Use htmlspecialchars() when untrusted or variable text is placed into normal HTML text or attribute contexts. Escaping is an output step: keep the original data unchanged and escape it for the context where it is rendered.
$input = '<strong>Tom & Jerry</strong>';
echo htmlspecialchars($input, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');Start with this current pattern. The examples below are retained, corrected where necessary, and expanded for additional variations and output.
<b>Hello this is bold</b> <i>This is italic</i> This is normal
this is a double quote " this is & this is less than < this is greater than >
Now to display the code for the above line formatted in different style we have to use htmlspecialchars() function like this
$contents="<b>Hello this is bold</b> <i>This is italic</i> This is normal this is a double quote " this is & this is less than < this is greater than >";
echo htmlspecialchars($content);
We can display some special chars especially html tags on the screen by using htmlspecialchars function of PHP. This is required when we have to show some sample codes on the page or screen. For example I want to display this line
if ($i < 5 )
Here we can't write < as it is , in this place I have to write < then while displaying this will display < on the screen. Same way some other chars are there which are to be written in different way or special care to be taken for displaying them. All these jobs can be done by using htmlspecialchars function.$input = "<script>alert('XSS');</script>";
$escaped_input = htmlspecialchars($input, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
echo $escaped_input; // Output: <script>alert('XSS');</script>
$str = 'Hello & welcome!';
echo htmlspecialchars($str); // Output: Hello & welcome!
$str = '© 2023 Plus2Net';
echo htmlspecialchars($str); // Output: © 2023 Plus2Net
echo htmlentities($str); // Output: © 2023 Plus2Net
These examples show how HTML output escaping preserves text safely for display. Escaping is context-specific and should not be confused with changing or sanitizing the stored input.
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.
| webchecker | 17-02-2010 |
| very good explanation, thank you | |