Skip to content
Technology·1 min read·

HTML entity encoder

Encode less-than, greater-than, ampersand, and quotes as HTML entities, or decode entities back to characters.

The answer

Encoding replaces the ampersand, less-than, greater-than, double quote, and apostrophe so they show as text instead of markup. Decoding reads common named entities and numeric character references.

Result

Encoded text

<em>

What do you want to do next?

How this works

The encoder touches only the five characters that start markup or quotes. It does not wrap the text in a tag and it does not encode letters.

The decoder knows the common named entities, including amp, lt, gt, quot, apos, nbsp, copy, and mdash, plus decimal and hexadecimal numeric references. An unknown name is left as written.

Practical steps

  1. 1

    Choose encode when the text will be placed in HTML.

  2. 2

    Choose decode when you already have entities and want the characters.

  3. 3

    Encode before you insert the text. Decoding user HTML does not make it safe to inject as markup.

Examples

  • A less-than sign

    The less-than sign becomes the lt entity, so a tag shows as text instead of markup.

Common mistakes

  • ×

    Decoding untrusted HTML and then inserting the result as live markup.

Frequently asked questions

Does encoding make a full HTML document safe?

It makes this text safe to show as text. It is not a sanitizer for a document you intend to render as HTML.

Is   decoded?

Yes. It becomes a non-breaking space.