HTML Entity Encoder/Decoder
Convert special characters to HTML entities and back. Keep your web content safe and display characters correctly.
Common HTML Entities Reference
| Character | Named Entity | Numeric Entity | Description |
|---|---|---|---|
| & | & | & | Ampersand |
| < | < | < | Less than |
| > | > | > | Greater than |
| " | " | " | Double quote |
| ' | ' | ' | Single quote / Apostrophe |
|   | Non-breaking space | |
| © | © | © | Copyright |
| ® | ® | ® | Registered trademark |
| ™ | ™ | ™ | Trademark |
| € | € | € | Euro sign |
| £ | £ | £ | Pound sign |
| ¥ | ¥ | ¥ | Yen sign |
| ¢ | ¢ | ¢ | Cent sign |
| § | § | § | Section sign |
| ¶ | ¶ | ¶ | Paragraph sign |
| ° | ° | ° | Degree sign |
| ± | ± | ± | Plus-minus sign |
| · | · | · | Middle dot |
| • | • | • | Bullet |
| … | … | … | Horizontal ellipsis |
| – | – | – | En dash |
| — | — | — | Em dash |
| « | « | « | Left double angle quote |
| » | » | » | Right double angle quote |
About HTML Entity Encoder
HTML entities are special codes used to represent characters that have reserved meaning in HTML or cannot be easily typed on a keyboard. When a browser encounters characters like <, >, or & in your HTML source, it interprets them as part of the markup rather than as literal text. HTML entity encoding replaces these characters with safe entity references such as <, >, and &, ensuring they display correctly on the page without being parsed as HTML code.
Entity encoding is a critical part of web security. Cross-Site Scripting (XSS) attacks exploit situations where user-supplied input is rendered as raw HTML. By encoding special characters before inserting them into a page, you prevent malicious scripts from executing in users' browsers. Every web application that displays user-generated content should encode HTML entities as a fundamental defense layer against injection attacks.
Named vs Numeric Entities
HTML supports two forms of entity references. Named entities use a human-readable name, such as & for the ampersand or © for the copyright symbol. They are easier to read in source code but limited to a predefined set of characters. Numeric entities use the character's Unicode code point, written as & (decimal) or & (hexadecimal). Numeric entities can represent any Unicode character, making them more versatile when you need to encode characters beyond the standard named set.
When to Use HTML Entity Encoding
You should encode HTML entities when displaying user input in web pages, embedding special characters in HTML attributes, including symbols not available on standard keyboards, or ensuring consistent rendering across different browsers and character encodings. This tool performs all encoding and decoding entirely in your browser -- no data is sent to any server, ensuring complete privacy for your content.
FAQ
Q: What is the difference between HTML encoding and URL encoding?
A: HTML encoding converts characters to HTML entity references (like &) for safe display within HTML documents. URL encoding converts characters to percent-encoded format (like %26) for safe inclusion in URLs. They serve different purposes: HTML encoding protects the structure of your web page markup, while URL encoding ensures data is transmitted correctly within URLs.
Q: Does HTML entity encoding prevent all XSS attacks?
A: HTML entity encoding is an essential defense against XSS but is not sufficient on its own. It effectively prevents injection in HTML text content and attribute values. However, you also need context-aware encoding for JavaScript strings, CSS values, and URL parameters. A comprehensive security strategy combines entity encoding with Content Security Policy headers and input validation.
Q: Should I encode all characters or only special ones?
A: For most use cases, encoding only the five critical HTML characters (&, <, >, ", ') is sufficient. Encoding all characters to numeric entities can be useful when you need to ensure compatibility with legacy systems, avoid character encoding issues, or obfuscate content. However, it significantly increases the size of your HTML output.
Q: Is my data safe when using this tool?
A: Yes, completely. This tool runs entirely in your browser using JavaScript. No data is transmitted to any server. Your input text and the encoded or decoded output never leave your device. You can verify this by monitoring your browser's network tab while using the tool.
Q: What characters must always be encoded in HTML?
A: The five characters that must always be encoded are: ampersand (&), less-than sign (<), greater-than sign (>), double quote ("), and single quote/apostrophe ('). These characters have special meaning in HTML syntax and will break your markup or create security vulnerabilities if left unencoded in user-generated content.