A fast and easy-to-configure HTML sanitizer written in Java that lets applications include HTML authored by third parties while protecting against cross-site scripting (XSS).
A fast and easy-to-configure HTML sanitizer written in Java. It lets applications include HTML authored by third parties while protecting against cross-site scripting (XSS).
OWASP Java HTML Sanitizer is designed for securely embedding untrusted HTML in web applications. The sanitizer JAR has no runtime dependencies. Its only compile-time dependency is spotbugs-annotations in provided scope; the other dependencies are used by the test suite. The project follows security best practices, has an extensive test suite, and has undergone adversarial security review.
The project is dual licensed under Apache-2.0 OR BSD-2-Clause, at the recipient's option. You may use it under either license and do not need to comply with both. COPYING is the authoritative statement of the dual-license grant.
Project Lead
Jim Manico is the founder of Manicode Security, where he trains developers and organizations in secure coding. He is an OWASP Distinguished Lifetime Member, a Java Champion, and the author of Iron-Clad Java. He leads the OWASP AISVS, Cheat Sheet Series, Java HTML Sanitizer, and Java Encoder projects.
Recognizing key contributors who have made significant impact on this project.