OWASP Java HTML Sanitizer

A fast and easy-to-configure HTML sanitizer written in Java that lets applications include HTML authored by third parties while protecting against cross-site scripting (XSS).

About OWASP Java HTML Sanitizer

Project Leaders

Jim Manico

Project Lead

Jim Manico is the founder of Manicode Security, where he trains developers and organizations in secure coding. He is an OWASP Distinguished Lifetime Member, a Java Champion, and the author of Iron-Clad Java. He leads the OWASP AISVS, Cheat Sheet Series, Java HTML Sanitizer, and Java Encoder projects.

EmailLinkedIn

Major Contributors

Recognizing key contributors who have made significant impact on this project.

Abhishek

Maintainer

Shares release management and maintenance.

GitHub

Andres Almiray

Maintainer

Shares release management and maintenance.

GitHub

Ben Evans

Maintainer

Shares release management and maintenance.

GitHub

Erik Costlow

Maintainer

Shares release management and maintenance.

GitHub

Brian Fox

Maintainer

Shares release management and maintenance.

GitHub

Mike Samuel

Founder

Founded the project and wrote the original sanitizer.

GitHub

Project Information

Lab Project
Classification
Tool
Language
Java
License
Apache License 2.0
Latest Version
20260924.2
Contributors
45
GitHub Stars
957
Downloads
456
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.