String Escaper

Plain text

Escaped html

<a href="x">A & B's</a>

About the String Escaper

Escape special characters for HTML, JavaScript, SQL, or CSV so a string is safe to embed — or reverse an already-escaped string back to plain text. Switch direction and target format independently, so any of the eight combinations is one click away.

This covers the four escaping formats that come up most often when building strings by hand: HTML entities for safely rendering user text on a page, JavaScript string escapes for embedding a value in generated code, SQL quote-doubling for a literal in a query, and CSV quoting for a field bound for a spreadsheet.

How to Use the String Escaper

1

Choose a target format — HTML, JavaScript, SQL, or CSV.

2

Choose a direction — Escape or Unescape.

3

Paste your text and copy the transformed result.

Frequently Asked Questions

Is my text sent anywhere?

No. Escaping and unescaping both run as plain JavaScript in your browser — nothing you type is sent to a server.

How does HTML unescape handle entities?

It decodes the common named entities (&, <, ©, —, and similar) plus any numeric entity (' or ') — it doesn't cover the full ~2000-entry HTML5 named entity table, just the ones that actually show up in practice.

What does the SQL and CSV escaping actually do?

SQL doubles up single quotes (' → '') per the ANSI-standard escaping every SQL dialect accepts. CSV wraps a field in double quotes and doubles any internal quotes, per RFC 4180 — only when the field actually needs it (contains a comma, quote, or newline).

Should I use SQL string escaping to prevent SQL injection in production code?

No — this tool is for one-off manual escaping when writing or debugging a query by hand. Production code should always use parameterized queries/prepared statements, which sidestep string escaping entirely and are the actual defense against SQL injection.