ToolBoxOnline
Developer

Escaping HTML Entities in RSS and XML Feeds: Where Decoding Goes Wrong

Your blog feeds have unreadable XML because half the entities are double-encoded and the other half are stripped. RSS parsers are strict — here's how to escape once and only once.

HTML entitiesRSS feedXML escapingdata corruptionfeed validators

You publish an RSS feed and it looks fine in the browser, but Feed Validator screams about malformed XML. The post titles show & instead of & and the body has stray entities like   that nobody can read. The fix is to escape HTML entities exactly once, in the right place, and to stop double escaping them at every step. An HTML entities tool helps you see what's actually in your feed versus what's supposed to be there — usually the difference is one extra round of escaping.

Why RSS Feeds Break So Easily

RSS and Atom feeds are XML, and XML has rules about which characters must be escaped. The ampersand is the big one — every & in your content needs to become & in the XML, and then the & in & doesn't need to be escaped again. Most CMS systems escape once on save and then escape again on feed generation, which produces & in the output. The counter-intuitive part is that the bug is invisible in the database (where the content is correct) and only shows up in the feed (where it's been escaped twice). Tools that read the feed see the literal text & and display the ampersand, but tools that read the raw XML break.

The Escape-Once Rule

Escape once at the storage layer and never again. If your database stores the literal character (your post title contains "Tom & Jerry"), escape it once when generating the feed XML. Don't escape it again on display. Don't escape it again when generating social cards. Don't escape it again when sending notifications. Use an HTML entities tool to spot-check your feed: paste the raw XML in, see what gets decoded, and if you see & in the decoded output, you've double-escaped somewhere. For the URL fields in the feed, a URL encoder catches the same kind of issue for links, since ampersands in URLs also need careful handling. For the JSON-LD that lives alongside the feed, a JSON formatter catches the same kind of double-encoding in structured data. The rule is one escape per source, no exceptions, no matter how many tools are in the pipeline.

Escape Once, Validate Often

We covered API corruption in our guide to HTML entities in JSON and APIs; the feed version is the same idea with stricter parsers. Escape once, validate the output, and the feed stops breaking.

Tools mentioned in this article

Share this tool