Encode special characters to HTML entities and decode entities back to text online. Handles & < > quotes, named and numeric entities.
| Input | Output |
|---|---|
| <p class='x'>Hi</p> | <p class='x'>Hi</p> |
| Hi A | decodes to: Hi A |
| &lt; | decodes one level to: < |
At minimum & and < in text content, plus double quotes inside attribute values. Encoding > and single quotes too is harmless and common practice — it keeps templates readable and avoids edge cases in older parsers.
Because every other entity starts with &. If you encoded < first, the < it produces would then have its & re-encoded into &lt; — showing literally < on the page. Order matters: & always goes first when encoding, last when decoding.
For the five reserved characters both work everywhere (< = <). Named entities are easier to read; numeric ones cover every Unicode point, including characters with no name. This tool decodes both.
Encoding text makes it display as text instead of markup, which stops injection through that text. It is not a full sanitizer: if you need to allow some tags from users, use a real allowlist sanitizer like DOMPurify instead.