Apache Wicket home

Apache Wicket

A component-oriented Java web framework: plain Java, plain HTML, no JavaScript build chain.

HelloWorld, one component in two views

Markup stays HTML that opens in any editor. Behaviour lives in Java. A wicket:id attribute binds a tag to a component, and that is the whole contract: no template language, no JavaScript toolchain.

Point at, focus or tap a callout to light its part in every view.

View A, markup HelloWorld.html
<html>
<body>
	<h1 wicket:id="message">Message goes here</h1>
</body>
</html>
View B, Java HelloWorld.java
public class HelloWorld extends WebPage {
	public HelloWorld() {
		add(new Label("message", "Hello World!"));
	}
}
View C, response deployment mode
<h1>Hello World!</h1>
Current release
11.0.0
For production
10.11.0 LTS
Released
Owner
The Apache Software Foundation
Sheet
1 / 5

Maven dependency

Release line
<dependency>
    <groupId>org.apache.wicket</groupId>
    <artifactId>wicket-core</artifactId>
    <version>10.11.0</version>
</dependency>

Release lines

StatusVersionDateSupport
In service 10.11.0 LTSFor productionSince Mar 2024Until 14.0.0, Jul 2027
11.0.0For new featuresSince Oct 2026Until 12.0.0, Jan 2027
Next 12.0.0Jan 2027Until 13.0.0, Apr 2027
10.12.0 LTSJan 2027Until 14.0.0, Jul 2027
13.0.0Apr 2027Until 14.0.0, Jul 2027
14.0.0 LTSJul 2027Until 18.0.0, Jul 2028
Out of service 9.24.0Jul 2020 to Oct 2026Ended with 11.0.0
8.19.0May 2018 to Oct 2026Ended with 11.0.0

Why Wicket

Wicket is a component-oriented, server-side Java web framework. Open source since 2004 and developed at the Apache Software Foundation, it powers long-lived applications that need complex, dynamic pages without a JavaScript build chain.

Plain Java and plain HTML: drawn on sheet 1.

Components for complex pages

Pages and components are real Java objects with encapsulation, inheritance and events. Build a panel once, with its own markup, styles and scripts, and reuse it on every page, or ship a whole component library as a JAR.

Parts list, this form
ItemPartQtyIds
1AddressPanel2billing, shipping
2TextField<String>4street, city in each panel
AddressPanel.java
public class AddressPanel extends Panel {
    public AddressPanel(String id, IModel<Address> address) {
        super(id, new CompoundPropertyModel<>(address));
        add(new TextField<String>("street"));
        add(new TextField<String>("city"));
    }
}

// one component, used twice on the same form
form.add(new AddressPanel("billing", billingAddress));
form.add(new AddressPanel("shipping", shippingAddress));

Ajax without writing JavaScript

Update parts of a page from Java. Wicket's Ajax components re-render only the components you add to the request, and come with a solid set of building blocks.

CounterPage.java
Label count = new Label("count", () -> clicks);
add(count.setOutputMarkupId(true));

add(new AjaxLink<Void>("increment") {
    @Override
    public void onClick(AjaxRequestTarget target) {
        clicks++;
        target.add(count);
    }
});

Secure by default

Component paths are session-relative and URLs do not expose your model. Wicket supports a strict Content Security Policy without unsafe-inline: every header contribution gets a nonce automatically. You only add what your application needs.

MyApplication.java
@Override
protected void init() {
    super.init();
    // CSP is on by default; allow one extra image host
    getCspSettings().blocking()
        .add(CSPDirective.IMG_SRC, "https://images.example.org");
}

Tested without a browser

WicketTester renders pages and components in a plain unit test: no browser, no container. Check the rendered markup, click links, submit forms.

