OpusDesk Hub Tools

HTML Entity Converter

Encode or decode a limited set of HTML character references.

What this tool does

Encode or decode a limited set of HTML character references. Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.

How to use HTML Entity Converter

  1. Prepare the input. Choose Encode or Decode.
  2. Run or configure the tool. Paste text and select Convert.
  3. Check and use the output. Use the result only in the intended text context and check unsupported entities.

How this tool works

Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.

Worked example

Input: Encode <b>&</b>

Output: &lt;b&gt;&amp;&lt;/b&gt;

Limits, assumptions and interpretation

This does not implement the complete HTML named-entity list or hexadecimal numeric references.

  • Supplementary Unicode characters are treated as UTF-16 units rather than full code points.
  • Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls.
  • Decoded text should not be inserted as executable untrusted HTML.

Supported inputs and limits

  • Encode <b>&</b>
  • This does not implement the complete HTML named-entity list or hexadecimal numeric references.
  • Supplementary Unicode characters are treated as UTF-16 units rather than full code points.
  • Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls.
  • Decoded text should not be inserted as executable untrusted HTML.

Frequently asked questions

What does this tool actually do?

Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.

What should I check before using the result?

This does not implement the complete HTML named-entity list or hexadecimal numeric references. Supplementary Unicode characters are treated as UTF-16 units rather than full code points. Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls. Decoded text should not be inserted as executable untrusted HTML.

Is information sent to a server?

Tool inputs are processed in this browser. This product does not use analytics or send your input to an external API. Clicking an external website link still visits that website.

Related tools