What this XML step proves
Escape text when literal XML markup characters must stay data.
What to review before handoff
Escaping text is not the same as validating an XML document or sanitizing active markup.
Convert ampersands, angle brackets, quotes, and apostrophes to XML entity references locally.
Check structure, namespaces, repeated records, mixed content and remote-looking references. Converter pages review generated XML output when that is the handoff artifact.
Reviewing current XML…
Browser DOM parsing checks well-formedness and structure. It is not an XSD/DTD/business-rule validator, sanitizer or permission to trust remote resources; this review does not fetch external schemas or entities.
Escape plain text for the XML context where it will actually be inserted. Text nodes, double-quoted attributes and single-quoted attributes require different quote handling; optionally convert non-ASCII characters to decimal or hexadecimal numeric references.
| Character class | Count | Encoding rule | XML reason |
|---|
Escape mode treats input as plain text. Existing entity-looking text is escaped again by design, which prevents an ampersand from being mistaken for trusted markup.
Escape text when literal XML markup characters must stay data.
Escaping text is not the same as validating an XML document or sanitizing active markup.