What this tool does
Encode or decode a limited set of HTML character references. Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.
How to use HTML Entity Converter
- Prepare the input. Choose Encode or Decode.
- Run or configure the tool. Paste text and select Convert.
- Check and use the output. Use the result only in the intended text context and check unsupported entities.
How this tool works
Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.
Worked example
Input: Encode <b>&</b>
Output: <b>&</b>
Limits, assumptions and interpretation
This does not implement the complete HTML named-entity list or hexadecimal numeric references.
- Supplementary Unicode characters are treated as UTF-16 units rather than full code points.
- Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls.
- Decoded text should not be inserted as executable untrusted HTML.
Supported inputs and limits
- Encode <b>&</b>
- This does not implement the complete HTML named-entity list or hexadecimal numeric references.
- Supplementary Unicode characters are treated as UTF-16 units rather than full code points.
- Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls.
- Decoded text should not be inserted as executable untrusted HTML.
Frequently asked questions
What does this tool actually do?
Encoding replaces &, <, >, quotes and apostrophes, then non-ASCII UTF-16 code units with decimal references. Decoding supports those five common references and decimal numeric references using String.fromCharCode.
What should I check before using the result?
This does not implement the complete HTML named-entity list or hexadecimal numeric references. Supplementary Unicode characters are treated as UTF-16 units rather than full code points. Encoding alone is not a universal XSS defense: HTML, attribute, URL, CSS and script contexts need different controls. Decoded text should not be inserted as executable untrusted HTML.
Is information sent to a server?
Tool inputs are processed in this browser. This product does not use analytics or send your input to an external API. Clicking an external website link still visits that website.