Shard Tools

HTML Entity Encoder

Encode text as HTML entities in your browser so it displays as text instead of being interpreted as markup.

Maintained by Roshan.

Use HTML Entity Encoder

Converts text or html to escaped html in this tab, with nothing sent anywhere.

Runs entirely on your deviceThe conversion happens in this browser tab. Nothing you type is uploaded, logged or stored, which is worth knowing for anything you would not paste into a search box.

Explore developer and data tools

Find related browser-local tools for nearby tasks without starting another search.

Browse all developer and data tools

About HTML Entity Encoder

Whenever text is placed inside a web page, a handful of characters are dangerous, because the browser reads them as instructions rather than content. A less-than sign starts a tag; an ampersand starts an entity; a quote can end an attribute. If a value containing any of these is dropped into a page without being escaped, at best it renders wrong and at worst it lets injected markup run - the mechanism behind a large share of cross-site scripting bugs. Encoding those characters as HTML entities is the fix: the less-than sign becomes an entity that displays as a less-than sign but is no longer read as the start of a tag. This tool escapes the five characters that matter, which is what makes arbitrary text safe to show on a page.

Using HTML Entity Encoder

  1. The five characters that change meaning in HTML - the ampersand, less-than, greater-than, double quote and single quote - are each replaced with the entity that displays them literally.
  2. The ampersand is handled first in effect, so an existing entity is not double-escaped into nonsense.
  3. Every other character is left as it is, since only these five are interpreted specially by an HTML parser.
  4. The result can be dropped into page content or an attribute value and will display exactly as typed.
  5. It is the same escaping a well-built template applies automatically, made available for the times you are assembling markup by hand.

Where html entity encoder helps

Showing code on a page

To display an HTML snippet as text rather than have it render, encode it first. The tags then appear as written.

Inserting user text into markup by hand

Any value you concatenate into HTML should be encoded, or a stray angle bracket can break the page or inject content.

Before you use the result

Questions about HTML Entity Encoder

Which characters get encoded?

The five that HTML treats specially: & < > " and '. Everything else is left alone.

Do accented letters need encoding?

Not in a UTF-8 page. They display fine as themselves, so they are left unchanged.

Why does encoding twice look wrong?

Because the entities themselves contain an ampersand, which gets re-encoded. Encode raw text once only.

Is this enough to prevent XSS?

For HTML text and attributes, escaping these characters is the core defence. Other contexts, like scripts or URLs, need their own escaping.

Related tools

HTML Entity Decoder

Decode HTML entities back into plain text in your browser, including numeric and named forms.

Unicode Escape

Convert text into Unicode escape sequences in your browser, handling characters above the basic plane.

URL Encoder and Decoder

Percent-encode and decode URLs in your browser, choosing between encoding a value inside a URL and encoding a whole address. Shows which characters differ.