https://github.com/ESAPI/esapi-java-legacy
java security
Score: 29.330164012747098
Last synced: about 16 hours ago
JSON representation
Repository metadata:
ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library that makes it easier for programmers to write lower-risk applications.
- Host: GitHub
- URL: https://github.com/ESAPI/esapi-java-legacy
- Owner: ESAPI
- License: other
- Created: 2014-09-10T02:12:29.000Z (about 11 years ago)
- Default Branch: develop
- Last Pushed: 2025-10-23T20:31:29.000Z (11 days ago)
- Last Synced: 2025-10-25T16:38:39.473Z (9 days ago)
- Topics: java, security
- Language: Java
- Homepage: https://owasp.org/www-project-enterprise-security-api/
- Size: 55.4 MB
- Stars: 640
- Watchers: 55
- Forks: 370
- Open Issues: 124
-
Metadata Files:
- Readme: README.md
- Contributing: CONTRIBUTING-TO-ESAPI.txt
- License: LICENSE
- Security: SECURITY.md
Owner metadata:
- Name: Enterprise Security API
- Login: ESAPI
- Email:
- Kind: organization
- Description:
- Website:
- Location:
- Twitter:
- Company:
- Icon url: https://avatars.githubusercontent.com/u/5580725?v=4
- Repositories: 6
- Last Synced at: 2024-03-27T12:50:39.032Z
- Profile URL: https://github.com/ESAPI
GitHub Events
Total
- Create event: 9
- Delete event: 4
- Fork event: 16
- Gollum event: 1
- Issue comment event: 125
- Issues event: 26
- Pull request event: 19
- Pull request review comment event: 18
- Pull request review event: 34
- Push event: 25
- Release event: 3
- Watch event: 29
- Total: 309
Last Year
- Create event: 9
- Delete event: 4
- Fork event: 15
- Gollum event: 1
- Issue comment event: 125
- Issues event: 26
- Pull request event: 18
- Pull request review comment event: 18
- Pull request review event: 34
- Push event: 25
- Release event: 3
- Watch event: 28
- Total: 306
Committers metadata
Last synced: 5 days ago
Total Commits: 2,131
Total Committers: 70
Avg Commits per committer: 30.443
Development Distribution Score (DDS): 0.672
Commits in past year: 55
Committers in past year: 4
Avg Commits per committer in past year: 13.75
Development Distribution Score (DDS) in past year: 0.127
| Name | Commits | |
|---|---|---|
| kwwall | k****l@g****m | 699 |
| kevin.w.wall | k****l@6****b | 238 |
| manico.james | m****s@6****b | 225 |
| Jeremiah Stacey | j****y@g****m | 196 |
| planetlevel | p****l@6****b | 185 |
| kfealz@gmail.com | k****z@g****m@6****b | 90 |
| chrisisbeef | c****f@6****b | 77 |
| Matt Seil | m****l@a****g | 76 |
| schallee@darkmist.net | s****e@d****t@6****b | 45 |
| rogan.dawes | r****s@6****b | 40 |
| arshan.dabirsiaghi | a****i@6****b | 25 |
| augustd | a****d@6****b | 25 |
| vanderaj@gmail.com | v****j@g****m@6****b | 18 |
| dwichers | d****s@6****b | 15 |
| davewichers | d****s@g****m | 15 |
| brent.shikoski@gmail.com | b****i@g****m@6****b | 14 |
| mike.boberski | m****i@6****b | 12 |
| Jeffrey Walton | n****r@g****m | 12 |
| mikehfauzy | m****y@6****b | 11 |
| Snyk bot | s****t@s****o | 9 |
| jtmelton | j****n@6****b | 8 |
| Wiiitek | k****b@g****m | 6 |
| Chris Schmidt | c****f | 6 |
| chris.schmidt@owasp.org | c****t@o****g@6****b | 5 |
| arshan.dabirsiaghi@gmail.com | a****i@g****m@6****b | 5 |
| Kad DEMBELE | k****d@t****g | 4 |
| Anthony Musyoki | a****i@g****m | 4 |
| karansanwal | k****l@g****m | 4 |
| dependabot[bot] | 4****] | 3 |
| augustd | a****d@c****m | 3 |
| and 40 more... | ||
Issue and Pull Request metadata
Last synced: 1 day ago
Total issues: 101
Total pull requests: 107
Average time to close issues: 4 months
Average time to close pull requests: 20 days
Total issue authors: 58
Total pull request authors: 26
Average comments per issue: 4.14
Average comments per pull request: 2.59
Merged pull request: 70
Bot issues: 0
Bot pull requests: 7
Past year issues: 16
Past year pull requests: 25
Past year average time to close issues: 3 days
Past year average time to close pull requests: 2 days
Past year issue authors: 12
Past year pull request authors: 9
Past year average comments per issue: 3.81
Past year average comments per pull request: 1.52
Past year merged pull request: 11
Past year bot issues: 0
Past year bot pull requests: 1
Top Issue Authors
- kwwall (29)
