Jaga is an ultra-lightweight, zero-dependency security layer for HTML templates, providing context-aware XSS protection between user input and the DOM.
-
Updated
Apr 1, 2026 - TypeScript
Jaga is an ultra-lightweight, zero-dependency security layer for HTML templates, providing context-aware XSS protection between user input and the DOM.
Context-aware output escaper for PHP (HTML, attribute, JavaScript, CSS, URL) — OWASP-aligned, dependency-free, PHP 7.4+.
HTML AST with safe-by-default, context-aware escaping for Standard ML. XSS holes are opt-in and greppable. Pure, dual-compiler (MLton + Poly/ML).
Add a description, image, and links to the html-escaping topic page so that developers can more easily learn about it.
To associate your repository with the html-escaping topic, visit your repo's landing page and select "manage topics."