HTML encoding means replacing characters that have a special meaning in HTML with codes called entities. A less-than sign starts a tag, an ampersand starts an entity, and quotes delimit attributes. When you want those characters to appear as text instead of being read as markup, you escape them. This guide explains what entities are, when you need them and the mistakes to avoid.
What HTML entities are
An entity is a stand-in for a character, written as an ampersand, a code, and a semicolon. The same character can usually be expressed three ways: a memorable named form, a decimal numeric form, or a hexadecimal numeric form. All three render identically in the browser.
Tom & Jerry <b> becomes Tom & Jerry <b> The © sign, three ways: named: © decimal: © hex: ©
Why escaping matters
- Security: escaping user input is a primary defense against cross-site scripting (XSS)
- Correctness: an unescaped < or & can silently break your page layout
- Display: showing code samples requires escaping the tags so they appear as text
- Attributes: escaping quotes prevents user data from breaking out of an attribute
Using the tool
Paste raw text to encode it into safe entities, or paste entity-laden HTML to decode it back into readable characters. Decode mode is great for cleaning up content scraped from a page or stored in a database where everything was over-escaped. All conversion runs privately in your browser.
Common mistakes
Do not double-escape: turning an already-escaped ampersand into a doubly-escaped one produces visible garbage on the page. Equally, do not rely on manual escaping for security in templates that already auto-escape, or you may end up with both. Understand whether your framework escapes for you, and let this tool handle the one-off conversions and debugging.
An entity reference cheat sheet
| Character | Named entity | Purpose |
|---|---|---|
| & | & | Escapes itself in text and URLs |
| < | < | Shows markup as text |
| > | > | Closes nothing when escaped |
| " | " | Safe inside double-quoted attributes |
| ' | ' | Safe inside single-quoted attributes |
| | Prevents line-break inside a phrase |
Escaping inside attributes matters as much as in text: an unescaped quote can break out of a data-attribute and change how JavaScript reads your string. For anything user-supplied that will be rendered as HTML, escaping is the difference between displaying text and executing markup — this tool covers the six cases that cover almost every real bug.
Frequently asked questions
HTML encoding replaces special characters like <, >, &, and quotes with safe entities (<, >, &, ") so the browser shows them as text instead of interpreting them as markup.
Replace the < character with the entity <. The encoder here does this automatically for every special character — and can go further by escaping all non-ASCII characters to numeric references.