HTML Encoder
Encode and decode HTML entities
How to use HTML Encoder
- 1Paste HTML text needing escaping (with < > & etc.).
- 2Choose encode (escape special chars) or decode (restore).
- 3Copy the result for web code, form values, or docs.
What is HTML escaping and why
map: & → & < → < > → > " → " ' → 'HTML escaping replaces syntax-meaning chars with entity references so the browser won't treat them as tags or attributes. E.g. write < as < to display a literal less-than.
When echoing user input back to a page, correct escaping prevents XSS (cross-site scripting)—a Web-security basic. Frameworks often auto-escape; manual HTML concatenation needs care.
This tool encodes/decodes both ways, handy to check what a snippet really renders as, or to restore someone else's escaped content.
Frequently asked questions
Is escaping the same as encryption?
No. Escaping only strips syntactic meaning; anyone can decode it. It's not secret and doesn't replace encryption.
When must I escape?
Whenever inserting data into HTML, attributes, URLs, or JS contexts. Riskiest is user input concatenated straight into a page—use context-correct escaping.
Why does decoding differ from the original?
If the source already had entities (e.g. &), decoding restores &. Expected; watch idempotency on repeated round-trips.
