Skip to content
Encoding Runs offline

HTML Encode / Decode

Escape HTML entities to prevent markup injection, or decode them.

Direction

Input

0 chars

Output

0 chars
Ctrl

Questions

Which characters must always be escaped?

In HTML text content, & and < must be escaped. Inside attribute values you additionally need " and ' depending on the quoting style. Escaping all five is the safe default and is what the minimal setting does.

Does escaping HTML make my application safe from XSS?

It is necessary but not sufficient. Escaping protects text and attribute contexts, but content placed inside script blocks, style blocks, event handler attributes or URL attributes needs context-specific handling. Escape at the point of output, in the right context, rather than at input.