10.11.0 LTS for production
Supported until 14.0.0, July 2027
<dependency>
<groupId>org.apache.wicket</groupId>
<artifactId>wicket-core</artifactId>
<version>10.11.0</version>
</dependency>
Write less, achieve more.
A component-oriented Java web framework: plain Java, plain HTML, no JavaScript build chain.
Two release lines are in service: 10 LTS for production and 11 for new features. Wicket 11.0.0 shipped on 4 October 2026 and opens a quarterly release schedule.
Supported until 14.0.0, July 2027
<dependency>
<groupId>org.apache.wicket</groupId>
<artifactId>wicket-core</artifactId>
<version>10.11.0</version>
</dependency>
Generate a ready-to-run Maven project, or add the dependency to the build you already have.
Open the quick startSupported until 12.0.0, January 2027 · Java 21
<dependency>
<groupId>org.apache.wicket</groupId>
<artifactId>wicket-core</artifactId>
<version>11.0.0</version>
</dependency>
Out of service · ended with 11.0.0
At most two lines are maintained at once: the current LTS and the current quarterly release. A new major ships every three months; every fourth is an LTS, supported until the next one. Support applies to the release line; features carry forward from main.
| Ribbon | Line | Version | Dates | Support |
|---|---|---|---|---|
| In service | ||||
| 10 LTS For production | 10.11.0 | Since Mar 2024 | Until 14.0.0, Jul 2027 | |
| 11 For new features | 11.0.0 | Since Oct 2026 | Until 12.0.0, Jan 2027 | |
| Next | ||||
| 12 | 12.0.0 | Jan 2027 | Until 13.0.0, Apr 2027 | |
| 10 LTS | 10.12.0 | Jan 2027 | Until 14.0.0, Jul 2027 | |
| 13 | 13.0.0 | Apr 2027 | Until 14.0.0, Jul 2027 | |
| 14 LTS | 14.0.0 | Jul 2027 | Until 18.0.0, Jul 2028 | |
| Out of service | ||||
| 9 | 9.24.0 | Jul 2020 to Oct 2026 | Ended with 11.0.0 | |
| 8 | 8.19.0 | May 2018 to Oct 2026 | Ended with 11.0.0 | |
| 7 | 7.18.0 | Jul 2015 to Apr 2021 | Ended | |
| 6 | 6.30.0 | Sep 2012 to Dec 2018 | Ended | |
| 1.5 | 1.5.16 | Sep 2011 to Aug 2016 | Ended | |
| 1.4 | 1.4.23 | Jul 2009 to Feb 2014 | Ended 16 Nov 2015 | |
| 1.3 | 1.3.7 | Last release Jul 2009 | Ended with 1.3.7 | |
| 1.0 SourceForge | 1.0.2 | Aug 2005, on wicket.sourceforge.net | Ended | |
Dates give the first and the last release of each line. Before Apache, Wicket lived on SourceForge: on 22 August 2005 wicket.sourceforge.net announced maintenance release 1.0.2 and 1.1-beta 3.
Wicket is a component-oriented, server-side Java web framework. Open source since 2004 and developed at the Apache Software Foundation, it powers long-lived applications that need complex, dynamic pages without a JavaScript build chain.
Markup stays HTML that opens in any editor. Behaviour lives in Java. A wicket:id attribute binds a tag to a component, and that is the whole contract: no template language, no JavaScript toolchain.
HelloWorld.html
<h1 wicket:id="message">Message goes here</h1>
HelloWorld.java
public class HelloWorld extends WebPage {
public HelloWorld() {
add(new Label("message", "Hello World!"));
}
}
Pages and components are real Java objects with encapsulation, inheritance and events. Build a panel once, with its own markup, styles and scripts, and reuse it on every page, or ship a whole component library as a JAR.
