HTML escape / unescape
Convert special characters into safe HTML entities or decode existing entities back into readable text in a simple browser-based workspace.
About this tool
A browser parsing HTML has no way to tell whether a < in your text was meant as literal punctuation or as the start of a tag. Escaping resolves that ambiguity by replacing the five characters that carry syntactic meaning — <, >, &, " and ' — with entity references such as < and &. The browser renders the entity as the original character but never treats it as markup. This is the mechanism behind cross-site scripting defence: if user-supplied text reaches a page unescaped, a submitted <script> tag becomes executing code rather than displayed text. Context matters as much as the escaping itself. Text between tags, an attribute value inside quotes, an unquoted attribute, and text inside a URL each need different treatment, and escaping designed for one is not sufficient for another. Unescaping runs the other way, turning entities back into readable characters — useful when a value has been double-escaped somewhere in a pipeline and you are staring at &lt; in your output. This tool converts in both directions entirely in your browser.
- 1
Paste your text or HTML into the input field.
- 2
Select Escape to convert special characters to HTML entities, or Unescape to convert entities back to characters.
- 3
The result appears instantly — safe to paste into HTML attributes or templates.
- 4
Click Copy to copy the output.
Escape snippets before rendering user content inside templates or docs.
Decode copied entity strings back into readable HTML or text.
Review how markup-safe content should look before publishing or embedding.
Escape HTML special characters
<script>alert('xss')</script><script>alert('xss')</script>Escape an attribute value
Say "hello" & goodbyeSay "hello" & goodbyeUnescape HTML entities
<h1>Hello & World</h1><h1>Hello & World</h1>Output shows &lt; instead of <
Cause: The text was escaped twice. Each pass converts the & of an existing entity into &, so < becomes &lt;. This usually means a template engine escaped a value that your application code had already escaped.
Fix: Unescape once here to confirm that is what happened, then remove one of the two escaping steps in your code. Most template engines escape by default — the fix is normally to stop escaping manually rather than to mark the value as raw.
Escaped text still executes as script
Cause: Escaping for HTML text content does not make a value safe everywhere. A value dropped into an inline event handler, a <script> block, or an unquoted attribute is parsed by a different grammar, where entity escaping does not neutralise the payload.
Fix: Escape for the context you are writing into: HTML text, quoted attribute, JavaScript string, and URL each need their own encoding. Never interpolate user input into a script block or an unquoted attribute.
Apostrophes come back as ' and break a comparison
Cause: Escaping is not canonical — ', ', and ' are all valid encodings of the same apostrophe, and different libraries pick different ones.
Fix: Compare unescaped values, not escaped ones. If you must store escaped text, escape once with a single library and treat that output as opaque rather than string-matching against it.
These answers explain common html escape/unescape tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.
What does HTML escaping do?
HTML escaping converts characters like <, >, &, quotes, and apostrophes into entity form so they render as text instead of being interpreted as markup.
When should I unescape HTML entities?
Unescape when you have copied encoded content such as <div> or & and you want to inspect the readable text or markup it represents.
Does HTML escaping make content fully secure?
It helps render text safely in HTML contexts, but full security still depends on the exact output context, templating system, and application behavior.
Can I use this tool for code snippets in docs or blogs?
Yes. It is useful for converting markup-heavy snippets into entity form so they display correctly inside documentation, CMS editors, and tutorials.
In browsers, create a temporary DOM element to escape HTML reliably. In Node.js, use a library like he or escape manually.
// Escape using a temporary DOM element (most reliable in browsers)
function escapeHtml(str) {
const div = document.createElement("div");
div.appendChild(document.createTextNode(str));
return div.innerHTML;
}
function unescapeHtml(str) {
const div = document.createElement("div");
div.innerHTML = str;
return div.textContent ?? "";
}
const raw = '<script>alert("xss")</script> & "quotes"';
console.log(escapeHtml(raw));
// <script>alert("xss")</script> & "quotes"See full JavaScript / Node.js examples →