Escape and unescape strings for JavaScript literals.
Escape and unescape strings for JSON payloads.
Format and beautify SQL queries with standard keyword capitalization and indentation.
Find and replace text using regular expressions and capture groups.
Strip punctuation, symbols, and non-alphanumeric characters from text.
Wrap text at specified column width, add line prefixes/suffixes, and indent.
A single apostrophe is enough to break a SQL statement — the classic O'Connor problem, where the quote inside the name terminates the string literal early and the rest of the value is parsed as SQL. Escaping fixes that by doubling the quote, so 'O''Connor' is read as one value rather than a broken statement. This tool does the escaping for you in both directions: paste raw text to get a version safe to place inside a string literal, or paste an escaped value to recover the original. It is genuinely useful when hand-writing a migration, building a seed script, or pasting user-supplied text into a query during debugging. It is worth being clear about what this is not: escaping is a formatting aid, not a security control. Parameterised queries are what actually prevent SQL injection, and no amount of manual escaping substitutes for them. Everything runs client-side, so data you are escaping never leaves your browser.
Double it. A value like O'Connor becomes O''Connor inside the literal, so the parser reads the pair as one apostrophe rather than the end of the string. This is standard SQL and works in MySQL, PostgreSQL, SQL Server, SQLite, and Oracle.
No. Escaping is a formatting aid, not a security control. Use parameterised queries or prepared statements — they keep data and SQL separate, which is what actually prevents injection.
Standard SQL treats the backslash as an ordinary character, so it is left alone. Note that MySQL in its default mode does treat backslash as an escape character, so double it yourself if you are targeting MySQL specifically.
Yes. Switch to unescape mode and the doubled quotes collapse back to single ones, recovering the original text exactly.
Yes. Line breaks, tabs, and Unicode characters including accented letters and non-Latin scripts pass through unchanged, so the escaped value round-trips byte for byte.
No. The escaping runs entirely in your browser, so text containing customer records or credentials is never transmitted, stored, or logged.