Apache Wicket

Apache Wicket , version 11

Write less, achieve more.

A component-oriented Java web framework: plain Java, plain HTML, no JavaScript build chain.

Two release lines are in service: 10 LTS for production and 11 for new features. Wicket 11.0.0 shipped on 4 October 2026 and opens a quarterly release schedule.

10.11.0 LTS for production

Supported until 14.0.0, July 2027

<dependency>
  <groupId>org.apache.wicket</groupId>
  <artifactId>wicket-core</artifactId>
  <version>10.11.0</version>
</dependency>

Start a project

Generate a ready-to-run Maven project, or add the dependency to the build you already have.

Open the quick start

11.0.0 for new features

Supported until 12.0.0, January 2027 · Java 21

<dependency>
  <groupId>org.apache.wicket</groupId>
  <artifactId>wicket-core</artifactId>
  <version>11.0.0</version>
</dependency>

Wicket 9

Out of service · ended with 11.0.0

First release
9.0.0 · 15 Jul 2020
Last release
9.24.0 · 30 Aug 2026
Support
Ended with 11.0.0

Release lines

At most two lines are maintained at once: the current LTS and the current quarterly release. A new major ships every three months; every fourth is an LTS, supported until the next one. Support applies to the release line; features carry forward from main.

How the release schedule works

Apache Wicket release lines, in service, scheduled and out of service
RibbonLineVersionDatesSupport
In service
10 LTS For production10.11.0Since Mar 2024Until 14.0.0, Jul 2027
11 For new features11.0.0Since Oct 2026Until 12.0.0, Jan 2027
Next
1212.0.0Jan 2027Until 13.0.0, Apr 2027
10 LTS10.12.0Jan 2027Until 14.0.0, Jul 2027
1313.0.0Apr 2027Until 14.0.0, Jul 2027
14 LTS14.0.0Jul 2027Until 18.0.0, Jul 2028
Out of service
99.24.0Jul 2020 to Oct 2026Ended with 11.0.0
88.19.0May 2018 to Oct 2026Ended with 11.0.0
77.18.0Jul 2015 to Apr 2021Ended
66.30.0Sep 2012 to Dec 2018Ended
1.51.5.16Sep 2011 to Aug 2016Ended
1.41.4.23Jul 2009 to Feb 2014Ended 16 Nov 2015
1.31.3.7Last release Jul 2009Ended with 1.3.7
1.0 SourceForge1.0.2Aug 2005, on wicket.sourceforge.netEnded

Dates give the first and the last release of each line. Before Apache, Wicket lived on SourceForge: on 22 August 2005 wicket.sourceforge.net announced maintenance release 1.0.2 and 1.1-beta 3.

Why Wicket

Wicket is a component-oriented, server-side Java web framework. Open source since 2004 and developed at the Apache Software Foundation, it powers long-lived applications that need complex, dynamic pages without a JavaScript build chain.

  1. Plain Java and plain HTML

    Markup stays HTML that opens in any editor. Behaviour lives in Java. A wicket:id attribute binds a tag to a component, and that is the whole contract: no template language, no JavaScript toolchain.

    HelloWorld.html

    <h1 wicket:id="message">Message goes here</h1>

    HelloWorld.java

    public class HelloWorld extends WebPage {
        public HelloWorld() {
            add(new Label("message", "Hello World!"));
        }
    }
  2. Components for complex pages

    Pages and components are real Java objects with encapsulation, inheritance and events. Build a panel once, with its own markup, styles and scripts, and reuse it on every page, or ship a whole component library as a JAR.

    AddressPanel.java

    public class AddressPanel extends Panel {
        public AddressPanel(String id, IModel<Address> address) {
            super(id, new CompoundPropertyModel<>(address));
            add(new TextField<String>("street"));
            add(new TextField<String>("city"));
        }
    }
    
    // one component, used twice on the same form
    form.add(new AddressPanel("billing", billingAddress));
    form.add(new AddressPanel("shipping", shippingAddress));
  3. Ajax without writing JavaScript

    Update parts of a page from Java. Wicket's Ajax components re-render only the components you add to the request, and come with a solid set of building blocks.

    CounterPage.java

    Label count = new Label("count", () -> clicks);
    add(count.setOutputMarkupId(true));
    
    add(new AjaxLink<Void>("increment") {
        @Override
        public void onClick(AjaxRequestTarget target) {
            clicks++;
            target.add(count);
        }
    });
  4. Secure by default

    Component paths are session-relative and URLs do not expose your model. Wicket supports a strict Content Security Policy without unsafe-inline: every header contribution gets a nonce automatically. You only add what your application needs.

