Escape HTML Entities

–
CharacterEntityWhy it needs escaping
&&opens every entity - must go first
<&lt;starts a tag
>&gt;ends a tag
"&quot;delimits attribute values
'&#39;delimits single-quoted attributes
Only these five characters change; accents, emoji and spaces pass through. Unescaped text from an unknown source is how injected scripts start - escaping is the boundary that makes pasted content inert text instead of live markup.
The reverse direction (entities back to characters) is unescaping - if your page shows entities as plain text, the content was escaped twice. Same family: strip HTML removes markup entirely, the find and replace tool fixes repeated words, and remove line breaks unwraps pasted PDFs.

Paste text and the five characters HTML treats as instructions - ampersand, less-than, greater-than, double quote, apostrophe - come out as safe entities: &amp; &lt; &gt; &quot; &#39;. The escaped result displays on any web page exactly as typed, which is the whole trick behind every site that shows code, math with angle brackets, or user comments without letting them break the layout.

The direction confuses people at first: you are not adding junk, you are writing the characters HTML reads instead of the characters it acts on. Unescaped, a pasted snippet that starts with a tag becomes a real element on your page - and text from an unknown source is exactly how injected scripts start. Escaped, the same snippet is inert text that renders as itself. This converter escapes as you type, entirely in your browser.

How to use

  1. Paste the text or snippet that needs to display as-is.
  2. Read the escaped version live - only the five instruction characters change, everything else passes through.
  3. Copy the entities into your HTML, CMS field or template where the text must render literally.

Frequently asked questions

Which characters does HTML escaping change?

Five: & becomes &amp;amp;, < becomes &amp;lt;, > becomes &amp;gt;, the double quote becomes &amp;quot;, and the apostrophe becomes &amp;#39;. The ampersand is the keystone - it opens every entity, so it must be escaped or the rest read as broken entities. Everything else (accents, emoji, spaces) is already legal text and passes through untouched.

When do I actually need to escape HTML?

Whenever text will appear inside a web page but is not meant to be HTML: code samples, XML or math with angle brackets (a < b), user comments, and any data whose content you cannot vouch for. The security framing matters more than the cosmetic one: escaping untrusted text before it enters a page is the primary defense against cross-site scripting - a pasted script tag that gets escaped renders as harmless text instead of running.

How do I unescape HTML entities back to text?

Reverse the map - &amp;amp; back to &, &amp;lt; back to < - which is what HTML source usually needs before it reads naturally. This tool escapes only. A tell that text was escaped twice: you see &amp;amp;amp; rendering as &amp;amp; on the page. Escape once, at the boundary where untrusted text enters, and never manually re-escape already-escaped output.

Does escaping change what search engines see?

The entities are the content: &amp;lt;b&amp;gt; displays as <b> to every reader and crawler - it is text, not markup, so it carries no formatting and no ranking weight. That is exactly right for showing code, and exactly wrong for emphasizing real content: escape what should be read as characters, write real tags for what should render. Mixing them up in either direction is the classic CMS mistake.

Related tools