Developer

XML Escape Tool

Escape special characters for XML and HTML, or unescape entities back to text. Handles ampersand, angle brackets and quotes safely.

Last reviewed by the Radiatus Cloud team

Escape special characters for safe XML/HTML, or unescape entities back to text.

Need this built for your product?

We design, build & host secure software & APIs.

Talk to an engineer

Escape text for XML and HTML

XML and HTML reserve a handful of characters that cannot appear literally in content: the ampersand begins an entity, the angle brackets delimit tags, and quotation marks delimit attribute values. To include these characters as data you must escape them into entities, turning an ampersand into the amp entity, a less-than sign into the lt entity, and so on. This tool escapes text into safe XML, and unescapes entities, including numeric character references, back into plain text.

An option controls whether quotation marks are escaped, which you need inside attribute values but not always in element content.

Why escaping is essential

Inserting unescaped text into XML or HTML is a common cause of broken documents and a serious security risk. An unescaped angle bracket can prematurely close or open a tag, and in web pages unescaped input is the root of cross-site scripting vulnerabilities. Escaping guarantees that text is treated as data rather than markup, keeping documents valid and safe.

The unescaper understands the five standard named entities and both decimal and hexadecimal numeric character references, so it handles the common ways entities are written. All processing happens locally in your browser, so your content stays private.

Related tools

  • JSON Formatter — Format and beautify JSON in your browser. Pinpoints syntax errors by line and column, flags unsafe integers, and never uploads your data to a server.
  • JSON Validator — Validate JSON syntax with precise line and column errors, and check documents against a JSON Schema. Runs locally in your browser, nothing uploaded.
  • Regex Tester — Test regular expressions against sample text with live match highlighting, capture groups and flag control. Runs entirely in your browser.
  • HTML Minifier — Minify HTML by removing comments and redundant whitespace, without breaking inline elements or pre blocks. Runs entirely in your browser.

Frequently Asked Questions

Which characters need escaping in XML?

The ampersand and the two angle brackets always, plus quotation marks inside attribute values. These five have reserved meaning in XML and HTML.

When should I escape quotes?

Escape quotes when the text goes inside an attribute value delimited by that quote character. In element content, escaping quotes is optional.

Does it decode numeric entities?

Yes. The unescaper handles decimal and hexadecimal numeric character references as well as the five standard named entities.

How does escaping prevent security issues?

Escaping ensures user text is treated as data, not markup, which stops it from injecting tags or scripts, the basis of cross-site scripting attacks.

Is XML escaping the same as HTML escaping?

They share the core five characters. HTML has many more named entities, but escaping the reserved five covers both for safe content.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Paste text to escape, or escaped XML to unescape.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.