Save every page as UTF-8 and declare <meta charset="utf-8"> in the first 1024 bytes: the HTML standard requires UTF-8, and W3Techs 13,241 finds it on 99.1% of sites. You can then type é or 中 directly and need a character reference only to escape markup, insert invisible characters or write symbols your keyboard lacks. A reference can be named (©), decimal (©) or hexadecimal (©, matching code point U+00A9); numeric forms work for any character.
| Char | Reference | Char | Reference | Char | Reference |
|---|---|---|---|---|---|
| & < > | & < > | © ® ™ | © ® ™ | × ÷ | × ÷ |
| " ' | " ' | € £ | € £ | ± − | ± − |
| no-break space | | ° § | ° § | ≤ ≥ ≠ | ≤ ≥ ≠ |
| soft hyphen | ­ | • … | • … | ← → | ← → |
| zero-width space | ​ | – — | – — | ✓ ½ | ✓ ½ |
Escape < and every & in text, and the quote character inside a quoted attribute. The forgiving parser hides bugs: it still recognizes 106 old names such as © and ¬ without the semicolon.
<p>Text: ?sort=asc©=2 and I'm ¬it;</p>
<p>Escaped: ?sort=asc&copy=2 and I'm &notit;</p>
<p>Same character three ways: © © ©</p>
Inside an attribute such as href="?a=1©=2", the parser leaves a semicolon-less name alone when = or a letter follows, a historical exception for old query strings. Do not rely on it. Frameworks such as React 7,897 and Vue 5,482 escape text for you; the risk returns when you bypass them with innerHTML (see Security).