Tools
Developer Security

HTML Entity Escaper

Escape or unescape HTML entities for safe output encoding.

Input

Output

Results appear here.

How this helps

Context-correct output encoding is the primary defence against cross-site scripting.

Everything runs locally in your browser. Never paste production secrets, tokens or real credentials into any online tool.