What is HTML escaping?
In HTML, < starts a tag and & starts a character reference. To display these characters literally — or to put user input into a page safely — you replace them with character references (often called HTML entities). This is HTML escaping. The browser shows the original character, but the parser no longer treats it as markup.
| Character | Named entity | Numeric reference |
|---|---|---|
& | & | & |
< | < | < |
> | > | > |
" | " | " |
' | ' | ' |
| © | © | © / © |
For example, <a href="x">Tom & Jerry's</a> escapes to <a href="x">Tom & Jerry's</a>. With the non-ASCII option, café 😀 becomes café 😀.
When to use it
- Showing HTML or XML source code in a blog post or documentation
- Fixing symbols that break in email templates or a CMS
- Checking that user input is correctly escaped as part of XSS (cross-site scripting) testing
- Turning scraped text full of
&and"back into readable text
Escaping in code
| Language | Escape | Unescape |
|---|---|---|
| Python | html.escape(s) | html.unescape(s) |
| PHP | htmlspecialchars($s, ENT_QUOTES) | html_entity_decode($s) |
| Java | StringEscapeUtils.escapeHtml4(s) (Apache Commons Text) | StringEscapeUtils.unescapeHtml4(s) |
| Go | html.EscapeString(s) | html.UnescapeString(s) |
| JavaScript | set element.textContent instead of innerHTML | new DOMParser().parseFromString(s, 'text/html').documentElement.textContent |
Most template engines (React JSX, Jinja2, Blade, Thymeleaf, Go's html/template) escape output automatically, so manual escaping is usually needed only when you build HTML strings yourself.
What unescape supports
Unescaping handles every named entity the browser knows ( , ©, … …), decimal references such as © and hexadecimal references such as ©. It is decoded once, so &amp; becomes & — use “Use result as input” to decode double-escaped text again.
Frequently asked questions
Why is the single quote escaped as ' instead of '?
' is not defined in HTML 4, so some older browsers and email clients do not recognize it. The numeric reference ' works everywhere.
Is HTML escaping enough to prevent XSS?
Escaping is the core defense for text inside HTML elements and quoted attribute values. Other contexts need different handling: javascript: URLs in href, data written inside <script> or event handler attributes, and CSS.
Which entities can be unescaped?
All named entities such as and ©, decimal references such as ©, and hexadecimal references such as ©.
Is my input sent anywhere?
No. The conversion runs entirely in your browser; nothing you type is uploaded or stored.