Server IP : 92.205.26.207 / Your IP : 216.73.216.16 Web Server : Apache System : Linux 207.26.205.92.host.secureserver.net 4.18.0-553.60.1.el8_10.x86_64 #1 SMP Thu Jul 10 04:01:16 EDT 2025 x86_64 User : zikryat ( 1002) PHP Version : 8.3.23 Disable Function : exec,passthru,shell_exec,system MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : ON Directory (0755) : /home/zikryat/public_html/node_modules/escape-goat/ |
[ Home ] | [ C0mmand ] | [ Upload File ] |
---|
<h1> <img src="logo.jpg" width="1280" alt="escape-goat"> </h1> > Escape a string for use in HTML or the inverse [](https://travis-ci.org/sindresorhus/escape-goat) ## Install ``` $ npm install escape-goat ``` ## Usage ```js const {htmlEscape, htmlUnescape} = require('escape-goat'); htmlEscape('🦄 & 🐐'); //=> '🦄 & 🐐' htmlUnescape('🦄 & 🐐'); //=> '🦄 & 🐐' htmlEscape('Hello <em>World</em>'); //=> 'Hello <em>World</em>' const url = 'https://sindresorhus.com?x="🦄"'; htmlEscape`<a href="${url}">Unicorn</a>`; //=> '<a href="https://sindresorhus.com?x="🦄"">Unicorn</a>' const escapedUrl = 'https://sindresorhus.com?x="🦄"'; htmlUnescape`URL from HTML: ${url}`; //=> 'URL from HTML: https://sindresorhus.com?x="🦄"' ``` ## API ### htmlEscape(string) Escapes the following characters in the given `string` argument: `&` `<` `>` `"` `'` The function also works as a [tagged template literal](https://developer.mozilla.org/en/docs/Web/JavaScript/Reference/Template_literals#Tagged_template_literals) that escapes interpolated values. ### htmlUnescape(htmlString) Unescapes the following HTML entities in the given `htmlString` argument: `&` `<` `>` `"` `'` The function also works as a [tagged template literal](https://developer.mozilla.org/en/docs/Web/JavaScript/Reference/Template_literals#Tagged_template_literals) that unescapes interpolated values. ## Tip Ensure you always quote your HTML attributes to prevent possible [XSS](https://en.wikipedia.org/wiki/Cross-site_scripting). ## FAQ ### Why yet another HTML escaping package? I couldn't find one I liked that was tiny, well-tested, and had both `.escape()` and `.unescape()`.