HTML Entity Encoder & Decoder Studio
Convert reserved HTML characters, symbols, and Unicode strings into named, decimal, or hexadecimal entities and decode them safely.
⚠️ 5 Fatal Traps in HTML Entities & XSS Defense Architecture
💥 1. The Incomplete 5-Character Sanitization Fallacy
Escaping only the five canonical characters (& < > " ') is insufficient to prevent Cross-Site Scripting (XSS) inside unquoted HTML attributes or JavaScript event handlers. Inside an unquoted attribute (<input value=${input}>), an attacker does not need quotes or angle brackets; a simple space or tab followed by onfocus=alert(1) autofocus achieves full script execution.
⚖️ 2. Double-Encoding Cascades (&amp; Pollution)
When user input is encoded during database storage and subsequently re-encoded during template rendering, ampersands compound exponentially: © becomes &copy;, displaying literal © code on screen instead of the copyright symbol. Applications should store unescaped canonical strings in the database and apply entity encoding exclusively at the final view rendering boundary.
🛡️ 3. Context Ineffectiveness in 'href' & 'src' URI Attributes
HTML entity encoding does NOT sanitize URLs. If an attacker inputs javascript:alert(document.cookie) and you entity-encode it as <a link-url="javascript:alert(1)">, modern web browsers decode the HTML entities inside URI attributes BEFORE executing the link, resulting in instant XSS. URIs require strict protocol whitelisting (http://, https://).
🔍 4. DOM-Based XSS via 'innerHTML' Entity Decoding
A pervasive JavaScript antipattern decodes HTML entities by creating an off-screen element and setting el.innerHTML = input followed by reading el.textContent. If the input contains <img src=x onerror=alert(1)>, setting innerHTML immediately fires the onerror event in browser memory before the element is even attached to the DOM.
🚀 5. XML / SVG Parser Abort on HTML Named Entities
While HTML5 recognizes over 2,000 named entities (e.g. , €, —), strict XML, XHTML, and SVG engines only natively recognize five: " & ' < >. Injecting into an SVG or RSS feed causes XML parsers to abort with fatal entity not defined parsing errors.