AddressPanel.java
public class AddressPanel extends Panel {
public AddressPanel(String id, IModel<Address> address) {
super(id, new CompoundPropertyModel<>(address));
add(new TextField<String>("street"));
add(new TextField<String>("city"));
}
}
// one component, used twice on the same form
form.add(new AddressPanel("billing", billingAddress));
form.add(new AddressPanel("shipping", shippingAddress));
Update parts of a page from Java. Wicket's Ajax components re-render only the components you add to the request, and come with a solid set of building blocks.
CounterPage.java
Label count = new Label("count", () -> clicks);
add(count.setOutputMarkupId(true));
add(new AjaxLink<Void>("increment") {
@Override
public void onClick(AjaxRequestTarget target) {
clicks++;
target.add(count);
}
});
Component paths are session-relative and URLs do not expose your model. Wicket supports a strict Content Security Policy without unsafe-inline: every header contribution gets a nonce automatically. You only add what your application needs.
MyApplication.java
@Override
protected void init() {
super.init();
// CSP is on by default; allow one extra image host
getCspSettings().blocking()
.add(CSPDirective.IMG_SRC, "https://images.example.org");
}
WicketTester renders pages and components in a plain unit test: no browser, no container. Check the rendered markup, click links, submit forms.
HelloWorldTest.java
WicketTester tester = new WicketTester(new MyApplication());
tester.startPage(HelloWorld.class);
tester.assertLabel("message", "Hello World!");
Wicket 11 opens the quarterly release schedule. It moves to a current Java and Jakarta baseline, tightens security, makes every component leaner and lets Ajax run without jQuery.
Everything about Wicket 11Java 21Jakarta Servlet 6.1Spring 7
Wicket 11 requires Java 21 and runs on Jakarta Servlet 6.1, and its Spring integration moves to Spring 7. Applications on Wicket 10 already use jakarta.servlet, so the step up is your JDK and your container.
Encryption is rebuilt on one authenticated scheme: encrypted URLs and stored pages cannot be altered unnoticed, the scheme generates its own key, and encrypted URLs stay cacheable. Components that write model values into markup escape them consistently, and the content security policy now covers script-src-attr and style-src-attr.
A component keeps its model, behaviors and metadata in one compact state object instead of a packed array. In the benchmarks, reading that state is 30 to 45% faster, and a component tree with Ajax behaviors serializes about 40% smaller, so sessions and the page store carry less.
A second, plain JavaScript implementation of the Ajax engine with the same client-side API. Opt in, and your pages, including autocomplete, palette and the upload progress bar, no longer download jQuery. jQuery remains the default and now supports jQuery 4.
WicketApplication.java
@Override
protected void init() {
super.init();
getJavaScriptLibrarySettings().setWicketAjaxReference(
WicketAjaxVanillaResourceReference.get());
}
Two lines run at any time. The LTS is the line for production: it receives security and bug fixes until the next LTS, a year later. The quarterly release brings new features and receives fixes until the next one replaces it.
End of life since Wicket 11.0.0: no more releases, not even security fixes. For production, move to 10 LTS: it brings jakarta.servlet, is supported until July 2027, and hands over to 14, the next LTS. 9.x moves to 10 directly; 8.x takes the Wicket 9 step first. To follow new features instead, continue from 10 to 11, which needs Java 21.
Stay on the LTS until Wicket 14, the next LTS, ships in July 2027. Moving to 11 for its new features means Java 21 and Jakarta Servlet 6.1.
Start on the LTS when the application should change slowly, or on 11 to get new features every quarter.
Starting with Apache Wicket 11.0, due in the first week of October 2026, Wicket moves to time-based releases: a new major release every three months, and an LTS release once a year. Wicket 10 is our current LTS and remains supported until the release of Wicket 14, expected in the first week of July 2027.
Many applications run on Wicket without saying so. Some say so through the Built with Wicket feed: ING Germany's internet banking, the ATLAS experiment at CERN for its controls and configuration software, Air Tahiti, the OneDev git server and Stellantis' media libraries among them.