HTML Entity Encoder

Convert special characters to HTML entities.

0 characters
0 characters

User types: <script>alert('hacked')</script>

You display it without encoding: congrats, you have an XSS vulnerability.

Essential Encodings

CharEntityWhy
<&lt;Opens tags
>&gt;Closes tags
&&amp;Starts entities
"&quot;Breaks attributes