Characters and Entities

Save every page as UTF-8 and declare <meta charset="utf-8"> in the first 1024 bytes: the HTML standard requires UTF-8, and W3Techs 13,241 finds it on 99.1% of sites. You can then type é or 中 directly and need a character reference only to escape markup, insert invisible characters or write symbols your keyboard lacks. A reference can be named (&copy;), decimal (&#169;) or hexadecimal (&#xA9;, matching code point U+00A9); numeric forms work for any character.

Character references you will actually use
Char Reference Char Reference Char Reference
& < > &amp; &lt; &gt; © ® ™ &copy; &reg; &trade; × ÷ &times; &divide;
" ' &quot; &apos; € £ &euro; &pound; ± − &plusmn; &minus;
no-break space &nbsp; ° § &deg; &sect; ≤ ≥ ≠ &le; &ge; &ne;
soft hyphen &shy; • … &bull; &hellip; ← → &larr; &rarr;
zero-width space &#x200B; – — &ndash; &mdash; ✓ ½ &check; &frac12;

Escape < and every & in text, and the quote character inside a quoted attribute. The forgiving parser hides bugs: it still recognizes 106 old names such as &copy and &not without the semicolon.

Unescaped ampersands and the legacy entity trapHTMLLive
<p>Text: ?sort=asc&copy=2 and I'm &notit;</p>
<p>Escaped: ?sort=asc&amp;copy=2 and I'm &amp;notit;</p>
<p>Same character three ways: &copy; &#169; &#xA9;</p>
Browser output of Listing 2.53
Browser output of 53

Inside an attribute such as href="?a=1&copy=2", the parser leaves a semicolon-less name alone when = or a letter follows, a historical exception for old query strings. Do not rely on it. Frameworks such as React 7,897 and Vue 5,482 escape text for you; the risk returns when you bypass them with innerHTML (see Security).