HTML Entities
Escape or unescape reserved HTML characters as named or numeric entities, with a reference table for the ones you actually need.
Convert
Entity reference
| Character | Named | Numeric | Notes |
|---|
About this HTML entity encoder
Five characters carry structural meaning in HTML and have to be escaped before they can appear as literal text: the ampersand &, the less-than sign <, the greater-than sign >, the double quote " and the single quote. Escaping the ampersand must happen first, otherwise the ampersand you introduce while escaping something else gets escaped a second time and the markup turns into &.
An entity can be written by name, such as ©, or numerically, such as © in decimal or © in hexadecimal. Names are shorter and easier to read, but the named set only covers a fixed list — anything outside it, including most emoji and every character above U+FFFF, can only be written numerically. The encode option above will convert non-ASCII text to decimal numeric references for exactly that reason.
The reason this matters beyond cosmetics is security. Inserting untrusted text into an HTML document without escaping is the classic cross-site scripting vector, because a value like <script> becomes executable markup rather than display text. Escaping is the first line of defence, but it is context-dependent: text inside an attribute, inside a <script> block and inside a URL each need different treatment, and HTML escaping alone is not sufficient for any of them. Note also that ' is defined in HTML5 and XML but not in HTML4, so ' remains the safer spelling.
Related tools
Found a bug, or need a tool that is not here? Email 2273917172@qq.com — a human reads every message.