Online HTML Entity Encoder & Decoder
HTML special-character escape / entity encode / entity decode / XSS prevention
What Is HTML Entity Encoding?
HTML entity encoding converts special characters in HTML (such as <, >, &, ", etc.) into their entity representations so the browser does not parse them as HTML tags. It is commonly used to prevent XSS attacks and correctly display special characters. For URL encoding, use the URL Encoder/Decoder.
FAQ
Which characters need HTML entity encoding?
Mainly characters with special meaning in HTML: < (\<), > (\>), & (\&), " (\"), ' (\'), and so on.
Where is the encoded text used?
Encoded text can be safely embedded in an HTML page; the browser displays the original characters instead of parsing them as tags. For other character representations, use a Unicode converter.
What is the difference between HTML entity encoding and URL encoding?
HTML entity encoding safely displays special characters inside HTML to prevent XSS; URL encoding transports special characters within a URL. They apply to different scenarios.