escape-goat
escape-goat copied to clipboard
&🐐; Escape a string for use in HTML or the inverse
Escape a string for use in HTML or the inverse
Install
$ npm install escape-goat
Usage
import {htmlEscape, htmlUnescape} from 'escape-goat';
htmlEscape('🦄 & 🐐');
//=> '🦄 & 🐐'
htmlUnescape('🦄 & 🐐');
//=> '🦄 & 🐐'
htmlEscape('Hello <em>World</em>');
//=> 'Hello <em>World</em>'
const url = 'https://sindresorhus.com?x="🦄"';
htmlEscape`<a href="${url}">Unicorn</a>`;
//=> '<a href="https://sindresorhus.com?x="🦄"">Unicorn</a>'
const escapedUrl = 'https://sindresorhus.com?x="🦄"';
htmlUnescape`URL from HTML: ${escapedUrl}`;
//=> 'URL from HTML: https://sindresorhus.com?x="🦄"'
API
htmlEscape(string)
Escapes the following characters in the given string argument: & < > " '
The function also works as a tagged template literal that escapes interpolated values.
Note: This method of escaping is only safe when inserting data into normal tags like body, div, p, b, td, etc. Inserting htmlEscape'd data into tags like script and style opens your app to XSS vulnerabilities.
htmlUnescape(htmlString)
Unescapes the following HTML entities in the given htmlString argument: & < > " '
The function also works as a tagged template literal that unescapes interpolated values.
Tip
Ensure you always quote your HTML attributes to prevent possible XSS.
FAQ
Why yet another HTML escaping package?
I couldn't find one I liked that was tiny, well-tested, and had both escape and unescape methods.