HTML Entity Escape
Developer · v1.0.0 · runs fully in the browser, data never leaves your device
Result
Common entity cheat sheet (click to copy)
Usage and limits
Escape user input before inserting it into HTML (especially with innerHTML), or you risk XSS. Unescaping is meant for reading entity text in logs or source code.
Important: unescaping untrusted content and then rendering it is deliberately creating XSS. Escaping only guarantees that "this text is displayed as text" — it does not replace correct output encoding for the context (attributes, URLs, and JS strings each need their own encoding).