PHP htmlspecialchars()Functions

PHP String 参考手册PHP String Reference Manual

Examples

Convert the predefined characters "<" (less than) and ">" (greater than) to HTML entities:

<?php $str = "This is some <b>bold</b> text."; echo htmlspecialchars($str); ?>

The HTML output of the above code is as follows (view source):

<!DOCTYPE html> <html> <body> This is some &lt;b&gt;bold&lt;/b&gt; text. </body> </html>

The browser output of the above code is as follows:

This is some <b>bold</b> text.

Run example »

Definition and Usage

The htmlspecialchars() function converts some predefined characters to HTML entities.

The predefined characters are:

  • & (ampersand) becomes &amp;
  • " (double quote) becomes &quot;
  • ' (single quote) becomes &#039;
  • < (less than) becomes &lt;
  • > (greater than) becomes &gt;

Tip:To convert special HTML entities back to characters, use htmlspecialchars_decode()function.


Syntax

htmlspecialchars(string,flags,character-set,double_encode)

Parameter Description
string Required. Specifies the string to convert.
flags Optional. Specifies how to handle quotes, invalid encoding, and which document type to use.

Available quote types:

  • ENT_COMPAT - Default. Only encodes double quotes.
  • ENT_QUOTES - Encodes double and single quotes.
  • ENT_NOQUOTES - Does not encode any quotes.

Invalid encoding:

  • ENT_IGNORE - Ignores invalid encoding instead of making the function return an empty string. Should be avoided, as this may have security implications.
  • ENT_SUBSTITUTE - Replaces invalid encoding with a specified character with the Unicode replacement character U+FFFD (UTF-8) or &#FFFD;, instead of returning an empty string.
  • ENT_DISALLOWED - Replaces invalid code points in the specified document type with the Unicode replacement character U+FFFD (UTF-8) or &#FFFD;.

Additional flags specifying the document type to use:

  • ENT_HTML401 - Default. Handles code as HTML 4.01.
  • ENT_HTML5 - Handles code as HTML 5.
  • ENT_XML1 - Handles code as XML 1.
  • ENT_XHTML - Handles code as XHTML.
character-set Optional. A string that specifies the character set to use.

Allowed values:

  • UTF-8 - Default. ASCII-compatible multibyte 8-bit Unicode
  • ISO-8859-1 - Western European
  • ISO-8859-15 - Western European (adds the Euro sign + French and Finnish letters missing from ISO-8859-1)
  • cp866 - DOS-specific Cyrillic character set
  • cp1251 - Windows-specific Cyrillic character set
  • cp1252 - Windows-specific Western European character set
  • KOI8-R - Russian
  • BIG5 - Traditional Chinese, mainly used in Taiwan
  • GB2312 - Simplified Chinese, national standard character set
  • BIG5-HKSCS - Big5 with Hong Kong extensions
  • Shift_JIS - Japanese
  • EUC-JP - Japanese
  • MacRoman - Character set used by Mac operating system

Note:In versions before PHP 5.4, unrecognized character sets will be ignored and replaced by ISO-8859-1. Since PHP 5.4, unrecognized character sets will be ignored and replaced by UTF-8.

double_encode Optional. A boolean value that specifies whether to encode existing HTML entities.
  • TRUE - Default. Will convert every entity.
  • FALSE - Will not encode existing HTML entities.

Technical Details

Return value: Returns the converted string.

Ifstringcontains invalid encoding, returns an empty string unless the ENT_IGNORE or ENT_SUBSTITUTE flags are set.
PHP Version: 4+
Changelog: In PHP 5,character-setthe default value of the parameter was changed to UTF-8.

In PHP 5.4, the following were added: ENT_SUBSTITUTE, ENT_DISALLOWED, ENT_HTML401, ENT_HTML5, ENT_XML1, and ENT_XHTML.

In PHP 5.3, ENT_IGNORE was added.

In PHP 5.2.3, addeddouble_encodeparameter.

In PHP 4.1, addedcharacter-setparameter.


More Examples

Example 1

Convert some predefined characters to HTML entities:

<?php $str = "Jane & 'Tarzan'"; echo htmlspecialchars($str, ENT_COMPAT); //Default, only encodes double quotes echo "<br>"; echo htmlspecialchars($str, ENT_QUOTES); //Encodes double and single quotes echo "<br>"; echo htmlspecialchars($str, ENT_NOQUOTES); //Does not encode any quotes ?>

The HTML output of the above code is as follows (view source):

<!DOCTYPE html> <html> <body> Jane &amp; 'Tarzan'<br> Jane &amp; 'Tarzan'<br> Jane &amp; 'Tarzan' </body> </html>

The browser output of the above code is as follows:

Jane & 'Tarzan'
Jane & 'Tarzan'
Jane & 'Tarzan'

Run example »

Example 2

Convert double quotes to HTML entities:

<?php $str = 'I love "PHP".'; echo htmlspecialchars($str, ENT_QUOTES); //Encodes double and single quotes ?>
;

The HTML output of the above code is as follows (view source):

<!DOCTYPE html> <html> <body> I love &quot;PHP&quot;. </body> </html>

The browser output of the above code is as follows:

I love "PHP".

Run example »


PHP String 参考手册PHP String Reference Manual Other Extensions