HelloWorldTest.java
WicketTester tester = new WicketTester(new MyApplication());
tester.startPage(HelloWorld.class);
tester.assertLabel("message", "Hello World!");

General notes: also included

  1. Internationalized. Over 25 languages out of the box, with translations per application, page or component.
  2. Many tabs, one session. Automatic page state storage lets users open pages in new tabs and windows safely.
  3. Dependency injection. Integrations for CDI, Spring and Guice.
  4. Jakarta EE. Use JPA, EJB, Bean Validation and CDI through Wicket's integrations.
  5. Your JavaScript and CSS. Global libraries mix cleanly with component-local resources.
  6. Apache License 2.0. One of the most permissive open source licenses, since day one.

Apache WicketWhy WicketSheet 2 / 5

New in Wicket 11

Wicket 11 opens the quarterly release schedule. It moves to a current Java and Jakarta baseline, tightens security, makes every component leaner and lets Ajax run without jQuery.

Everything about Wicket 11 · Dates: release lines, sheet 1

A new baseline

Java
21
Jakarta Servlet
6.1
Spring
7

Wicket 11 requires Java 21 and runs on Jakarta Servlet 6.1, and its Spring integration moves to Spring 7. Applications on Wicket 10 already use jakarta.servlet, so the step up is your JDK and your container.

More secure by default

Encryption is rebuilt on one authenticated scheme: encrypted URLs and stored pages cannot be altered unnoticed, the scheme generates its own key, and encrypted URLs stay cacheable. Components that write model values into markup escape them consistently, and the content security policy now covers script-src-attr and style-src-attr.

Leaner components

A component keeps its model, behaviors and metadata in one compact state object instead of a packed array. In the benchmarks, reading that state is 30 to 45% faster, and a component tree with Ajax behaviors serializes about 40% smaller, so sessions and the page store carry less.

WICKET 10 WICKET 11 ABOUT 40% SMALLER
Serialized size of a component tree with Ajax behaviors, relative.

Ajax without jQuery

A second, plain JavaScript implementation of the Ajax engine with the same client-side API. Opt in, and your pages, including autocomplete, palette and the upload progress bar, no longer download jQuery. jQuery remains the default and now supports jQuery 4.

WicketApplication.java
@Override
protected void init() {
    super.init();
    getJavaScriptLibrarySettings().setWicketAjaxReference(
        WicketAjaxVanillaResourceReference.get());
}

Apache WicketRevision 11Sheet 3 / 5

Upgrade paths

Two lines run at any time. The LTS is the line for production: it receives security and bug fixes until the next LTS, a year later. The quarterly release brings new features and receives fixes until the next one replaces it. Features are developed on main and carry forward into every release that follows.

Support windows per line: release lines, sheet 1 · How the release schedule works

You are onYour routeGuide
Wicket 8.x or 9.x

8.x 9 (Java 11) 10 LTS (Java 17) 14 LTS, July 2027

End of life since Wicket 11.0.0: no more releases, not even security fixes. For production, move to 10 LTS: it brings jakarta.servlet, is supported until July 2027, and hands over to 14, the next LTS. 9.x moves to 10 directly; 8.x takes the Wicket 9 step first. To follow new features instead, continue from 10 to 11, which needs Java 21.

Migration to Wicket 9
Migration to Wicket 10
Wicket 10.x

Stay on the LTS until Wicket 14, the next LTS, ships in July 2027. Moving to 11 for its new features means Java 21 and Jakarta Servlet 6.1.

New in Wicket 11
Starting out

Start on the LTS when the application should change slowly, or on 11 to get new features every quarter.

Quick start

Apache WicketUpgrade pathsSheet 4 / 5

Announcements

  1. A new release cadence for Apache Wicket

    Starting with Apache Wicket 11.0, due in the first week of October 2026, Wicket moves to time-based releases: a new major release every three months, and an LTS release once a year.

  2. Apache Wicket 10.11.0 released

  3. Apache Wicket 9.24.0 released

  4. Apache Wicket 8.19.0 released

  5. Apache Wicket 10.10.0 released

News archive · Atom feed

Apache WicketAnnouncementsSheet 5 / 5