Files
2026-08-27 21:09:14 +00:00

25 lines
568 B
Plaintext

---
title: Escape an HTML string
sidebarTitle: Escape HTML
mode: center
---
`Bun.escapeHTML()` escapes HTML characters in a string. It makes the following replacements.
- `"` becomes `"""`
- `&` becomes `"&"`
- `'` becomes `"'"`
- `<` becomes `"&lt;"`
- `>` becomes `"&gt;"`
This function is optimized for large input. It converts non-string values to a string before escaping them.
```ts
Bun.escapeHTML("<script>alert('Hello World!')</script>");
// &lt;script&gt;alert(&#x27;Hello World!&#x27;)&lt;/script&gt;
```
---
See [Utils](/runtime/utils).