What this tool does
XML has exactly five characters that a parser cannot read literally inside content, and this tool replaces each of them with its predefined entity:
| Character | Becomes |
|---|---|
& | & |
< | < |
> | > |
" | " |
' | ' |
Everything else passes through untouched — accents, emoji, tabs and newlines are all legal XML content and are left exactly as you typed them.
When you need it
Whenever text you did not write ends up inside markup: a product name containing &, a code snippet containing <, an attribute value containing a quote. This is markup escaping, not string-literal escaping — if you are building a Java or C# source file rather than an XML document, the rules are different and the matching tool is the one for that language.
What it does not do
It escapes; it does not validate. If your text is already a fragment of XML, escaping it turns the tags into visible text rather than markup — which is usually what you want for embedding a snippet, and never what you want for merging documents.
Private by design
Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.