Some characters are reserved in HTML. To display them literally, you must use an entity.
An entity looks like &name; or &#number;.
Reserved Characters
| Character | Entity | Why |
|---|---|---|
< |
< |
Starts a tag |
> |
> |
Ends a tag |
& |
& |
Starts an entity |
" |
" |
Wraps attributes |
' |
' |
Wraps attributes |
Example
<p>Use <p> to make a paragraph.</p>
<p>Ram & Shyam</p>Without entities, the browser would try to render <p> as a tag rather
than show it.
Non-breaking Space
is a space the browser will never break a line at, and never
collapses.
Example
<p>NPR 480</p>
<p>10 km</p>This stops "NPR" and "480" being split across two lines.
Common Symbols
| Symbol | Entity |
|---|---|
| © | © |
| ® | ® |
| ™ | ™ |
| € | € |
| £ | £ |
| ₹ | ₹ |
| — | — |
| – | – |
| … | … |
| → | → |
| ★ | ★ |
Example
<p>© 2026 Scolar. All rights reserved.</p>
<p>Rating: ★★★★☆</p>Numeric Entities
Any character can be written by its Unicode number.
Example
<p>नेपाल</p> <!-- नेपाल -->You Usually Do Not Need Entities
With <meta charset="UTF-8">, you can type most characters directly —
including Devanagari and emoji.
Example
<meta charset="UTF-8">
...
<p>नेपाल 🇳🇵</p>Only the five reserved characters genuinely require entities.
Escaping User Content
If your site displays text typed by visitors, you must escape <,
> and & before printing it — otherwise a visitor can inject
<script> into your page. This is called XSS.
See PHP Security Essentials for how to do this on the server.