HTML Escape / Unescape

Convert HTML special characters such as < > & into entities like &lt;, or decode entities back into plain text. Everything runs in your browser.

What is HTML escaping?

In HTML, < starts a tag and & starts a character reference. To display these characters literally — or to put user input into a page safely — you replace them with character references (often called HTML entities). This is HTML escaping. The browser shows the original character, but the parser no longer treats it as markup.

CharacterNamed entityNumeric reference
&&amp;&#38;
<&lt;&#60;
>&gt;&#62;
"&quot;&#34;
'&apos;&#39;
© &copy;&#169; / &#xA9;

For example, <a href="x">Tom & Jerry's</a> escapes to &lt;a href=&quot;x&quot;&gt;Tom &amp; Jerry&#39;s&lt;/a&gt;. With the non-ASCII option, café 😀 becomes caf&#xE9; &#x1F600;.

When to use it

  • Showing HTML or XML source code in a blog post or documentation
  • Fixing symbols that break in email templates or a CMS
  • Checking that user input is correctly escaped as part of XSS (cross-site scripting) testing
  • Turning scraped text full of &amp; and &quot; back into readable text

Escaping in code

LanguageEscapeUnescape
Pythonhtml.escape(s)html.unescape(s)
PHPhtmlspecialchars($s, ENT_QUOTES)html_entity_decode($s)
JavaStringEscapeUtils.escapeHtml4(s) (Apache Commons Text)StringEscapeUtils.unescapeHtml4(s)
Gohtml.EscapeString(s)html.UnescapeString(s)
JavaScriptset element.textContent instead of innerHTMLnew DOMParser().parseFromString(s, 'text/html').documentElement.textContent

Most template engines (React JSX, Jinja2, Blade, Thymeleaf, Go's html/template) escape output automatically, so manual escaping is usually needed only when you build HTML strings yourself.

What unescape supports

Unescaping handles every named entity the browser knows (&nbsp;, &copy;, &hellip; …), decimal references such as &#169; and hexadecimal references such as &#xA9;. It is decoded once, so &amp;amp; becomes &amp; — use “Use result as input” to decode double-escaped text again.

Frequently asked questions

Why is the single quote escaped as &#39; instead of &apos;?

&apos; is not defined in HTML 4, so some older browsers and email clients do not recognize it. The numeric reference &#39; works everywhere.

Is HTML escaping enough to prevent XSS?

Escaping is the core defense for text inside HTML elements and quoted attribute values. Other contexts need different handling: javascript: URLs in href, data written inside <script> or event handler attributes, and CSS.

Which entities can be unescaped?

All named entities such as &nbsp; and &copy;, decimal references such as &#169;, and hexadecimal references such as &#xA9;.

Is my input sent anywhere?

No. The conversion runs entirely in your browser; nothing you type is uploaded or stored.