🏷️
🧼

Sanitise User Input for HTML Output

Encode user-provided strings before inserting them into HTML — prevents XSS injection attacks.

Giriş gerekmez
Output:
Examples:
Plain text / HTML
Encoded HTML
Output will appear here…
Common HTML entities reference
&&
<&lt;
>&gt;
"&quot;
'&#39;
·&nbsp;
©&copy;
®&reg;
&trade;
&euro;
&mdash;
&hellip;

Security tips

🧼

Paste any user input here to see exactly which characters get encoded. < becomes &lt;, > becomes &gt;, & becomes &amp; — all rendered as text, not HTML.

🛡️

Cross-Site Scripting (XSS) attacks inject <script> tags via user input fields. Encoding all user output is the primary defense.

💡

Always encode on output (when rendering), not on input (when saving). Store raw data, encode when displaying — this avoids double-encoding bugs.

🔍

Test with payloads like <script>alert(1)</script> and onmouseover="alert(1)" to verify your encoding catches all attack vectors.

Nasıl çalışır

1
Giriş
Enter your data into the tool above. Everything stays local to your browser.
2
İşle
The tool processes your data instantly in your browser using JavaScript. No server, no waiting.
3
İndir
Get your result instantly. Nothing is stored after you leave the page — complete privacy.

Neden bizimki?

Tamamen ücretsiz — hiçbir zaman gizli maliyet yok
Hesap, e-posta veya giriş gerekmez
Dosyalar hiçbir zaman cihazınızı terk etmez
Hiçbir dosya boyutu sınırı yok
Hiçbir çıktıda filigran yok

Also check out…

Sık sorulan sorular