Skip to content

HTML unescape

EncodeExperimentalLimited support. Verify anything critical.

HTML unescape is a browser-local developer utility that converts the five core structural HTML entities—&, <, >, ", and '—back into literal text. It handles ampersands, angle brackets, quotation marks, and apostrophes in a predictable single pass, so encoded content can be inspected, tested, or reused without sending the input to a server. It is intentionally narrower than a full HTML parser and leaves unsupported named entities unchanged. The complete input stays in browser memory while the conversion runs locally on your device.

Skip to the tool

This tool processes text on your device. The text is not uploaded.

  • Only the five entities this site writes are reversed.
  • Named entities beyond amp, lt, gt, quot, #39 are left as-is.

How to use HTML unescape

What is HTML unescape?

HTML unescape is a developer utility designed to reverse the five core structural HTML entities (&, <, >, ", and ') back into their original literal characters. This process decodes text safely in a specific order that prevents the accidental double-decoding of ampersands. Notably, this tool only unescapes these five structural entities and ignores other named entities. Crucially, all text processing happens entirely locally within your browser, ensuring that your data never leaves your device and providing maximum privacy and security.

How Unescaping Mechanics Work

HTML entity unescaping is the process of translating serialized HTML character entities (like &lt; or &amp;) back into their original literal Unicode characters (like < or &).

Preventing Double-Unescape Hazards

A common vulnerability in naive entity decoders is executing entity replacements in an arbitrary sequence. If &amp; is decoded to & before processing &lt;, an escaped sequence such as &amp;lt; will incorrectly decode to < instead of the intended literal string &lt;.

This tool performs unescaping using deterministic single-pass regular expression matching, which completely mitigates these double-unescape hazards. By processing specific entities before ampersands, you achieve accurate decoding results on the first pass.

Practical developer use cases
  • Cleaning Scraped Web Content: Converting entity-encoded text extracted from web crawlers, HTML tables, and article feeds into clean plain text for natural language processing or display.
  • Processing XML & RSS Feeds: Safely parsing news feeds and podcast XML entries where article titles and descriptions frequently contain escaped entities like &amp;, &quot;, or &#39;.
  • Database Text Normalization: Cleaning legacy database tables where form values were aggressively pre-escaped before insertion.
  • Markdown Preparation: Preparing sanitized HTML text snippets for conversion into readable markdown tables, headings, and code blocks.
Best practices and security considerations

When handling user-generated content or untrusted inputs, it is critical to understand the security implications of decoding text.

Beware of Cross-Site Scripting (XSS) Unescaping untrusted HTML can introduce XSS vulnerabilities into your web application. If you decode user-generated HTML entities and then inject the resulting raw string directly into a DOM element (for instance, by using innerHTML or dangerouslySetInnerHTML), any malicious scripts present in that string will execute.

Safe Rendering Contexts You should only unescape text when you intend to render it in safe, plain-text contexts. For example, rendering into the DOM using textContent or innerText is safe because these APIs treat the text as literals rather than structural HTML tags.

Scope of Entity Support Remember that while there are over 2,000 HTML5 named entities, this specific unescape tool targets only the five core structural entities. For complete decoding of the entire HTML entity spec, a dedicated HTML parser should be used.

Code examples

If you need to implement your own safe HTML unescaping function, consider the following examples which demonstrate safe decoding logic.

JavaScript / TypeScript

function unescapeHtml(escapedText: string): string {
  // Map specific entities to their literal representations
  const map: Record<string, string> = {
    "&lt;": "<",
    "&gt;": ">",
    "&quot;": '"',
    "&#39;": "'",
    "&apos;": "'",
    "&amp;": "&",
  };
  
  // Single-pass replacement avoids double-unescaping issues
  return escapedText.replace(/&(?:lt|gt|quot|apos|#39|amp);/g, (entity) => map[entity]);
}

Python 3

import html

def unescape_html(escaped_text: str) -> str:
    # Python's standard library handles full entity unescaping safely
    return html.unescape(escaped_text)

How it works

  1. Enter what you haveType or pick your text. Nothing is submitted anywhere.
  2. It runs in this tabThe calculation happens on your device, using your browser's own data.
  3. Take the resultRead the text, then copy, download, or share a link.

Reimplemented locally. Not derived from IT-Tools source.

Basis
independent
Licence
MIT
Last reviewed

Frequently asked questions

In what order are HTML entities decoded?

Specific entities (&lt;, &gt;, &quot;, &#39;) are decoded before the ampersand entity (&amp;). This prevents accidental double-decoding where '&amp;lt;' might improperly resolve to '<' in a single pass.

Are all 2,000+ HTML5 named entities supported?

This tool specifically targets the five core structural entities (&amp;, &lt;, &gt;, &quot;, &#39;) used for safe HTML text emission.

Can unescaping untrusted HTML introduce XSS into my application?

Yes. If you unescape user-generated HTML entities and inject the resulting raw string into a DOM element (e.g. via innerHTML), malicious scripts can execute. Unescape only when rendering in safe plain-text contexts.

Is unescaping performed locally in the browser?

Yes. The replacement regular expressions run entirely within your local browser JavaScript engine without external network requests.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close