What HTML escaping does
Five characters have a structural meaning in HTML. If they appear in text you want to display — a code sample, a user’s comment, a product name like Tom & Jerry — the browser may read them as markup. HTML escaping (also called HTML encoding) replaces each with an entity so it renders literally:
| Character | Entity | Why |
|---|---|---|
& | & | Starts every entity; must always be escaped first. |
< | < | Would open a tag. |
> | > | Closes a tag; escaped for symmetry and old parsers. |
" | " | Ends a double-quoted attribute value. |
' | ' | Ends a single-quoted attribute value (' is HTML5 and XML only). |
So <strong>Hello</strong> becomes <strong>Hello</strong> and shows up on the page as the tag text rather than bold type.
Text to HTML entities (encode)
Choose Escape / Encode. Special chars only gives the five-character HTML escape above, which is all a UTF-8 page needs. Choose + non-ASCII to also turn accented letters, curly quotes, dashes, symbols and emoji into entities — useful for ASCII-only email templates, legacy CMS fields or source files. Every character encodes letters and digits too, as numeric entities.
The entity format decides how those characters are written: Named uses the mnemonic where one exists (é, ©, —, €) and falls back to a numeric entity; Decimal gives é; Hex gives é. Characters outside the Basic Multilingual Plane, such as emoji, are encoded by their full code point (😀), not as two surrogate halves.
HTML entities to text (decode)
Choose Unescape / Decode, or leave Auto-detect on and paste text that contains entities. The HTML decoder handles all 2,000+ HTML5 named entities ( , …, →…), decimal entities (€ → €) and hex entities (€ → €). Tags in the input are left as text: decoding <p> gives you <p>, it does not render it.
- Double-encoded text:
&lt;decodes to<, not<. When the output still contains entities the tool says so and offers Decode again. - Non-breaking spaces:
becomes U+00A0, which looks like a space but is a different character. Search-and-replace it if you need ordinary spaces. - Decoded text is not safe HTML: once decoded,
<script>is live markup again. Decode for reading or data cleanup, and escape again before inserting it into a page.
Named vs numeric entities
| Character | Named | Decimal | Hex |
|---|---|---|---|
| non-breaking space | |   |   |
| © | © | © | © |
| é | é | é | é |
| — | — | — | — |
| “ ” | “ ” | “ ” | “ ” |
| € | € | € | € |
| ™ | ™ | ™ | ™ |
| → | → | → | → |
XML only knows five named entities (& < > " '), so choose Decimal or Hex when the output goes into XML, RSS or SVG.
Escaping HTML in code
JavaScript
const escapeHtml = s => s.replace(/&/g, "&").replace(/</g, "<")
.replace(/>/g, ">").replace(/"/g, """).replace(/'/g, "'");
// decode every entity with the browser's own parser
const t = document.createElement("textarea");
t.innerHTML = "Café & crème"; t.value; // "Café & crème"
Python
import html
html.escape('<a href="x">Tom & Jerry\'s</a>') # quote=True escapes " and ' too
html.unescape("Café €5") # 'Café €5'
PHP
htmlspecialchars($s, ENT_QUOTES | ENT_HTML5, 'UTF-8'); // escape
html_entity_decode($s, ENT_QUOTES | ENT_HTML5, 'UTF-8'); // decode
htmlentities($s, ENT_QUOTES | ENT_HTML5, 'UTF-8'); // encode non-ASCII too
Common questions
How do I convert HTML entities to text?
Paste the text and choose Decode (Auto-detect does this when it sees entities). Every named entity such as <, © or , and every numeric entity such as ' or €, is turned back into its character. If the result still contains entities, the text was encoded twice and a Decode again button appears.
Which characters must be escaped in HTML?
In text content, & and < must be escaped as & and <. Inside an attribute value, also escape the quote that delimits it: " for double quotes and ' for single quotes. Escaping > as > is not required but is common and harmless, so this tool escapes all five.
What is the difference between named and numeric HTML entities?
A named entity uses a mnemonic, like é for é. A numeric entity uses the Unicode code point, in decimal (é) or hex (é). Every character has a numeric form, but only about 2,000 have names. Numeric entities work everywhere, including XML, which only defines five named entities.
Do I need to encode accented letters and emoji?
Not if the page is served as UTF-8, which almost every modern page is. Encode non-ASCII characters only when the destination is not UTF-8 safe, such as an old email template, a legacy CMS field, or source code that must stay ASCII.
Is escaping HTML enough to prevent XSS?
Escaping protects HTML text and quoted attribute values. It does not make a value safe inside a script block, a style block, an unquoted attribute, or a URL such as a javascript: link. Use your template engine’s context-aware escaping and a Content Security Policy as well.
Is my text uploaded?
No. Encoding and decoding run in your browser. Nothing is sent to a server.