Escape or Unescape strings for 8 formats: HTML, XML, JavaScript, Java, .Net (C#), JSON, CSV, and SQL.
All processing happens locally in your browser — your data is never uploaded to any server.
Format:
Direction:
Input
Output
⚠ Security Warning: String escaping is not a substitute for parameterized queries.
Escaping alone does NOT prevent SQL injection. Always use parameterized queries (prepared statements) in production code.
How to use: Choose a format and direction (Escape / Unescape), then type or paste your text
— the output updates automatically. Click Process to manually trigger conversion.
For JSON, JavaScript, Java, and .Net modes, check Escape all non-ASCII chars to convert characters like Chinese
into \uXXXX sequences.
Unescape reverses the escaping: < becomes <, \n becomes a newline, etc.
HTML:Escape converts &<>"' to HTML entities (&<>"'). Use this when embedding user-generated text in HTML to prevent XSS attacks. Unescape converts HTML entities (&<>"') back to their original characters. Uses the browser's native HTML parser for reliable decoding of all named and numeric entities.
XML:Escape converts the same 5 characters as HTML (&<>"') to XML-safe entities. XML requires all & characters to be escaped, even in attribute values. Unescape converts XML entities back to their original characters. Handles the 5 predefined XML entities plus numeric character references. Same logic as HTML unescape.
JavaScript:Escape converts special characters to JavaScript escape sequences: \n\t\\\"\'\xHH\uHHHH\u{H...}. Use this when generating JavaScript string literals dynamically. Unescape converts JavaScript escape sequences (\n\t\xHH\uHHHH etc.) back to literal characters. Handles all standard ECMAScript escape sequences including \u{H...} code point escapes.
JSON:Escape converts \"\\ and control characters to JSON-safe escape sequences per RFC 8259. Use this when embedding text inside JSON string values. Unescape converts JSON escape sequences (\"\\\n\uXXXX etc.) back to literal characters. Follows RFC 8259: only valid JSON escape sequences are decoded.
CSV:Escape per RFC 4180: wraps fields in double quotes if they contain commas, double quotes, or line breaks. Internal double quotes are doubled (" → ""). Unescape reverses RFC 4180 CSV escaping: removes outer double quotes and un-doubles internal quotes ("" → "). Handles multi-line fields and quoted commas correctly.
SQL:Escape escapes single quotes by doubling them (' → ''), which works across all major databases (MySQL, PostgreSQL, SQL Server, SQLite). This handles string literal escaping only — it does not protect against SQL injection in dynamic queries. Unescape converts doubled single quotes ('' → ') back to single quotes. Reverses the standard SQL string literal escaping.
Java:Escape converts special characters to Java escape sequences: \n\t\r\\\"\'\uXXXX etc. Use this when generating Java string literals. Unescape converts Java escape sequences back to literal characters. Handles all standard Java escape sequences including \uXXXX Unicode escapes.
.Net (C#):Escape converts special characters to C# escape sequences: \n\t\r\a\v\0\\\"\uXXXX\UHHHHHHHH etc. Use this when generating C# string literals. Unescape converts C# escape sequences back to literal characters. Handles all standard C# sequences including \UHHHHHHHH UTF-32 and variable-length \xHH... hex escapes.
Escaping depends on context
The same text needs different escapes depending on where it lands: HTML body needs < & >, a double-quoted attribute additionally needs ", a JavaScript string needs backslash escapes, and a URL needs percent-encoding. Escaping for the wrong context is how markup injection and XSS happen.
Rule of thumb: escape for the destination, not the source — decide by where the data is going, not where it came from.
🔷 String Escaper
Paste text and select a format to escape or unescape.