HTML unescape
EncodeExperimentalLimited support. Verify anything critical.
HTML unescape is a browser-local developer utility that converts the five core structural HTML entities—&, <, >, ", and '—back into literal text. It handles ampersands, angle brackets, quotation marks, and apostrophes in a predictable single pass, so encoded content can be inspected, tested, or reused without sending the input to a server. It is intentionally narrower than a full HTML parser and leaves unsupported named entities unchanged. The complete input stays in browser memory while the conversion runs locally on your device.
This tool processes text on your device. The text is not uploaded.
How to use HTML unescape
What is HTML unescape?
HTML unescape is a developer utility designed to reverse the five core structural HTML entities (&, <, >, ", and ') back into their original literal characters. This process decodes text safely in a specific order that prevents the accidental double-decoding of ampersands. Notably, this tool only unescapes these five structural entities and ignores other named entities. Crucially, all text processing happens entirely locally within your browser, ensuring that your data never leaves your device and providing maximum privacy and security.
How Unescaping Mechanics Work
HTML entity unescaping is the process of translating serialized HTML character entities (like < or &) back into their original literal Unicode characters (like < or &).
Preventing Double-Unescape Hazards
A common vulnerability in naive entity decoders is executing entity replacements in an arbitrary sequence. If & is decoded to & before processing <, an escaped sequence such as &lt; will incorrectly decode to < instead of the intended literal string <.
This tool performs unescaping using deterministic single-pass regular expression matching, which completely mitigates these double-unescape hazards. By processing specific entities before ampersands, you achieve accurate decoding results on the first pass.
Practical developer use cases
- Cleaning Scraped Web Content: Converting entity-encoded text extracted from web crawlers, HTML tables, and article feeds into clean plain text for natural language processing or display.
- Processing XML & RSS Feeds: Safely parsing news feeds and podcast XML entries where article titles and descriptions frequently contain escaped entities like
&,", or'. - Database Text Normalization: Cleaning legacy database tables where form values were aggressively pre-escaped before insertion.
- Markdown Preparation: Preparing sanitized HTML text snippets for conversion into readable markdown tables, headings, and code blocks.
Best practices and security considerations
When handling user-generated content or untrusted inputs, it is critical to understand the security implications of decoding text.
Beware of Cross-Site Scripting (XSS)
Unescaping untrusted HTML can introduce XSS vulnerabilities into your web application. If you decode user-generated HTML entities and then inject the resulting raw string directly into a DOM element (for instance, by using innerHTML or dangerouslySetInnerHTML), any malicious scripts present in that string will execute.
Safe Rendering Contexts
You should only unescape text when you intend to render it in safe, plain-text contexts. For example, rendering into the DOM using textContent or innerText is safe because these APIs treat the text as literals rather than structural HTML tags.
Scope of Entity Support Remember that while there are over 2,000 HTML5 named entities, this specific unescape tool targets only the five core structural entities. For complete decoding of the entire HTML entity spec, a dedicated HTML parser should be used.
Code examples
If you need to implement your own safe HTML unescaping function, consider the following examples which demonstrate safe decoding logic.
JavaScript / TypeScript
function unescapeHtml(escapedText: string): string {
// Map specific entities to their literal representations
const map: Record<string, string> = {
"<": "<",
">": ">",
""": '"',
"'": "'",
"'": "'",
"&": "&",
};
// Single-pass replacement avoids double-unescaping issues
return escapedText.replace(/&(?:lt|gt|quot|apos|#39|amp);/g, (entity) => map[entity]);
}Python 3
import html
def unescape_html(escaped_text: str) -> str:
# Python's standard library handles full entity unescaping safely
return html.unescape(escaped_text)How it works
- Enter what you haveType or pick your text. Nothing is submitted anywhere.
- It runs in this tabThe calculation happens on your device, using your browser's own data.
- Take the resultRead the text, then copy, download, or share a link.
Reimplemented locally. Not derived from IT-Tools source.
- Basis
- independent
- Licence
- MIT
- Last reviewed
Frequently asked questions
In what order are HTML entities decoded?
Specific entities (<, >, ", ') are decoded before the ampersand entity (&). This prevents accidental double-decoding where '&lt;' might improperly resolve to '<' in a single pass.
Are all 2,000+ HTML5 named entities supported?
This tool specifically targets the five core structural entities (&, <, >, ", ') used for safe HTML text emission.
Can unescaping untrusted HTML introduce XSS into my application?
Yes. If you unescape user-generated HTML entities and inject the resulting raw string into a DOM element (e.g. via innerHTML), malicious scripts can execute. Unescape only when rendering in safe plain-text contexts.
Is unescaping performed locally in the browser?
Yes. The replacement regular expressions run entirely within your local browser JavaScript engine without external network requests.