- xeno6696 (4)
- meg23 (4)
- jeremiahjstacey (4)
- JerryDevis (3)
- raine93 (2)
- dwhacker (2)
- vpalli-bnym (2)
- sh26masood (2)
- RutujaPSonawane (1)
- Zokal84 (1)
- akwick (1)
- Somdutta (1)
- noloader (1)
- saravanansubiramaniam (1)
Top Pull Request Authors
- kwwall (29)
- jeremiahjstacey (19)
- noloader (8)
- dependabot[bot] (7)
- xeno6696 (5)
- DarioViva42 (4)
- reschke (4)
- DebajitKumarPhukan (4)
- davewichers (3)
- picsouds (2)
- JosephWitthuhnTR (2)
- mpreziuso (2)
- RodolfoAndre (2)
- sabbott1877 (2)
- mickeyz07 (2)
Top Issue Labels
- bug (42)
- enhancement (24)
- Priority-Low (7)
- Build-Maven (7)
- Component-Docs (6)
- Priority-Medium (5)
- wontfix (5)
- imported (4)
- Component-Encoder (4)
- falsepositive (4)
- good first issue (3)
- javadoc (3)
- Configuration (3)
- Component-Logger (3)
- question (3)
- Component-SecurityConfiguration (2)
- Priority-High (2)
- Component-Encryptor (2)
- Vulnerable Dependencies (2)
- Component-Validator (2)
- Security (1)
- help wanted (1)
- OpSys-All (1)
- Milestone-Release2.1 (1)
- NothingToFixHere (1)
- Milestone-Release2.2 (1)
- documentation_comments (1)
- wait4future (1)
- General Code Cleanup (1)
- Java 1.8 (1)
Top Pull Request Labels
- Vulnerable Dependencies (6)
- javadoc (2)
- dependencies (1)
- java (1)
Package metadata
- Total packages: 1
- Total downloads: unknown
- Total docker downloads: 102,265,081
- Total dependent packages: 106
- Total dependent repositories: 1,483
- Total versions: 30
- Total advisories: 7
repo1.maven.org: org.owasp.esapi:esapi
The Enterprise Security API (ESAPI) project is an OWASP project to create simple strong security controls for every web platform. Security controls are not simple to build. You can read about the hundreds of pitfalls for unwary developers on the OWASP web site. By providing developers with a set of strong controls, we aim to eliminate some of the complexity of creating secure web applications. This can result in significant cost savings across the SDLC.
- Homepage: https://owasp.org/www-project-enterprise-security-api/
- Documentation: https://appdoc.app/artifact/org.owasp.esapi/esapi/
- Licenses: BSD,Creative Commons 3.0 BY-SA
- Latest release: 2.1.0 (published about 12 years ago)
- Last Synced: 2025-10-30T19:03:06.312Z (4 days ago)
- Versions: 30
- Dependent Packages: 106
- Dependent Repositories: 1,483
- Docker Downloads: 102,265,081
-
Rankings:
- Dependent repos count: 0.302%
- Docker downloads count: 0.508%
- Dependent packages count: 0.705%
- Average: 5.179%
- Forks count: 9.398%
- Stargazers count: 14.98%
-
Advisories:
- Missing Cryptographic Step in OWASP Enterprise Security API for Java
- Missing Cryptographic Step in OWASP Enterprise Security API for Java
- DoS vulnerabilities persist in ESAPI file uploads despite remediation of CVE-2023-24998
- Path traversal in the OWASP Enterprise Security API
- Validator.isValidSafeHTML is being deprecated and will be deleted from org.owasp.esapi:esapi in 1 year
- Padding oracle attacks
- Cross-site Scripting in org.owasp.esapi:esapi
Dependencies
- actions/checkout v2 composite
- actions/setup-java v1 composite
- actions/checkout v2 composite
- github/super-linter v4 composite
- javax.servlet.jsp:javax.servlet.jsp-api 2.3.3 provided
- javax.servlet:javax.servlet-api 3.1.0 provided
- com.github.spotbugs:spotbugs-annotations 4.7.3
- commons-beanutils:commons-beanutils 1.9.4
- commons-configuration:commons-configuration 1.10
- commons-fileupload:commons-fileupload 1.4
- commons-io:commons-io 2.11.0
- commons-lang:commons-lang 2.6
- org.apache-extras.beanshell:bsh 2.0b6
- org.apache.commons:commons-collections4 4.4
- org.owasp.antisamy:antisamy 1.7.2
- org.slf4j:slf4j-api 2.0.4
- xml-apis:xml-apis 1.4.01
- xom:xom 1.3.8
- commons-codec:commons-codec 1.15 test
- junit:junit 4.13.2 test
- org.bouncycastle:bcprov-jdk15on 1.70 test
- org.hamcrest:hamcrest-core 2.2 test
- org.mockito:mockito-core 3.12.4 test
- org.openjdk.jmh:jmh-core 1.36 test
- org.powermock:powermock-api-mockito2 2.0.9 test
- org.powermock:powermock-core 2.0.9 test
- org.powermock:powermock-module-junit4 2.0.9 test
- org.powermock:powermock-reflect 2.0.9 test