Skip to content
UniKit

HTML entity escaper

Escape and unescape HTML entities online: 250+ named entities, decimal and hex numeric references, minimal or full non-ASCII escaping, and an option to keep existing entities.

Runs in your browserEvery computation happens in your browser — your data never leaves this device.

Result

Named entity lookup

ÆÆU+00C6
ÁÁU+00C1
ÂÂU+00C2
ÀÀU+00C0
ΑΑU+0391
ÅÅU+00C5
ÃÃU+00C3
ÄÄU+00C4
ΒΒU+0392
ÇÇU+00C7
ΧΧU+03A7
‡‡U+2021
ΔΔU+0394
ÐÐU+00D0
ÉÉU+00C9
ÊÊU+00CA
ÈÈU+00C8
ΕΕU+0395
ΗΗU+0397
ËËU+00CB
ΓΓU+0393
^^U+005E
ÍÍU+00CD
ÎÎU+00CE
ÌÌU+00CC
ΙΙU+0399
ÏÏU+00CF
ΚΚU+039A
ΛΛU+039B
ΜΜU+039C

 U+000A
ÑÑU+00D1
ΝΝU+039D
ŒŒU+0152
ÓÓU+00D3
ÔÔU+00D4
ÒÒU+00D2
ΩΩU+03A9
ΟΟU+039F
ØØU+00D8
ÕÕU+00D5
ÖÖU+00D6
ΦΦU+03A6
ΠΠU+03A0
″″U+2033
ΨΨU+03A8
ΡΡU+03A1
ŠŠU+0160
ΣΣU+03A3
ÞÞU+00DE
	 U+0009
ΤΤU+03A4
ΘΘU+0398
ÚÚU+00DA
ÛÛU+00DB
ÙÙU+00D9
ΥΥU+03A5
ÜÜU+00DC
ΞΞU+039E
ÝÝU+00DD

What this tool does

  • Escape & < > and quotes before injecting user input or database text into an HTML page so it cannot break out as markup.
  • Decode the &nbsp;, &#x4F60; and &mdash; references in someone else’s markup to see what characters they actually mean.
  • Generate XML, RSS or email templates with every non-ASCII character turned into a numeric reference, safe for systems that only accept ASCII.
  • Debug string concatenation: keeping existing entities lets you re-run escaping on text that is already partly escaped without double-encoding it.

Example

Input

<a href="x">Tom & Jerry</a>

Output

&lt;a href=&quot;x&quot;&gt;Tom &amp; Jerry&lt;/a&gt;

The default "special characters" range escapes & < > and both quote characters, leaving everything else — including Chinese text — untouched. Switch the range to "all non-ASCII" to escape those too.

Frequently asked questions

Why is my Chinese text not escaped?

The default special-character range only touches & < > and the quote characters, which are the ones that can break the document structure. Chinese is perfectly safe in a UTF-8 page; choose the "all non-ASCII" range if you want every character as a numeric reference.

How do I stop &amp; from becoming &amp;amp;?

Turn on "keep existing entities". The escaper then recognises &amp;, &copy;, &#169; and &#xA9; style references and copies them through untouched. With the option off, & is treated as a plain character — which is exactly what standard escaping does.

What is the difference between named, decimal and hex references?

They render identically, only the spelling differs. Named entities (&copy;) read best but the set is limited; decimal (&#169;) has the widest support; hex (&#xA9;) is common in XML and older editors. Characters without a named entity automatically fall back to decimal.

What happens if I unescape &#0; or &#xD800;?

You get an error, because U+0000 and the surrogate range (U+D800–U+DFFF) are not valid Unicode scalar values and cannot become characters. Unrecognised references such as a misspelled &foo; are left exactly as they are.

How many named entities are included?

281 common WHATWG entities covering Latin and Greek letters, maths symbols, arrows, currency and punctuation. The full HTML5 list has over 2000 entries, so obscure ones are missing here — use a numeric reference instead.

Keywords:html entitieshtml 实体escapeunescape转义反转义&amp;&nbsp;html encodehtml decode

Related tools