Escape and unescape strings for HTML, JavaScript and URL contexts. Converts & < > quotes and backslash sequences in both directions. All client-side.
Every context has its own reserved characters. An ampersand that renders fine as plain text breaks an XML parser the moment it lands inside an attribute value. A double quote inside a JavaScript string literal ends the string early unless preceded by a backslash. A space in a URL query value becomes a malformed request depending on which server processes it. String Escape / Unescape covers all three contexts in one tool and works in both directions, so the same page that encodes a payload also decodes what comes back.
The three modes stay independent because their reserved character sets do not overlap cleanly. HTML mode targets five characters and their entity forms. JS mode handles backslash sequences including newlines, tabs, null bytes, and the Unicode line terminators that break automatic semicolon insertion. URL mode applies encodeURIComponent, the correct function for encoding a query-string value or a path segment, leaving the unreserved characters alone.
The lead sample is an XML-shaped error body containing angle brackets, an ampersand, double quotes and embedded newlines. In HTML mode, < becomes <, > becomes >, & becomes &, and the double quotes around 404 become ". In JS mode the two newlines become \n and the double quotes become \", producing a literal safe to paste inside a double-quoted JavaScript string. In URL mode the angle brackets become %3C and %3E and spaces become %20.
HTML mode encodes five characters (&, <, >, ", ') and decodes named references, decimal numeric references and hex numeric references. It does not expand all named HTML5 entities because the goal is safe escaping, not full HTML parsing. JS mode handles \n, \r, \t, \0, \uHHHH (four hex digits), \xHH (two hex digits), and the two Unicode paragraph separators U+2028 and U+2029 that crash some JSON-in-HTML embeds. URL mode encodes every character outside the unreserved set (A-Z, a-z, 0-9, hyphen, underscore, dot, tilde). It does not accept a full URL — only a single component such as a query-string value or a path segment; passing a complete URL will percent-encode the slashes and colons, which is normally not the intended result.