HTML escape / unescape

Escape text for HTML or unescape character references in your browser. Encodes & < > " and ' for text nodes; decodes named and numeric references.

How it works
  • Escapes & < > " and ' for HTML text nodes. This is not a full XSS sanitizer for attributes or scripts.

Escapes & < > " and ' for HTML text nodes. This is not a full XSS sanitizer for attributes or scripts.

About HTML escaping

What is HTML escaping?

HTML escaping replaces characters that have special meaning in HTML so they render as text instead of markup. This page encodes & < > " and ' to &amp; &lt; &gt; &quot; and &#39;.

Unescape reverses that: it decodes named references amp, lt, gt, quot, and apos, plus numeric references such as &#39; and &#x27;. Work happens in your browser. Escaping text nodes is not a substitute for context-aware encoding or an XSS sanitizer.

Escape and unescape in code

JavaScript
text.replace(/&/g, "&amp;")
    .replace(/</g, "&lt;")
    .replace(/>/g, "&gt;")
    .replace(/"/g, "&quot;")
    .replace(/'/g, "&#39;")
Python
html.escape(text, quote=True)
html.unescape(text)
Entities
&  &amp;
<  &lt;
>  &gt;
"  &quot;
'  &#39;

HTML escape FAQ

What is HTML escape?
HTML escaping encodes characters that would otherwise be treated as markup. This page turns & < > " and ' into &amp; &lt; &gt; &quot; and &#39; so they display as text.
What is HTML unescape?
HTML unescape decodes character references back to text. Named amp, lt, gt, quot, and apos are supported, as are decimal and hexadecimal numeric references.
Does HTML escape prevent XSS?
No. Escaping those five characters is enough for HTML text nodes, but attributes, URLs, and scripts need context-aware encoding. This is not a sanitizer.
How do I HTML-escape a string in code?
In JavaScript replace & < > " and ' with their entities. In Python use html.escape(text, quote=True) and html.unescape(text).