en

HTML Entity Encoder and Decoder - SimeonOnSecurity

NOTE: This tool runs entirely in your browser with client-side JavaScript. Input is transformed locally and is never transmitted, logged, or stored.

Why Entities Matter for Testing

  • Encoding is how you display markup safely. Turning < into &lt; is what stops a browser treating user input as a tag.
  • Decoding matters because browsers decode twice. If one layer decodes and another does not, a payload can slip past a filter that inspected the encoded form.
  • Numeric forms bypass naive filters. A filter looking only for the literal &lt;script&gt; misses &#60;script&#62; and &#x3C;script&#x3E;, which a browser treats identically.
  • Decode to inspect, encode to display. When reviewing a payload, decode it to see what the browser will actually receive.

Sponsored by The Cyber Sentinels Club


FlockYou — ALPR and Flock Safety camera awareness devices from STS Collective
Shop Now — Save up to 20% Today Code: SIMEONONSECURITY