About the HTML Encoder / Decoder
This escapes the characters that have special meaning in HTML — <, >, &, ", ' — into their entity equivalents so they display as literal text instead of being interpreted as markup, and decodes entities back the other way. Developers and writers use it to show code samples on a web page without the browser rendering them, to safely drop user-supplied text into HTML, to fix double-encoded content, or to read what an entity-laden string actually says.
How it works
- Encode replaces the five markup-sensitive characters with their standard entities:
&→&,<→<,>→>,"→",'→'. Doing&first prevents double-escaping the others. - Decode uses the browser's own HTML parser to resolve entities, so it understands not just those five but named entities like
©and and numeric ones like—, turning them back into the real characters.
Both run live as you type.
Assumptions and behaviour
- Encoding targets the five special characters that matter for HTML safety and display; ordinary letters, digits, punctuation and non-ASCII text are left as-is (they don't need escaping in a UTF-8 page).
- Decoding is browser-powered, so it handles the full range of named and numeric HTML entities, not just the five the encoder produces.
- Escaping both quote types (
"and') makes the output safe to place inside HTML attribute values as well as body text.
Limitations
- Encoding doesn't convert non-ASCII to numeric entities. Accented letters and emoji are left as literal characters, which is correct for a UTF-8 page but not what you'd want if you specifically need an ASCII-only, fully-entity-encoded output.
- It's HTML escaping, not sanitisation. Escaping makes text safe to display; it does not clean or validate a block of HTML you intend to render as markup.
- Decoding interprets any entity it recognises, so partial or malformed entities may resolve in ways the browser deems reasonable rather than erroring.
Privacy
Encoding and decoding run entirely in your browser. Your text is never uploaded or stored.

