ZYBERMART

HTML Entity Encoder

Escape text for safe use in HTML, or turn HTML entities back into characters.

Common HTML entities

CharacterNamedNumericDescription
<&lt;&#60;Less than
>&gt;&#62;Greater than
&&amp;&#38;Ampersand
"&quot;&#34;Double quote
'&apos;&#39;Apostrophe
(space)&nbsp;&#160;Non-breaking space
©&copy;&#169;Copyright
®&reg;&#174;Registered
™&trade;&#8482;Trademark
€&euro;&#8364;Euro
—&mdash;&#8212;Em dash
…&hellip;&#8230;Ellipsis

Need to type these characters instead? The special characters page lets you copy them with one click.

Frequently asked questions

What are HTML entities?

HTML entities are codes that represent characters in HTML. They start with & and end with ;, such as &lt; for < or &copy; for ©. They let you show characters that would otherwise be read as HTML code, or that are hard to type.

Which characters must be encoded?

In page text, always encode < and &. Inside attribute values, also encode the quote character used around the value (" or '). Encoding > is optional but common. Everything else, including emoji, can be written directly in a UTF-8 page.

What is the difference between named and numeric entities?

Named entities such as &eacute; are easier to read, but only exist for some characters. Numeric entities such as &#233; (decimal) or &#xE9; (hex) work for every Unicode character.

Does encoding prevent XSS?

Encoding < > & " and ' is the right defense when inserting untrusted text into HTML content or quoted attributes. It is not enough inside <script> blocks, URLs or CSS, which need their own escaping.