Takes untrusted third-party HTML and returns HTML that is safe to embed, enforcing a configurable policy of elements, attributes, CSS and URLs. Used server-side across the Java ecosystem to stop cross-site scripting in user-generated content; GitHub lists more than 4,300 dependent repositories. 45 Maven releases since 2011.

Fund this project

Unverified URL

The funding manifest has not provided proof via wellKnown that this link is associated with it. Learn more.

Continue