HTML tags to print on page by htmlspecialchars function

Escape text before inserting it into HTML

Use htmlspecialchars() when untrusted or variable text is placed into normal HTML text or attribute contexts. Escaping is an output step: keep the original data unchanged and escape it for the context where it is rendered.

$input = '<strong>Tom & Jerry</strong>';
echo htmlspecialchars($input, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');

Start with this current pattern. The examples below are retained, corrected where necessary, and expanded for additional variations and output.

Read this line below, we want to display the formatting of this line.

Hello this is bold This is italic This is normal this is a double quote " this is & this is less than < this is greater than >

The html part of the above line is here
<b>Hello this is bold</b> <i>This is italic</i> This is normal 
this is a double quote " this is & this is less than < this is greater than  >
Now to display the code for the above line formatted in different style we have to use htmlspecialchars() function like this

$contents="<b>Hello this is bold</b> <i>This is italic</i> This is normal this is a double quote " this is & this is less than < this is greater than  >";
 
echo htmlspecialchars($content);
We can display some special chars especially html tags on the screen by using htmlspecialchars function of PHP. This is required when we have to show some sample codes on the page or screen. For example I want to display this line
if ($i < 5 )
Here we can't write < as it is , in this place I have to write &lt; then while displaying this will display < on the screen. Same way some other chars are there which are to be written in different way or special care to be taken for displaying them. All these jobs can be done by using htmlspecialchars function.

This function takes care of &, < ( less than ), > ( greater than ), " double quote ( if ENT_NOQUOTES is not set. ) and single quote (only when ENT_QUOTES is set). Single quote became &#039; and double quote became &quot;. Same way < ( less than ) became &lt; and > ( greater than ) became &gt;

Example: Escaping User Input for HTML Output

$input = "<script>alert('XSS');</script>";
$escaped_input = htmlspecialchars($input, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
echo $escaped_input;  // Output: <script>alert('XSS');</script>

Example: Handling Special Characters

$str = 'Hello & welcome!';
echo htmlspecialchars($str);  // Output: Hello & welcome!

Example: Comparing htmlspecialchars() and htmlentities()

$str = '© 2023 Plus2Net';
echo htmlspecialchars($str);  // Output: © 2023 Plus2Net
echo htmlentities($str);  // Output: © 2023 Plus2Net
These examples show how HTML output escaping preserves text safely for display. Escaping is context-specific and should not be confused with changing or sanitizing the stored input.

htmlspecialchar is used to generate html code for web pages
String Functions Remove HTML tags


Subscribe to our YouTube Channel here



plus2net.com







webchecker

17-02-2010

very good explanation, thank you




PHP video Tutorials
✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer