การเข้ารหัส
HTML Entities Encode/Decode
เข้ารหัสและถอดรหัส HTML entities — แสดงอักขระพิเศษบนหน้าเว็บอย่างปลอดภัย
HTML entities are a way to write characters that would otherwise break markup (<, >, &) or have no keyboard key, as safe text sequences like < or &. This tool encodes and decodes such entities right in your browser.
How to use it
- Encode: paste text and characters like <, >, &, and quotes get replaced with their matching entities.
- Decode: paste HTML containing entities (&, ©, etc.) to see the plain text.
- Both named entities (&) and numeric ones (& or &) are supported.
Common uses
- Safely displaying user text (a comment, a message) on a page without risking broken markup or an injected script.
- Embedding HTML code samples in an article or documentation so the browser shows them as text instead of rendering them.
- Decoding content copied from another site where the characters arrived already entity-encoded.
Things to keep in mind
HTML entity escaping only protects against XSS via a page's text content — it does not protect a JavaScript context (innerHTML, eval) or href/src attributes containing unvalidated URLs.
Encode exactly at the point where text gets inserted into HTML, not ahead of time when saving to a database — otherwise the data gets mangled when reused outside an HTML context.
บทความเกี่ยวกับเครื่องมือนี้: HTML Entities: วิธีแสดงอักขระพิเศษอย่างปลอดภัย
คำถามที่พบบ่อย
เอนทิตี HTML แบบชื่อกับแบบตัวเลขต่างกันอย่างไร?
เอนทิตีแบบชื่อ เช่น & อ่านง่ายกว่า ส่วนแบบตัวเลข เช่น & หรือ & (ฐานสิบหรือฐานสิบหก) ใช้ได้กับทุกอักขระ รวมถึงตัวที่ไม่มีชื่อเรียก ทั้งสองแบบแสดงผลเหมือนกันในเบราว์เซอร์
เมื่อไหร่ที่จำเป็นต้องเข้ารหัสเอนทิตี HTML จริง ๆ?
เข้ารหัสอักขระอย่าง < > & " ' ทุกครั้งที่แทรกข้อความจากผู้ใช้หรือข้อความไดนามิกลงใน HTML เพื่อให้เบราว์เซอร์ถือว่าเป็นข้อความ ไม่ใช่ส่วนหนึ่งของแท็กหรือแอตทริบิวต์
โหมด "พื้นฐาน" กับ "ทุกอักขระ" ต่างกันอย่างไร?
โหมดพื้นฐานจะเข้ารหัสเฉพาะอักขระที่มีความหมายเชิงโครงสร้างใน HTML (เช่น < > & " ') ส่วน "ทุกอักขระ" จะแปลงอักขระนอก ASCII อื่น ๆ เป็นเอนทิตีตัวเลขด้วย ซึ่งมีประโยชน์กับตัวแยกวิเคราะห์รุ่นเก่าหรือเข้มงวด
ต้อง escape ข้อความในแอตทริบิวต์ต่างจากในเนื้อหาหน้าเว็บหรือไม่?
อักขระหลัก (<, >, &) escape เหมือนกัน แต่ภายในแอตทริบิวต์ที่อยู่ในเครื่องหมายคำพูด จำเป็นอย่างยิ่งที่ต้อง escape เครื่องหมายคำพูดชนิดเดียวกับที่ล้อมรอบแอตทริบิวต์นั้นด้วย ไม่เช่นนั้นค่าจะ "ขาด" เร็วกว่าที่คาดไว้
การ escape HTML ป้องกัน XSS ได้ทุกรูปแบบหรือไม่?
ไม่ มันปิดช่องโหว่ที่พบบ่อยที่สุด — การแทรกข้อความลงในเนื้อหา HTML — แต่ไม่ได้ป้องกัน XSS ที่เกิดผ่านบริบท JavaScript (เช่น innerHTML ที่ตามด้วยการรันโค้ด) หรือ URL ที่ไม่ผ่านการตรวจสอบใน href/src