Why HTML entities exist — and the one place most developers get them wrong
HTML has a small set of reserved characters: <, >, &, and " are the main ones. When these appear in page content, the browser tries to parse them as markup. Entity encoding replaces them with safe representations — < for <, & for &, and so on — so the browser renders them as visible text rather than interpreting them as tags. This is how you show code examples on a webpage without the HTML collapsing on itself.
The place developers most often forget entity encoding is inside HTML attribute values. Encoding content between tags is well-understood — most frameworks handle it automatically. But attributes are different. If you're building a title or href attribute dynamically and a user-supplied value contains a quote character, that character can break out of the attribute context and become a vector for injection. The fix is encoding. Named entities like < are more readable; numeric entities like < work in more contexts including XML. Either is correct for HTML.
