Docuboxer
By Sergio Alonzo Piña··5 min read

HTML entities and XSS: what to escape and where

The minimal set of characters to escape, what changes between text, attributes, scripts and URLs, and where escaping alone leaves a gap.

Escaping HTML means replacing the characters a browser would read as markup, <, > and & above all, with entities such as &lt;, &gt; and &amp;. The HTML entities tool encodes and decodes text in your browser without sending it anywhere. Doing this right whenever you insert user text into a page is the first line of defense against cross-site scripting (XSS), the attack that gets a site to run someone else's code.

What problem do entities solve?

In HTML, < opens a tag and & starts an entity. To display the text <p> on screen, rather than get a paragraph, you write &lt;p&gt;. The same goes for a quote inside an attribute or for a space that must not wrap at the end of a line.

The minimal set and the common ones

CharacterNamed entityNumericPurpose
&&amp;&#38;Starts entities, so always escaped
<&lt;&#60;Prevents opening a tag
>&gt;&#62;Closes a tag
"&quot;&#34;Double quote inside an attribute
'&apos;&#39;Single quote inside an attribute
non-breaking space&nbsp;&#160;A space that won't wrap or collapse
é&eacute;&#233;Optional with UTF-8
©&copy;&#169;Optional with UTF-8

On a UTF-8 page you don't need to write accents or symbols as entities: you can type them directly. Only the first five characters in the table are mandatory escapes.

How to use the tool

  1. Open HTML Entities and choose Encode or Decode.
  2. For encoding, pick the scope: Essentials only (& < > " ', the right set for inserting text into HTML) or All non-ASCII, which also encodes accents, symbols and emoji.
  3. Pick the format: named, decimal or hexadecimal.
  4. Paste your text. With <p>Text with "quotes", accents and ñ & more</p>, essentials mode returns &lt;p&gt;Text with &quot;quotes&quot;, accents and ñ &amp; more&lt;/p&gt;.
  5. To decode, the tool accepts named, decimal and hex entities mixed together, with or without the trailing semicolon.

The name table covers the five essentials and the Latin-1 block, which includes accented letters, plus common typographic symbols. It doesn't include the more than two thousand HTML5 entities, so it suits everyday work rather than rare math symbols. When an entity isn't in the table, the tool falls back to the numeric form.

How entities connect to XSS

XSS happens when a site inserts user text into a page without escaping it. If someone submits <script>...</script> as a comment and the page prints it as-is, the browser runs it. If the page turns < and > into &lt; and &gt;, the browser shows harmless text. The OWASP cross-site scripting prevention cheat sheet covers it in depth and separates the cases by where the data lands.

Where HTML escaping isn't enough

The right escaping depends on context:

  • Inside element text: the minimal entities do the job.
  • Inside an attribute: you also need to escape quotes, and to quote the value.
  • Inside a script or event handler (onclick): a different escaping, JavaScript's, is required. The tool has a separate JS and JSON escapes mode that turns line breaks, quotes and accents into sequences such as \n, \" and é.
  • Inside a URL: you need URL encoding, not entities. See URL encoding: what %20 means.

The general rule: escape for the place the data is going, and let your framework do it whenever you can. Frameworks like React escape the text you render by default, and trouble starts when that protection is bypassed on purpose, for example with dangerouslySetInnerHTML.

A safety detail when decoding

Decoding entities sounds harmless, yet the common browser trick, assigning the text to an element and reading back what remains, treats your input as real HTML and can run code. That's why the tool decodes with a lookup table and regular expressions on plain text and never builds page elements from what you type. If pasting text into outside sites worries you, read the privacy risk of online JSON formatters.

Frequently asked questions

What is an HTML entity?

A sequence starting with & and ending with ; that stands for a character, like &amp; for the ampersand or &lt; for the less-than sign. It lets you show characters HTML would otherwise read as code.

Which characters must always be escaped in HTML?

The ampersand, the less-than and greater-than signs, and double or single quotes when they sit inside an attribute. Accents and symbols aren't needed on a UTF-8 page.

What is &nbsp;?

A non-breaking space: a space that doesn't wrap at the end of a line or collapse with other spaces.

Is escaping HTML enough to prevent XSS?

It is the foundation, but it depends on context. Inside a script or a URL a different escaping is needed. The best approach is a framework that escapes by default.

What is the JS and JSON escapes mode for?

For putting text with line breaks, quotes or accents inside a JavaScript or JSON string, turning them into escape sequences.

Is my text sent to a server?

No. Everything happens in your browser.

Encode and decode HTML entities

Essentials only or all non-ASCII, as named, decimal or hex. Runs locally, free, no signup.

Open HTML Entities →

Related tools

You might also like: 13 developer tools that respect your privacy, minify JavaScript, CSS and HTML and Format SQL, HTML and minified code, step by step.