HTML Escape / Unescape
- Pick a mode: escape or unescape.
- Paste or type your text.
- The result updates as you type and can be copied directly.
Escaping converts & to &, < to <, > to >, double quotes to " and single quotes to '.
It is exactly those five because they carry structural meaning in HTML. The < opens a tag, quotes delimit attribute values, and & begins an entity itself.
The & must be converted first. Escaping in the wrong order would turn < into &lt;, corrupting the result — a classic bug in hand-rolled implementations.
When unescaping, beyond those entities the tool recognises , ', numeric entities such as é and hexadecimal ones such as 😀.
Inserting user-supplied text straight into HTML without escaping is the origin of XSS. A comment containing a script tag becomes executable code on the page of whoever reads it.
Escaping turns that text into inert content: the browser displays the characters instead of interpreting them.
An important caveat: escaping for HTML does not protect in every context. Inside an event attribute, a URL or a JavaScript block, the escaping rules differ. The robust solution is to use your framework API, which already handles this, or a sanitisation library.
- Displaying a snippet of HTML inside a page without it being rendered.
- Investigating why text shows a visible &lt; on screen — a sign of double escaping.
- Preparing content for a field that does not escape on its own.
- Recovering the original text from already-escaped HTML.
Frequently asked questions
It is double escaping: the text was escaped twice. The & of the original < became &. Unescaping once here returns the correct value.
In the context of element content, yes. Inside an event attribute, a URL or a JavaScript block, no — each context needs its own escaping. Use your framework API or a sanitisation library.
Because ' is not part of HTML 4 and some older parsers do not recognise it. The numeric form ' works everywhere.
A space that does not break the line. It is useful to keep two words together, but scattered through text it is usually a leftover from content pasted out of an editor.
No. The conversion happens in your browser.