mirrorangel

HTML Entity Escape

Developer · v1.0.0 · runs fully in the browser, data never leaves your device

Result
Common entity cheat sheet (click to copy)

Usage and limits

Escape user input before inserting it into HTML (especially with innerHTML), or you risk XSS. Unescaping is meant for reading entity text in logs or source code.

Important: unescaping untrusted content and then rendering it is deliberately creating XSS. Escaping only guarantees that "this text is displayed as text" — it does not replace correct output encoding for the context (attributes, URLs, and JS strings each need their own encoding).

Similar tools