Contextual output encoding for Java 8+ with a zero-dependency core. Version 1.5.0 is now available on Maven Central.
OWASP Java Encoder 1.5.0 was released on September 28, 2026 and is available from Maven Central.
This release includes security and correctness fixes, new JSON encoding APIs with JSP/Jakarta tags and EL functions, and XML 1.1 bindings. Java 8 remains supported. Upgrade encoder, encoder-jsp, and encoder-jakarta-jsp to 1.5.0 and review the release and migration notes for intentional encoding-output changes.
The optional ESAPI adapter is retired and has no 1.5.0 release. Existing users should migrate to direct Java Encoder APIs.
The OWASP Java Encoder is a Java 1.8+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting! Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts (primarily JavaScript) are injected into otherwise trusted web sites. One of the primary defenses to stop Cross Site Scripting is a technique called Contextual Output Encoding. WARNING: Please note that XSS prevention requires other defensive strategies besides encoding! For more information, please read the Cross Site Scripting prevention cheatsheet. We actively track project issues and seek to remediate any issues that arise. The project owners feel this project is stable and ready for production use and are seeking project status promotion. Happy Encoding!
The OWASP Java Encoder library is intended for quick contextual encoding with very little overhead, either in performance or usage. To get started, simply add the encoder-1.5.0.jar, import org.owasp.encoder.Encode and start encoding. Please look at the javadoc for Encode, to see the variety of contexts for which you can encode. Tag libraries and JSP EL functions can be found in the encoder-jsp-1.5.0.jar.
Extensive documentation on how to use this project can be found in our GitHub repository.
Project Leader
Jim Manico is the founder of Manicode Security, where he trains developers and organizations in secure coding. He is an OWASP Distinguished Lifetime Member, a Java Champion, and the author of Iron-Clad Java. He leads the OWASP AISVS, Cheat Sheet Series, Java HTML Sanitizer, and Java Encoder projects.