Also, if you hand-code these encoding routines, you're almost certain to miss something out. Please follow the OWASP reference implementations:
https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_P...
https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)_P...
In a previous project, we didn't even have an effective means of counting all the potential points of failure; you really don't want that, because it takes a lot of effort to fix.
I've seen developers use PHP's htmlspecialchars() (or hand-rolled versions thereof) when rendering snippets of inline JavaScript. The problem is that only HTML entity encodes <, >, &, ', and ", which still leaves you open to XSS because it doesn't encode all the characters that can be exploited in a JavaScript context.
Following the OWASP guidelines will negate all of that danger.