🏷️

HTML Entity Converter

Convert characters to and from HTML entities. Escape user input safely, decode entities back to text, with a reference table of common entities.

✓ Free forever✓ No signup✓ 100% private — runs in your browser
HTML Entity Converter
Encode or decode HTML entities. Handles all standard named entities and numeric references.
Input
Output
Result appears here…
Common Entity Reference
${[['&','&'],['<','<'],['>','>'],['"','"'],["'",'''],['©','©'],['®','®'],['™','™'],['€','€'],['£','£'],['¥','¥'],['→','→'],['←','←'],['↑','↑'],['↓','↓'],['•','•'],['…','…'],['—','—'],['–','–'],['×','×'],['÷','÷'],['±','±'],['≠','≠'],['≤','≤'],['≥','≥'],['∞','∞']] .map(([char,entity])=>`${char} = ${entity}`).join('')}

Five characters have structural meaning in HTML. Putting them into a page as literal text — rather than as entities — either breaks the markup or, far worse, allows injected content to execute. Escaping is the fix, and it is the foundation of cross-site scripting prevention.

How to use the HTML Entity Converter

  1. Paste the text you want to escape or decode
  2. Click Encode to convert characters to entities, or Decode for the reverse
  3. Use the reference table to look up a specific entity
  4. Copy the result

The five that matter

  • & → &amp; — must be escaped first, or you double-escape everything else.
  • < → &lt; — opens a tag.
  • > → &gt; — closes a tag.
  • " → &quot; — ends an attribute value.
  • ' → &#39; — ends a single-quoted attribute value.

Escaping only the angle brackets is a common half-measure. If the text lands inside an attribute, an unescaped quote closes the attribute early and everything after it is parsed as markup — which is a working XSS vector.

Escaping is context-dependent

HTML entity escaping is correct for text in the document body and in attribute values. It is not sufficient everywhere.

Inside a <script> block, the parser is reading JavaScript, not HTML — entities are not decoded and escaping them does nothing useful. Inside a URL attribute such as href, a javascript: value executes regardless of entity escaping. Inside CSS, different rules apply again.

In practice: use your framework's escaping, which is context-aware, and never build HTML by concatenating strings with user input.

Frequently asked questions

Does escaping HTML prevent XSS?

It prevents the most common form, where user text lands in the page body or an attribute. It does not protect text injected into script blocks, URL attributes or CSS — those need context-appropriate handling.

Why is & escaped first?

Because entities themselves start with &. Escape < to &lt; first and then escape the ampersands, and you get &amp;lt; — the literal text, not a less-than sign.

What is the difference between &#39; and &apos;?

Both produce an apostrophe, but &apos; is not defined in HTML 4 and fails in very old browsers. &#39; is the numeric reference and works everywhere.

Do I need to escape non-English characters?

Not if your page declares UTF-8, which it should. Accented characters and emoji render correctly as literal text. Entities for them are a legacy workaround.