HTML Entity Encoder and Decoder - SimeonOnSecurity
NOTE: This tool runs entirely in your browser with client-side JavaScript. Input is transformed locally and is never transmitted, logged, or stored.
Why Entities Matter for Testing
- Encoding is how you display markup safely. Turning
<into<is what stops a browser treating user input as a tag. - Decoding matters because browsers decode twice. If one layer decodes and another does not, a payload can slip past a filter that inspected the encoded form.
- Numeric forms bypass naive filters. A filter looking only for the literal
<script>misses<script>and<script>, which a browser treats identically. - Decode to inspect, encode to display. When reviewing a payload, decode it to see what the browser will actually receive.
Sponsored by The Cyber Sentinels Club