    MyApplication.java

    @Override
    protected void init() {
        super.init();
        // CSP is on by default; allow one extra image host
        getCspSettings().blocking()
            .add(CSPDirective.IMG_SRC, "https://images.example.org");
    }
  5. Tested without a browser

    WicketTester renders pages and components in a plain unit test: no browser, no container. Check the rendered markup, click links, submit forms.

    HelloWorldTest.java

    WicketTester tester = new WicketTester(new MyApplication());
    tester.startPage(HelloWorld.class);
    tester.assertLabel("message", "Hello World!");

Also included

Internationalized
Over 25 languages out of the box, with translations per application, page or component.
Many tabs, one session
Automatic page state storage lets users open pages in new tabs and windows safely.
Dependency injection
Integrations for CDI, Spring and Guice.
Jakarta EE
Use JPA, EJB, Bean Validation and CDI through Wicket's integrations.
Your JavaScript and CSS
Global libraries mix cleanly with component-local resources.
Apache License 2.0
One of the most permissive open source licenses, since day one.

New in Wicket 11

Wicket 11 opens the quarterly release schedule. It moves to a current Java and Jakarta baseline, tightens security, makes every component leaner and lets Ajax run without jQuery.

Everything about Wicket 11

A new baseline

Java 21Jakarta Servlet 6.1Spring 7

Wicket 11 requires Java 21 and runs on Jakarta Servlet 6.1, and its Spring integration moves to Spring 7. Applications on Wicket 10 already use jakarta.servlet, so the step up is your JDK and your container.

More secure by default

Encryption is rebuilt on one authenticated scheme: encrypted URLs and stored pages cannot be altered unnoticed, the scheme generates its own key, and encrypted URLs stay cacheable. Components that write model values into markup escape them consistently, and the content security policy now covers script-src-attr and style-src-attr.

Leaner components

A component keeps its model, behaviors and metadata in one compact state object instead of a packed array. In the benchmarks, reading that state is 30 to 45% faster, and a component tree with Ajax behaviors serializes about 40% smaller, so sessions and the page store carry less.

Ajax without jQuery

A second, plain JavaScript implementation of the Ajax engine with the same client-side API. Opt in, and your pages, including autocomplete, palette and the upload progress bar, no longer download jQuery. jQuery remains the default and now supports jQuery 4.

WicketApplication.java

@Override
protected void init() {
    super.init();
    getJavaScriptLibrarySettings().setWicketAjaxReference(
        WicketAjaxVanillaResourceReference.get());
}

Upgrade paths

Two lines run at any time. The LTS is the line for production: it receives security and bug fixes until the next LTS, a year later. The quarterly release brings new features and receives fixes until the next one replaces it.

From Wicket 8.x or 9.x

  1. 8.x
  2. 9 Java 11
  3. 10 LTS Java 17
  4. 14 LTS July 2027

End of life since Wicket 11.0.0: no more releases, not even security fixes. For production, move to 10 LTS: it brings jakarta.servlet, is supported until July 2027, and hands over to 14, the next LTS. 9.x moves to 10 directly; 8.x takes the Wicket 9 step first. To follow new features instead, continue from 10 to 11, which needs Java 21.

Migration to Wicket 9 Migration to Wicket 10

From Wicket 10.x

  1. 10 LTS until July 2027
  2. 14 LTS until 18.0.0

Stay on the LTS until Wicket 14, the next LTS, ships in July 2027. Moving to 11 for its new features means Java 21 and Jakarta Servlet 6.1.

New in Wicket 11

Starting out

  1. 10 LTS changes slowly
  2. 11 new features every quarter

Start on the LTS when the application should change slowly, or on 11 to get new features every quarter.

Quick start

Announcements

  1. A new release cadence for Apache Wicket

    Starting with Apache Wicket 11.0, due in the first week of October 2026, Wicket moves to time-based releases: a new major release every three months, and an LTS release once a year. Wicket 10 is our current LTS and remains supported until the release of Wicket 14, expected in the first week of July 2027.

Built with Wicket

Many applications run on Wicket without saying so. Some say so through the Built with Wicket feed: ING Germany's internet banking, the ATLAS experiment at CERN for its controls and configuration software, Air Tahiti, the OneDev git server and Stellantis' media libraries among them.

Submit your own project