String Escaper

Escape or Unescape strings for 8 formats: HTML, XML, JavaScript, Java, .Net (C#), JSON, CSV, and SQL.
All processing happens locally in your browser — your data is never uploaded to any server.
Format:
Direction:
⚠ Security Warning: String escaping is not a substitute for parameterized queries. Escaping alone does NOT prevent SQL injection. Always use parameterized queries (prepared statements) in production code.
How to use: Choose a format and direction (Escape / Unescape), then type or paste your text — the output updates automatically. Click Process to manually trigger conversion.
For JSON, JavaScript, Java, and .Net modes, check Escape all non-ASCII chars to convert characters like Chinese into \uXXXX sequences.
Unescape reverses the escaping: &lt; becomes <, \n becomes a newline, etc.
HTML: Escape converts & < > " ' to HTML entities (&amp; &lt; &gt; &quot; &#39;). Use this when embedding user-generated text in HTML to prevent XSS attacks.
Unescape converts HTML entities (&amp; &lt; &gt; &quot; &#39;) back to their original characters. Uses the browser's native HTML parser for reliable decoding of all named and numeric entities.
XML: Escape converts the same 5 characters as HTML (& < > " ') to XML-safe entities. XML requires all & characters to be escaped, even in attribute values.
Unescape converts XML entities back to their original characters. Handles the 5 predefined XML entities plus numeric character references. Same logic as HTML unescape.
JavaScript: Escape converts special characters to JavaScript escape sequences: \n \t \\ \" \' \xHH \uHHHH \u{H...}. Use this when generating JavaScript string literals dynamically.
Unescape converts JavaScript escape sequences (\n \t \xHH \uHHHH etc.) back to literal characters. Handles all standard ECMAScript escape sequences including \u{H...} code point escapes.
JSON: Escape converts \" \\ and control characters to JSON-safe escape sequences per RFC 8259. Use this when embedding text inside JSON string values.
Unescape converts JSON escape sequences (\" \\ \n \uXXXX etc.) back to literal characters. Follows RFC 8259: only valid JSON escape sequences are decoded.
CSV: Escape per RFC 4180: wraps fields in double quotes if they contain commas, double quotes, or line breaks. Internal double quotes are doubled (" → "").
Unescape reverses RFC 4180 CSV escaping: removes outer double quotes and un-doubles internal quotes ("" → "). Handles multi-line fields and quoted commas correctly.
SQL: Escape escapes single quotes by doubling them (' → ''), which works across all major databases (MySQL, PostgreSQL, SQL Server, SQLite). This handles string literal escaping only — it does not protect against SQL injection in dynamic queries.
Unescape converts doubled single quotes ('' → ') back to single quotes. Reverses the standard SQL string literal escaping.
Java: Escape converts special characters to Java escape sequences: \n \t \r \\ \" \' \uXXXX etc. Use this when generating Java string literals.
Unescape converts Java escape sequences back to literal characters. Handles all standard Java escape sequences including \uXXXX Unicode escapes.
.Net (C#): Escape converts special characters to C# escape sequences: \n \t \r \a \v \0 \\ \" \uXXXX \UHHHHHHHH etc. Use this when generating C# string literals.
Unescape converts C# escape sequences back to literal characters. Handles all standard C# sequences including \UHHHHHHHH UTF-32 and variable-length \xHH... hex escapes.
Escaping depends on context

The same text needs different escapes depending on where it lands: HTML body needs &lt; &amp; &gt;, a double-quoted attribute additionally needs &quot;, a JavaScript string needs backslash escapes, and a URL needs percent-encoding. Escaping for the wrong context is how markup injection and XSS happen.

Rule of thumb: escape for the destination, not the source — decide by where the data is going, not where it came from.