OSS TanbouSign in with GitHub

integrate authentication, authorization, cryptography, and session management into Java applications

OSS scale score 288.0OSS health 100
About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
4,460
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 1, 2026
On this page

Overview

Apache Shiro is a Java security framework for authentication, authorization, cryptography, and session management. Its API can secure applications ranging from small programs to web and enterprise systems.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Handle authentication and authorization through a shared security API

The README identifies authentication, authorization, cryptography, and session management as Shiro's core capabilities.

Sources: [2]

Apply the security model across different kinds of Java applications

Shiro is intended for applications ranging from small deployments to web and enterprise systems rather than being tied to one specific container.

Sources: [2]

Best fit

Fits Java backends that want explicit control over identity, permissions, and sessions

It is a candidate when teams want to compose application security around Shiro APIs instead of delegating the full model to a larger application framework.

Sources: [2]

Before adoption

Follow security updates around RememberMe serialization and request paths

Version 3.0.1 adds JEP-290 ObjectInputFilter support for RememberMe deserialization, replay controls, fail-closed request-path normalization, and related security hardening.

Sources: [3]

Official sources

  1. [1]apache/shiro — GitHub repository(2026-10-06)
  2. [2]Apache Shiro — README(2026-10-06)
  3. [3]Apache Shiro 3.0.1 release(2026-10-06)
Supplemental curator note

It fits Java applications that need authentication and authorization without tying security to a single web stack. Keep RememberMe, session serialization, and request-path handling current with security patch releases.

Try it in 3 steps

  1. 1

    Get the source

    git clone --depth 1 https://github.com/apache/shiro.git
  2. 2

    Enter the repository

    cd shiro
  3. 3

    Check the official steps

    Continue with the commands in the README Installation, Quick Start, or Getting Started section.

    find . -maxdepth 1 -iname 'README*' -exec sed -n '1,220p' {} \; -quit
Check the official README

Growth

Growth trends · Last 30 days

4,460 Stars

Trend data is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • java
  • library
  • shiro
  • web-framework
Stars
4,460
Forks
2,291
Watchers
4,460
Open issues
7
Contributors
82
Owner type
Organization
Primary language
Java
License
Apache-2.0
Repository last updated
Oct 1, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?