Thank you for the replay,.
But please have a loot at my code
I already encoded & to & , why it html encode it again? become &, that is incorrect
I tested in the <a href="&" /> tag, no such problem,. it only happens to my custom tags , or iframe src attribute