Escape text for safe HTML output, or turn entities like & back into readable characters.
Escaping `&`, `<`, `>`, `"` and `'` is what stops user-supplied text from being parsed as markup, which is the root of most cross-site scripting bugs.
Decoding is handy in the other direction, when a log line or API response arrives with entities already baked in.