Modes
- Encode — escapes only the five characters that matter for HTML safety: & < > " '.
- Encode all — also converts symbols (©, €, —) and every non-ASCII character to named or numeric entities.
- Decode — turns any named (©), decimal (©) or hex (©) entity back into the character.
Common entities
| Character | Entity |
|---|---|
| < | < |
| > | > |
| & | & |
| " | " |
| non-breaking space | |
Escaping user input before putting it in HTML prevents cross-site scripting (XSS). For URLs, use the URL Encoder / Decoder instead.
Frequently asked questions
Do I need entities for accented letters?
Not on UTF-8 pages; é and ü can be written directly. Use "Encode all" only for ASCII-only systems.
What is the difference between © and ©?
Both produce ©. One is numeric, the other named; browsers treat them the same.
Is this the same as URL encoding?
No. URL encoding uses %20-style codes for URLs; HTML entities are for HTML content.

