DevToolsForYou
Private by defaultRuns in your browser

HTML escape / unescape

Convert special characters into safe HTML entities or decode existing entities back into readable text in a simple browser-based workspace.

Quick samplesUseful for testing
HTML Escape/Unescape

About this tool

A browser parsing HTML has no way to tell whether a < in your text was meant as literal punctuation or as the start of a tag. Escaping resolves that ambiguity by replacing the five characters that carry syntactic meaning — <, >, &, " and ' — with entity references such as &lt; and &amp;. The browser renders the entity as the original character but never treats it as markup. This is the mechanism behind cross-site scripting defence: if user-supplied text reaches a page unescaped, a submitted <script> tag becomes executing code rather than displayed text. Context matters as much as the escaping itself. Text between tags, an attribute value inside quotes, an unquoted attribute, and text inside a URL each need different treatment, and escaping designed for one is not sufficient for another. Unescaping runs the other way, turning entities back into readable characters — useful when a value has been double-escaped somewhere in a pipeline and you are staring at &amp;lt; in your output. This tool converts in both directions entirely in your browser.

No signup requiredRuns in your browserInstant results
How to use
  1. 1

    Paste your text or HTML into the input field.

  2. 2

    Select Escape to convert special characters to HTML entities, or Unescape to convert entities back to characters.

  3. 3

    The result appears instantly — safe to paste into HTML attributes or templates.

  4. 4

    Click Copy to copy the output.

Why use this tool?
  • →

    Escape snippets before rendering user content inside templates or docs.

  • →

    Decode copied entity strings back into readable HTML or text.

  • →

    Review how markup-safe content should look before publishing or embedding.

ExamplesInput → output

Escape HTML special characters

Input<script>alert('xss')</script>
Output&lt;script&gt;alert(&#39;xss&#39;)&lt;/script&gt;

Escape an attribute value

InputSay "hello" & goodbye
OutputSay &quot;hello&quot; &amp; goodbye

Unescape HTML entities

Input&lt;h1&gt;Hello &amp; World&lt;/h1&gt;
Output<h1>Hello & World</h1>
Common errorsAnd how to fix them

Output shows &amp;lt; instead of <

Cause: The text was escaped twice. Each pass converts the & of an existing entity into &amp;, so &lt; becomes &amp;lt;. This usually means a template engine escaped a value that your application code had already escaped.

Fix: Unescape once here to confirm that is what happened, then remove one of the two escaping steps in your code. Most template engines escape by default — the fix is normally to stop escaping manually rather than to mark the value as raw.

Escaped text still executes as script

Cause: Escaping for HTML text content does not make a value safe everywhere. A value dropped into an inline event handler, a <script> block, or an unquoted attribute is parsed by a different grammar, where entity escaping does not neutralise the payload.

Fix: Escape for the context you are writing into: HTML text, quoted attribute, JavaScript string, and URL each need their own encoding. Never interpolate user input into a script block or an unquoted attribute.

Apostrophes come back as &#39; and break a comparison

Cause: Escaping is not canonical — &#39;, &apos;, and &#x27; are all valid encodings of the same apostrophe, and different libraries pick different ones.

Fix: Compare unescaped values, not escaped ones. If you must store escaped text, escape once with a single library and treat that output as opaque rather than string-matching against it.

Frequently asked questionsCommon questions answered

These answers explain common html escape/unescape tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.

What does HTML escaping do?

HTML escaping converts characters like <, >, &, quotes, and apostrophes into entity form so they render as text instead of being interpreted as markup.

When should I unescape HTML entities?

Unescape when you have copied encoded content such as &lt;div&gt; or &amp; and you want to inspect the readable text or markup it represents.

Does HTML escaping make content fully secure?

It helps render text safely in HTML contexts, but full security still depends on the exact output context, templating system, and application behavior.

Can I use this tool for code snippets in docs or blogs?

Yes. It is useful for converting markup-heavy snippets into entity form so they display correctly inside documentation, CMS editors, and tutorials.

Code examplesUse this tool in your code

In browsers, create a temporary DOM element to escape HTML reliably. In Node.js, use a library like he or escape manually.

JavaScript / Node.jsBrowser
// Escape using a temporary DOM element (most reliable in browsers)
function escapeHtml(str) {
  const div = document.createElement("div");
  div.appendChild(document.createTextNode(str));
  return div.innerHTML;
}

function unescapeHtml(str) {
  const div = document.createElement("div");
  div.innerHTML = str;
  return div.textContent ?? "";
}

const raw = '<script>alert("xss")</script> & "quotes"';
console.log(escapeHtml(raw));
// &lt;script&gt;alert("xss")&lt;/script&gt; &amp; "quotes"
See full JavaScript / Node.js examples →