- What does HTML encoding do?
- It replaces characters that have special meaning in HTML with entities, so they display as literal text instead of being interpreted as markup. The five that always matter are the ampersand, the two angle brackets, and both quote characters; this tool converts them to &, <, >, ", and '.
- When do I need to escape HTML?
- Whenever text that is not meant to be markup ends up inside a page: user-generated content, code samples, text placed into attributes, or HTML snippets shown as examples. Escaping user content before rendering is the standard defense against cross-site scripting (XSS), because injected tags and scripts become harmless visible text.
- What is the difference between ' and '?
- Both represent the single quote. ' is guaranteed in XML and modern HTML5 but was missing from HTML 4, so very old parsers may not understand it. The numeric form ' works everywhere, which is why this tool emits it when encoding.
- Named or numeric entities: which should I use?
- They decode to the same characters. Named entities like é are easier for people to read; numeric ones like é (decimal) or é (hex) work for every Unicode character including those without a name. When this tool encodes non-ASCII text it uses numeric entities because they are universally valid.
- Does this tool decode every named entity?
- Yes. Instead of shipping a fixed entity list, it asks your browser's own HTML parser to resolve each named entity, so everything in the WHATWG standard is supported, from & to … to obscure math symbols. Unknown names are left unchanged, matching real browser behavior.
- Is my text sent to a server?
- No. Encoding and decoding run entirely in your browser with JavaScript. You can load the page, disconnect from the internet, and keep working.