🏷️
🧼

Sanitise User Input for HTML Output

Encode user-provided strings before inserting them into HTML — prevents XSS injection attacks.

ບໍ່ຈໍາເປັນຕ້ອງເຂົ້າສູ່ລະບົບ
Output:
Examples:
Plain text / HTML
Encoded HTML
Output will appear here…
Common HTML entities reference
&&
<&lt;
>&gt;
"&quot;
'&#39;
·&nbsp;
©&copy;
®&reg;
&trade;
&euro;
&mdash;
&hellip;

Security tips

🧼

Paste any user input here to see exactly which characters get encoded. < becomes &lt;, > becomes &gt;, & becomes &amp; — all rendered as text, not HTML.

🛡️

Cross-Site Scripting (XSS) attacks inject <script> tags via user input fields. Encoding all user output is the primary defense.

💡

Always encode on output (when rendering), not on input (when saving). Store raw data, encode when displaying — this avoids double-encoding bugs.

🔍

Test with payloads like <script>alert(1)</script> and onmouseover="alert(1)" to verify your encoding catches all attack vectors.

ມັນເຮັດວຽກແນວໃດ

1
ເຂົ້າ
Enter your data into the tool above. Everything stays local to your browser.
2
ຂະບວນການ
The tool processes your data instantly in your browser using JavaScript. No server, no waiting.
3
ດາວໂຫຼດ
Get your result instantly. Nothing is stored after you leave the page — complete privacy.

ເປັນຫຍັງຕ້ອງໃຊ້ຂອງພວກເຮົາ?

ບໍ່ເສຍຄ່າຢ່າງສົມບູນ - ບໍ່ມີຄ່າໃຊ້ຈ່າຍທີ່ເຊື່ອງໄວ້, ເຄີຍ
ບໍ່ມີບັນຊີ, ອີເມວ, ຫຼືເຂົ້າສູ່ລະບົບ
ໄຟລ໌ບໍ່ເຄີຍອອກຈາກອຸປະກອນຂອງທ່ານ
ບໍ່ມີຂອບເຂດຈໍາກັດຂະຫນາດໄຟລ໌ໃດໆ
ບໍ່ມີ watermarks ໃນຜົນຜະລິດໃດໆ

Also check out…

ຄໍາຖາມທີ່ຖາມເລື້ອຍໆ