Reducing the ESAPI Library's Attack Surface - ESAPI/esapi-java-legacy GitHub Wiki
TODO - We should create a GitHub issue to track this
The general idea behind this is rather than having all the ESAPI components enabled by default, some of the ones (e.g., ones which have reference implementations that were intended as models to base customized versions on, but are not in themselves scalable implementations) would be included here.
This wiki article should discuss the pros and cons, compare it to other mechanisms such as deprecation, and describe the ESAPI mechanism in detail.