What this does
Escape turns the characters XML reserves into entities: & becomes &, < becomes <, and > becomes >. Inside attribute values quotes need escaping too, as " and '; turn that option off for plain text content.
Unescape
Unescape decodes the five predefined entities and numeric references such as A and 😀. HTML-only names like are not defined in XML, so they are left unchanged and listed. References to code points XML 1.0 forbids are also left alone.
Options
You can escape every non-ASCII character as a hexadecimal reference, which is handy when the target is ASCII-only. Control characters that XML 1.0 cannot represent at all (such as U+0001) are removed by default, with a count of what was dropped.
Privacy
Everything runs in your browser. Your input is never uploaded, stored, or put in the URL.