When found in a replacement value, ' should be left untouched, not escaped as ' which makes the entity visible instead of displaying an apostrophe in a browser.