Developer

What Is HTML Encoding? Entities & Escaping Explained

ToolOrbit Engineering 2 min readUpdated
What Is HTML Encoding? Entities & Escaping Explained

HTML encoding means replacing characters that have a special meaning in HTML with codes called entities. A less-than sign starts a tag, an ampersand starts an entity, and quotes delimit attributes. When you want those characters to appear as text instead of being read as markup, you escape them. This guide explains what entities are, when you need them and the mistakes to avoid.

What HTML entities are

An entity is a stand-in for a character, written as an ampersand, a code, and a semicolon. The same character can usually be expressed three ways: a memorable named form, a decimal numeric form, or a hexadecimal numeric form. All three render identically in the browser.

Tom & Jerry <b>   becomes   Tom &amp; Jerry &lt;b&gt;

The © sign, three ways:
named: &copy;   decimal: &#169;   hex: &#xA9;

Why escaping matters

  • Security: escaping user input is a primary defense against cross-site scripting (XSS)
  • Correctness: an unescaped < or & can silently break your page layout
  • Display: showing code samples requires escaping the tags so they appear as text
  • Attributes: escaping quotes prevents user data from breaking out of an attribute
Tip: Escape based on context. The five characters & < > double-quote and apostrophe cover HTML text and attributes, but data placed inside script or style blocks needs different handling entirely.

Using the tool

Paste raw text to encode it into safe entities, or paste entity-laden HTML to decode it back into readable characters. Decode mode is great for cleaning up content scraped from a page or stored in a database where everything was over-escaped. All conversion runs privately in your browser.

Common mistakes

Do not double-escape: turning an already-escaped ampersand into a doubly-escaped one produces visible garbage on the page. Equally, do not rely on manual escaping for security in templates that already auto-escape, or you may end up with both. Understand whether your framework escapes for you, and let this tool handle the one-off conversions and debugging.

An entity reference cheat sheet

Entities you will actually need
CharacterNamed entityPurpose
&&amp;Escapes itself in text and URLs
<&lt;Shows markup as text
>&gt;Closes nothing when escaped
"&quot;Safe inside double-quoted attributes
'&#39;Safe inside single-quoted attributes
 &nbsp;Prevents line-break inside a phrase

Escaping inside attributes matters as much as in text: an unescaped quote can break out of a data-attribute and change how JavaScript reads your string. For anything user-supplied that will be rendered as HTML, escaping is the difference between displaying text and executing markup — this tool covers the six cases that cover almost every real bug.


Frequently asked questions

HTML encoding replaces special characters like <, >, &, and quotes with safe entities (&lt;, &gt;, &amp;, &quot;) so the browser shows them as text instead of interpreting them as markup.

Replace the < character with the entity &lt;. The encoder here does this automatically for every special character — and can go further by escaping all non-ASCII characters to numeric references.


Tools mentioned

More reading

View all guides
What Is Base64? How Encoding Works and Common Mistakes
Developer

What Is Base64? How Encoding Works and Common Mistakes

What Base64 encoding actually does, where it is used, and the mistakes that cause broken or oversized output.

2 min readUpdated
encodeURI vs encodeURIComponent: Which One to Use
Developer

encodeURI vs encodeURIComponent: Which One to Use

How percent-encoding works, the difference between encoding a whole URL and a single component, and the mistakes that break links.

2 min readUpdated
What Is a UUID? Version 4 vs Version 7 Explained
Developer

What Is a UUID? Version 4 vs Version 7 Explained

What a UUID looks like, why version 4 is the safe default, when version 7 is better, and best practices for IDs.

2 min readUpdated
How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption
Developer

How SHA-256 and SHA-512 Hashes Work: Hashing vs Encryption

What a hash function does, how to choose between SHA-256 and SHA-512, and why hashing is not encryption.

2 min readUpdated
What Is a JWT? Header, Payload and Signature Explained
Developer

What Is a JWT? Header, Payload and Signature Explained

A JSON Web Token has three parts. Learn what the header, payload and signature contain, how to read the claims, and why decoding is not verifying.

2 min readUpdated
Unix Time Explained: Seconds, Milliseconds and Time Zones
Developer

Unix Time Explained: Seconds, Milliseconds and Time Zones

What a Unix timestamp is, how to tell seconds from milliseconds, how time zones come into it, and the values worth recognising.

2 min readUpdated
Binary, Octal, Decimal and Hex: How Number Bases Work
Developer

Binary, Octal, Decimal and Hex: How Number Bases Work

How positional number bases work, why very large values need exact arithmetic, and the hex and binary values you meet every day.

2 min readUpdated
Regex Basics: How Patterns, Flags and Character Classes Work
Developer

Regex Basics: How Patterns, Flags and Character Classes Work

How a regular expression is built, what the flags change, and the character classes you will use most.

2 min readUpdated