HTML Entity Encoder
Escape HTML special characters into entities before they go into markup, or decode a run of entities back into readable text. Live, both directions, in your browser.
What must be escaped, and why only five characters
The parser only treats five characters as structural: & < > " '. The ampersand starts a reference, the angle brackets delimit tags, and the two quotes delimit attribute values. Everything else - newlines, equals signs, colons - is ordinary text and stays as it is, so encoding a whole document into entities buys nothing and makes the source unreadable. The counter reports how many of the five were actually found, which is normally a small number even on a long string.
Decoding is the mirror operation, and it is where the caution belongs: never decode untrusted input and then insert the result as markup. Entities are how an attacker hides a tag from a naive filter - decode first and you have just handed them the injection. Use decode for reading and for repairing your own content, and let the encoder do the escaping on the way into the page.
Usage example
You are pasting a customer quote containing 5 < 10 and an ampersand into an HTML template. Encode it: the output escapes exactly those characters, the counter shows three, and the text now sits inside your tag without the < being read as the start of an element. Paste the encoded form back with decode selected to confirm it round-trips to your original sentence.
The reverse case shows up in scraped content: a page full of & and " is a double-encoded paste, and one decode pass restores it - if the output still shows entities, it was encoded twice and needs a second pass. Once the text is clean, the Markdown to HTML converter takes it from plain copy into structured markup, and the word frequency counter handles any counting you need over the same string.
Frequently asked questions
Which characters does this encode?
The five structural ones: & < > " '. The ampersand is escaped first so an already-encoded entity is not double-processed incorrectly, and numeric references in the input are left alone when decoding.
Why does my decoded output still show code like '
It was encoded more than once - run decode again until the text stops changing. Anything still showing entities after two passes is likely literal content rather than markup.
Is decoding safe?
For reading, yes. The danger is feeding decoded output back into HTML: that is where a filtered payload becomes live markup. Decode to inspect, encode before inserting - the direction matters more than the tool.
Related tools
Markdown to HTML
Convert Markdown to HTML you can paste into a CMS, with angle brackets escaped first.
HTML Formatter
Indent and line-break minified HTML so nested tags are readable.
Base64 Image Encoder
Turn an image file into a Base64 data URL you can paste straight into HTML or CSS, or decode a data URL back into a viewable image. Runs in your browser.