Formats
- JSON / JavaScript — quotes, backslashes, new lines, tabs.
- HTML / XML — &, <, >, quotes as entities.
- SQL — doubles single quotes. Always prefer prepared statements in real code.
- CSV — wraps fields that contain commas, quotes or line breaks.
- Regex — escapes . * + ? ^ $ { } ( ) | [ ] \ /.
- Shell — safe single-quoted string.
Frequently asked questions
Is escaping the same as encoding?
Related: URL encoding uses %XX codes — use the URL Encoder for that.
Does SQL escaping prevent injection?
It helps, but parameterised queries are the correct protection.
Is my text uploaded?
No.

