Apache commons is providing Html-escaping, no need to reinvent the wheel: > It supports all known HTML 4.0 entities, including funky accents. Note that the > commonly used apostrophe escape character (') is not a legal entity and so > is not supported). So I manually checked that nothing is relying on escaped single-quotes, and didn't manage to find anything that does.