Jaga is an ultra-lightweight, zero-dependency security layer for HTML templates, providing context-aware XSS protection between user input and the DOM.
-
Updated
Sep 1, 2026 - TypeScript
Jaga is an ultra-lightweight, zero-dependency security layer for HTML templates, providing context-aware XSS protection between user input and the DOM.
Context-aware output escaper for PHP (HTML, attribute, JavaScript, CSS, URL) — OWASP-aligned, dependency-free, PHP 7.4+.
Educational Node.js web security app demonstrating Stored/Reflected XSS attacks and context-aware HTML entity escaping defenses.
Context-aware, just-sufficient output encoding to prevent XSS in HTML, attribute, URI, and CSS contexts
HTML AST with safe-by-default, context-aware escaping for Standard ML. XSS holes are opt-in and greppable. Pure, dual-compiler (MLton + Poly/ML).
To associate your repository with the html-escaping topic, visit your repo's landing page and select "manage topics."