I think part of the reason that we don't have such a function yet is that it is essentially a one-liner if you use decimal notation for entities:
function escape_html(s) { return s.replace(/[&<>"']/g, m => `&#${m.charCodeAt(0)};`) }
That being said, a built-in function would be convenient and faster.