HTML encoder and decoder

Convert HTML-sensitive characters to numeric character references, or decode HTML entities and markup to plain text.

Encoding and decoding

Link

Encoding converts characters such as <, >, &, quotes, and non-ASCII characters to decimal references. For example, <h1> becomes &#60;h1&#62;, so it displays as text when inserted into an HTML text node. Decoding uses the browser’s HTML parser and returns text content. Named entities such as &amp; and numeric references are decoded. Markup itself is removed, so <strong>Hello</strong> becomes Hello. &nbsp; becomes a non-breaking space, which may look like an ordinary space but behaves differently during wrapping.

Security boundary

Link

Encoding is useful when displaying text in an HTML text context, but it is not general input validation or complete XSS protection. HTML attributes, URLs, CSS, and JavaScript strings have different escaping rules. Applications should use their framework’s contextual escaping and a vetted sanitizer when HTML markup must be allowed. Do not decode untrusted input and then insert the result as HTML.

Privacy and storage

Link

Processing happens in your browser. The input and selected action are saved in localStorage and remain after a reload. Clear them after handling sensitive content on a shared device.

Link

Widget made with staark