ECMAScript String Escape Sequences: Architecture & Rules
In JavaScript source files and JSON serialization streams, special characters cannot always be represented literally without causing syntax ambiguity or parse errors. A developer relies on escape characters js to denote control codes, quotes, and international glyphs.
When working with legacy databases or external APIs that output double-escaped strings, utilizing this javascript string decoder and javascript unescape tool eliminates corrupted backslashes without running insecure eval() statements.
| Escape Sequence |
Character Name |
Unicode Code Point |
ASCII Code |
Allowed in JSON? |
\n |
Line Feed (Newline) |
U+000A |
10 |
Yes |
\r |
Carriage Return |
U+000D |
13 |
Yes |
\t |
Horizontal Tab |
U+0009 |
9 |
Yes |
\" |
Double Quotation Mark |
U+0022 |
34 |
Yes |
\' |
Single Quotation Mark |
U+0027 |
39 |
No (JSON requires double quotes) |
\\ |
Reverse Solidus (Backslash) |
U+005C |
92 |
Yes |
\uXXXX |
Unicode 4-Hex Digit |
U+XXXX |
Variable |
Yes |
How to Javascript Escape Text for HTML & Prevent XSS
A primary security vulnerability in web engineering is Cross-Site Scripting (XSS). When developers dynamically inject user data into the HTML Document Object Model, they must javascript escape text for html so that browser rendering engines interpret strings as passive text rather than executable script elements.
Our tool sanitizes the 5 critical HTML entities:
& becomes &
< becomes <
> becomes >
" becomes "
' becomes '
Frequently Asked Questions: JS String Decoding
Why should I avoid using eval() to unescape JavaScript strings?
Using eval('"' + str + '"') exposes your application to Arbitrary Code Execution if the input string contains maliciously crafted payloads. This client-side unescaper parses escape tokens deterministically with zero evaluation risk.
How does JSON unescape handle multi-byte emoji and supplementary planes?
JSON represents astral characters (like emojis \uD83D\uDE00) as UTF-16 surrogate pairs. Our decoder parses surrogate pairs in accordance with Unicode Technical Report #17, reconstructing the actual 32-bit emoji symbol correctly.
Can this tool unescape URL encoded strings?
Yes. Switching the Target Syntax to "URI Component" allows decoding percent-encoded characters like %20 (space) or %3F (question mark) via decodeURIComponent.
Does this tool work completely client-side?
Yes. All character transformations occur strictly within your browser's JavaScript sandbox. No strings or database credentials are ever logged or uploaded.