SECURITY TOOL
HTML Entity Encoder/Decoder
Convert text to HTML entities and back. Highlights XSS-dangerous characters, supports named, numeric, and hex formats. All processing happens in your browser.
100% client-side
Real-time conversion
XSS-safe output
Encode — Text → Entities
Encoded entities will appear here…
Decode — Entities → Text
Decoded text will appear here…
XSS Warning:
Characters highlighted in < > " ' & are injection vectors. Always encode user input before rendering in HTML.
Best Practice:
Use
textContent instead of innerHTML when inserting user data. This auto-escapes entities and prevents XSS.
Entity Reference
Char
Named
Numeric
Description
Copied!
Related Tools
All done!
Your file is ready for download.
Enjoying Fixie? A small donation keeps these tools free for everyone.