🏷️
🧼

Sanitise User Input for HTML Output

Encode user-provided strings before inserting them into HTML — prevents XSS injection attacks.

Ingen pålogging kreves
Output:
Examples:
Plain text / HTML
Encoded HTML
Output will appear here…
Common HTML entities reference
&&
<&lt;
>&gt;
"&quot;
'&#39;
·&nbsp;
©&copy;
®&reg;
&trade;
&euro;
&mdash;
&hellip;

Security tips

🧼

Paste any user input here to see exactly which characters get encoded. < becomes &lt;, > becomes &gt;, & becomes &amp; — all rendered as text, not HTML.

🛡️

Cross-Site Scripting (XSS) attacks inject <script> tags via user input fields. Encoding all user output is the primary defense.

💡

Always encode on output (when rendering), not on input (when saving). Store raw data, encode when displaying — this avoids double-encoding bugs.

🔍

Test with payloads like <script>alert(1)</script> and onmouseover="alert(1)" to verify your encoding catches all attack vectors.

Hvordan det fungerer

1
Gå inn
Enter your data into the tool above. Everything stays local to your browser.
2
Prosess
The tool processes your data instantly in your browser using JavaScript. No server, no waiting.
3
Last ned
Get your result instantly. Nothing is stored after you leave the page — complete privacy.

Hvorfor bruke vår?

Helt gratis – aldri noen skjulte kostnader
Ingen konto, e-post eller pålogging kreves
Filer forlater aldri enheten din
Ingen filstørrelsesbegrensninger overhodet
Ingen vannmerker på noen utgang

Also check out…

Ofte stilte spørsmål