Side note: /&([^&;]+);/g won't actually parse character entities in HTML correctly. There're a number of corner cases in the HTML5 spec for historical reasons, and this is one of them. In
some cases, it's legal (well, it's a parse error, but the parser must return the specified entity) to leave off the trailing semicolon. Except in attributes, where it depends on what the character following the last character of the entity is. The particular cases are enumerated in a table that is over 2000 lines long.
http://www.whatwg.org/specs/web-apps/current-work/multipage/...
The example is particularly instructive: ¬it; is parsed as ¬ followed by "it;", but ∉ is parsed as a full entity.
So yes, even for HTML entity parsing (which wasn't the question she was being asked), the correct answer really is "use a library".