Content that doesn’t change or that doesn’t change often should be included using a mechanism which won’t try to interpret it. Specifically,
<%@ include file="..." %>
, which includes the file in the JSP servlet translation phase (i.e. it happens once), should be used
instead of <jsp:include page="..." />
, which includes the page on the file, when the content is being served to the user.
Noncompliant code example
<jsp:include page="header.jsp"> <!-- Noncompliant -->
Compliant solution
<%@ include file="header.jsp" %>