String Literal Escape Auditor

A syntax check is not an evaluation. The escapes that change a value in silence outnumber the ones that raise.

Paste one string literal exactly as it appears in source, quote characters and all. The page evaluates the same bytes under six escape grammars at once and shows, per source span, what each one produces and where they disagree. Nothing is sent anywhere and no interpreter is invoked: the grammars are implemented here, because handing the bytes to the browser's own parser would collapse two of the columns into one.

Three sibling tools ask the same question about other shapes. unicode-character-inspector emits the JavaScript, HTML and CSS escape forms for a character, which is the encode direction on text that has already been decoded; this tool runs the decode direction, taking a source literal and evaluating its escape sequences into characters. json-precision-auditor asks it about number literals: which ones change value when a parser reads them, including the ones that re-print byte for byte identical to what you pasted. yaml-type-coercion-auditor asks it about YAML scalars: which ones resolve to a different type, or a different value, depending on which parser reads the file.

Pasting is taken verbatim as plain text. Nothing is decoded, normalised or trimmed before the grammars see it. Input is capped at 20,000 characters.

Cross host disagreement matrix

One row per source span, in source order. A row is marked hosts disagree in text as well as by shading whenever the six columns do not all produce the same result. Positions count from zero at the first character inside the quotes. The JSON column's error messages are the one exception, and they say so: a JSON parser counts the opening quotation mark as position 0, so those numbers run one ahead of every other position on this page.

Six columns for five hosts: PowerShell and POSIX shell are one host slot, split into two columns because they do not always agree. Doubling a backslash separates them, for instance, since POSIX treats \\ as an escape and PowerShell does not. In the summary line above, a distinct outcome means either one resulting code point sequence, or one refusal counted by the reason the host gives for it.

Per host evaluation

A resulting control character is never rendered as itself. It appears as a bordered pill naming its code point, so an invisible result stays visible. JavaScript, JSON and PowerShell strings are UTF-16, so those columns report a code point count and a code unit count separately, and a code unit in the surrogate range that has no partner is read out as a code unit and labelled a lone surrogate rather than being folded into a neighbour. Python holds unpaired surrogates as they are, which is why a surrogate pair written as two \u escapes is one code point in JavaScript and two in Python.

Self test

The fixtures below are compared against values recorded from real interpreters. The run always includes one positive control, an assertion written to fail on purpose, so a self test that silently stops running is visible instead of invisible.

Not run yet. Use the Run self test button.

How each column is decided

  1. Strip exactly one matched pair of surrounding quote characters and remember which kind it was. If there is no matched pair the whole input is treated as content and an advisory says so.
  2. Split the content into spans once. A span is either a run of ordinary characters or a candidate escape beginning at a backslash. Every column is indexed by the same source positions, so the matrix rows line up by construction.
  3. Each column applies its own grammar table to the same bytes and reports, per item, the source span, the resulting code points and exactly one verdict.
  4. A column that hits a parse error keeps walking so you can see where the refusal happened and what followed it. Its summary still reads as a hard refusal, never as a partial result.

Grammar sources

Behaviour was reimplemented from these published specifications and checked against real interpreters. No code is reproduced here. This project is independent and unaffiliated with any of the vendors, standards bodies or projects named on this page.