verify a value survives a round trip unchanged.

Category Encoding