Skip to content

HTML Entity Encode

Escape characters that break HTML — &, <, >, quotes — with named or numeric entities.

Input

Output

Escaping characters that break HTML

Five characters change the meaning of HTML: &, <, >, " and '. Writing them as entities tells the browser to display the character rather than treat it as markup — which is also the baseline defence against cross-site scripting when user input ends up in a page.

Numeric references (&#38; or &#x26;) mean the same thing as named ones and work in every parser, which makes them the safer choice when the output will be consumed by something other than a browser.

Frequently asked questions

Does escaping make my page safe from XSS?

It is necessary but not sufficient. Escaping for HTML text is different from escaping inside an attribute, a URL, or a <script> block. Use the escaping that matches the context the value lands in.

Why is &nbsp; not a normal space?

It is U+00A0, a non-breaking space. It looks identical but prevents a line break and is not collapsed with adjacent whitespace.

Related tools