F

HTML 实体编解码HTML Entity Encoder

HTML实体编码与解码HTML entity encoding and decoding.

编码 (HTML 实体)

—

解码 (原始文本)

—

关于 HTML 实体编解码About HTML Entity Encoder

在 HTML 中展示 <、>、& 等字符时,必须写成 &lt;、&amp; 等实体形式,否则会被浏览器误解析为标签,甚至引发 XSS 安全问题。本工具提供 HTML 实体编码与解码双向转换,是输出用户内容、编写模板时的安全助手。When displaying characters like <, > and & in HTML, they must be written as entities such as &lt; and &amp;, or the browser will misparse them as tags — or worse, expose XSS risks. This tool converts between HTML entities and plain characters in both directions, a handy safety aid for templates and user-generated content.

使用方法How to Use

  1. 粘贴原始文本,点击「编码」将特殊字符转换为实体。Paste raw text and click "Encode" to turn special characters into entities.
  2. 粘贴含实体的文本,点击「解码」还原为普通字符。Paste entity-laden text and click "Decode" to restore plain characters.
  3. 将结果复制到 HTML 模板、富文本或接口字段中使用。Copy the result into HTML templates, rich text or API fields.

常见问题FAQ

哪些字符必须转义?Which characters must be escaped?

最关键的是 & < > " ' 五个字符。在 HTML 文本节点中输出用户内容时转义它们,可有效防止 XSS 注入。The critical five are & < > " and '. Escaping them when rendering user content in HTML text nodes effectively prevents XSS injection.

数字实体和命名实体有什么区别?What is the difference between numeric and named entities?

&#x41; 是十六进制数字实体,&Amp; 是命名实体,二者表示同一字符。数字实体覆盖全部 Unicode,命名实体只有常用的一百多个。&#x41; is a hexadecimal numeric entity and &Amp; a named one; both denote the same character. Numeric entities cover all of Unicode, while named entities exist only for a hundred or so common characters.

只做实体转义就一定能防 XSS 吗?Is entity escaping alone enough to prevent XSS?

对 HTML 文本节点是够的;但若内容会进入属性、内联脚本、style 或 URL 位置,还需要对应上下文的转义与过滤,不能一概而论。It suffices for HTML text nodes, but content placed into attributes, inline scripts, styles or URLs needs context-specific escaping and filtering as well.

相关阅读Related Reading

相关工具Related Tools