BasicApps Logo
HTML Entities Encoder/Decoder

Encode and decode HTML entities for safe text display in web pages and prevent XSS attacks

Text to Encode

Characters: 0 | Bytes: 0

XSS Prevention

• < >: Prevent script injection
• &: Avoid entity confusion
• " ': Secure attribute values
• Always encode: User input content
• Context matters: HTML vs attributes

Named Entities

• Readable: &copy; vs ©
• Standard: HTML5 specification
• Limited: ~2000 predefined entities
• Best for: Common symbols
• Fallback: Use numeric for others

Numeric Entities

• Universal: Any Unicode character
• Decimal: € (Euro symbol)
• Hex: € (Euro symbol)
• Range: 0 to 1,114,111 (Unicode)
• Use when: No named equivalent

Why HTML entities exist — and the one place most developers get them wrong

HTML has a small set of reserved characters: <, >, &, and " are the main ones. When these appear in page content, the browser tries to parse them as markup. Entity encoding replaces them with safe representations — &lt; for <, &amp; for &, and so on — so the browser renders them as visible text rather than interpreting them as tags. This is how you show code examples on a webpage without the HTML collapsing on itself.

The place developers most often forget entity encoding is inside HTML attribute values. Encoding content between tags is well-understood — most frameworks handle it automatically. But attributes are different. If you're building a title or href attribute dynamically and a user-supplied value contains a quote character, that character can break out of the attribute context and become a vector for injection. The fix is encoding. Named entities like &lt; are more readable; numeric entities like &#60; work in more contexts including XML. Either is correct for HTML.