Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Security Tools New Tool

Free Online HTML, JavaScript and XML Escape and Unescape

Escape text so it cannot break out of HTML, a JavaScript string or an XML document, and unescape it again. Each language gets its own rules: HTML entities named or numeric, JavaScript backslash sequences including the script tag trap, and the five entities XML actually defines. Nothing is uploaded.

Free Forever Nothing Uploaded Three Languages Runs in your browser
Free Online HTML, JavaScript and XML Escape and Unescape
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
Escape & Unescape Everything happens in this tab. Nothing you paste is sent anywhere.
Your text
Result
Where it goes
HTML
JavaScript
XML

0 characters in 0 out 0 replaced

Reference Click a row to put it in the input box.
Character Name Decimal Hex What it is

Nothing in the table matches that.

Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

Why This Page Does Not Unescape With innerHTML

The one-line trick that turns an unescaper into a hole.

There is a well known shortcut for unescaping HTML entities in a browser: make an element, set its innerHTML to the text, and read back textContent. It is three lines and it handles every entity the browser knows, which is all of them. It is also an XSS hole the moment the text is not yours.

The reason is that innerHTML does not decode a string, it parses HTML. Give it <img src=x onerror=alert(1)> and the browser builds an image element, tries to load x, fails, and runs the handler. Script tags inserted that way do not run, which is what makes people think the trick is safe, but event handlers on other elements do, and so do a dozen other constructions. On a page where the input is pasted by the person using it the damage is limited to themselves; in a shared component, or anywhere the text arrived from a URL, a database or another user, it is a real vulnerability.

So the unescaping here is done the long way: a table of names to code points, written into the page, and a scan that replaces one reference at a time. It costs a few hundred lines and it cannot run anything, because nothing is ever handed to the HTML parser. Use DOMParser with text/html if you need the browser's own table in your own code, and never innerHTML on text you did not write.

How to Escape Text for HTML, JavaScript or XML

A few steps, and nothing is uploaded.

1
Say where the text is going HTML, a JavaScript string, or an XML document. The three have different rules, and escaping for one of them is not escaping for another.
2
Pick a direction Escape text so it cannot break out, or unescape it back to what it was. The page runs as you type, with no button to press.
3
Choose how much to escape In HTML, only the five that matter is right almost always. In JavaScript, say which quote the string sits in. In XML, decide whether anything outside ASCII becomes a numeric reference.
4
Use the table, on the HTML side Search the entities people actually look up, by name, by number or by description, and click a row to drop it into the input box.

What to Know About Escaping

Including why unescaping with innerHTML is a bad idea.

Unescaping here is done from a table, not by setting innerHTML. The usual three-line trick, assigning text to an element's innerHTML and reading textContent, hands untrusted text to the HTML parser. <img src=x onerror=...> runs code that way, which is how a decoder becomes an XSS hole. Nothing on this page is ever parsed as HTML.
In a JavaScript string the quotes are not the dangerous part; the closing script tag is. The HTML parser looks for </script inside a script element whether or not it is in the middle of a string, and ends the script there. So data that contains that text, escaped perfectly for JavaScript, still breaks the page and can inject markup. Writing it with a backslash in the middle means the same thing to JavaScript and nothing to the HTML parser, which is what the switch on this page does.
XML has five named entities and that is all, so HTML pasted into XML usually fails to load. There is no &nbsp; in XML, nor any of the other 247 names HTML 4 defined. An XML parser meeting an unknown entity does not ignore it, it refuses the whole document, which is why one copied line can make an entire feed or configuration file unreadable. Unescaping here names the ones XML will not accept instead of silently fixing them.
Escaping cannot make unsafe markup safe on its own, and the context decides the rules. Escaping the five characters is the right defence for text placed in element content or in a quoted attribute. It does nothing for text put into a URL, into a style block or into an unquoted attribute, where the rules are different again and escaping the wrong characters gives you false confidence. That is the reason this page asks where the text is going instead of offering one escape button.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

Three languages HTML entities, JavaScript backslash escapes, and the five XML entities.
The script tag trap A closing script tag and an HTML comment are broken up, which quotes alone do not fix.
Unescapes all the forms Named, decimal and hex references, and JavaScript x, u and brace escapes.
No innerHTML anywhere Unescaping runs off a table in the page, so nothing can execute.
A reference you can search The entities people look up, with character, name, decimal and hex.
Runs in your browser Nothing is uploaded. The page works with the network off.

About Escaping and Unescaping

Escaping is what keeps text as text. A few characters mean something to whatever is going to read the string next, and if they are passed through untouched the reader stops treating them as content and starts treating them as structure. That is the whole of how cross site scripting works, and it is also why a single apostrophe in a surname can break a page that has worked for years. The fix is never to remove the character; it is to write it in the form that particular reader understands.

Which form depends entirely on who is reading. HTML wants entities, and in practice wants five of them. A JavaScript string wants backslash escapes, and it also wants the closing script tag broken up, which has nothing to do with JavaScript at all and everything to do with the HTML parser that gets there first. XML wants entities too, but it defines only five names and refuses a document containing any other, so text that is perfect HTML is often unusable XML. One escape button cannot serve all three, which is why this page asks where the text is going.

The unescaping is the part that took care, and not because the formats are hard. The obvious way to decode HTML entities in a browser is to let the browser do it through innerHTML, and that is a genuine security hole on untrusted text, so this page builds its own table instead and scans the string by hand. It costs more code, it is limited to the names in that table, and it cannot execute anything, which is the trade worth making.

Frequently Asked Questions

The five that matter, the script tag trap, and what XML does not have.

In element content, the ampersand and the less-than sign. In a quoted attribute value, also the quote character you used. Most guidance says five, adding the greater-than sign and the apostrophe, which is harmless and gives one rule that is safe in both places. Escaping more than that is a style choice, not a security measure.

Because it was escaped twice. Something escaped the ampersand of a real entity, so the browser now shows the text of the entity rather than acting on it. Unescape it once here and you get the entity back; unescape again and you get the space. Double escaping almost always means two layers both trying to be safe, such as a template that escapes output and a database field that was already escaped when it was stored.

No, and this is the trap. The HTML parser ends a script element at the first closing script tag it sees, even inside a string, so data containing that text breaks out no matter how well the quotes are escaped. Break it up with a backslash, which this page does, or better still put the data in a JSON script block and parse it rather than writing it into executable code.

Almost certainly an entity XML does not define. XML knows amp, lt, gt, quot and apos and nothing else, so a single nbsp or mdash makes the parser refuse the whole document. Unescape the text here with XML selected and the page will name the entities XML will not accept, then escape it again for XML.

No. All three languages are handled in your browser, from tables written into the page, and no request is made. That also means nothing is parsed as HTML at any point, which is the reason this unescaper cannot be used against you. You can confirm it in the Network tab, or by turning your wifi off and using the page anyway.

Every Other Security Tool

10 more tools in this set. All free, all in your browser.

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner