Secrets and encoding

How to escape HTML before you display user text

Text might contain <, >, or & and will be inserted into HTML. Escape it on HTML Escape.

URL encoding, percent-decoding, and HTML escaping are different jobs.
HTML escaping is for element text, and it is a different job from encoding a URL.

What to run

Open HTML Escape. It stays in the browser.

How to read the result

< becomes &lt;. & becomes &amp;.

That is safe to put in element text.

It is not safe inside a URL attribute by itself, and it is not a sanitiser for a whole HTML document.

What to open next

Open URL Encoder for href values. It stays in the browser.

Open Graph Generator already emits escaped tags if you use its snippet. It stays in the browser.