Skip to main content
buildradar
Sign in
Owner · OWASP

OWASP

OWASP's tracked open-source repos, sorted by stars.

36 repos
  • The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    33,054+37Star change over the last 7 days
  • mastg@OWASP

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

    13,152+9Star change over the last 7 days
  • wstg@OWASP

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    9,779+16Star change over the last 7 days
  • Top10@OWASP

    Official OWASP Top 10 Document Repository

    6,038+11Star change over the last 7 days
  • Nettacker@OWASP

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

    5,548+6Star change over the last 7 days
  • Go-SCP@OWASP

    Golang Secure Coding Practices guide

    5,290+5Star change over the last 7 days
  • ASVS@OWASP

    Application Security Verification Standard

    3,586+6Star change over the last 7 days
  • masvs@OWASP

    The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

    2,441+2Star change over the last 7 days
  • API-Security@OWASP

    OWASP API Security Project

    2,342+2Star change over the last 7 days
  • The OWASP Developer Guide

    2,168-1Star change over the last 7 days
  • NodeGoat@OWASP

    The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

    2,062+2Star change over the last 7 days
  • threat-dragon@OWASP

    An open source threat modeling tool from OWASP

    1,577+4Star change over the last 7 days
  • crAPI@OWASP

    completely ridiculous API (crAPI)

    1,567+1Star change over the last 7 days
  • QRLJacking@OWASP

    QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.

    1,562+3Star change over the last 7 days
  • wrongsecrets@OWASP

    Vulnerable app with examples showing how to not use secrets

    1,459+0Star change over the last 7 days
  • Web and mobile application security training platform

    1,456+0Star change over the last 7 days
  • OWASP Foundation Web Respository

    1,435+2Star change over the last 7 days
  • OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    1,407+5Star change over the last 7 days
  • OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

    1,383+5Star change over the last 7 days
  • joomscan@OWASP

    OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/

    1,196+4Star change over the last 7 days
  • pytm@OWASP

    A Pythonic framework for threat modeling

    1,155+0Star change over the last 7 days
  • The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

    1,103+4Star change over the last 7 days
  • Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

    950+1Star change over the last 7 days
  • IoTGoat@OWASP

    IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.

    931+8Star change over the last 7 days
  • railsgoat@OWASP

    A vulnerable version of Rails that follows the OWASP Top 10

    923+1Star change over the last 7 days
  • :warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

    885-2Star change over the last 7 days
  • OWASP Foundation web repository

    796+8Star change over the last 7 days
  • APTS@OWASP

    OWASP Autonomous Penetration Testing Standard

    694+2Star change over the last 7 days
  • cve-lite-cli@OWASP

    Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.

    686+5Star change over the last 7 days
  • OFFAT@OWASP

    The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.

    671-1Star change over the last 7 days
  • OWASP Foundation main site repository

    665+1Star change over the last 7 days
  • ZSC@OWASP

    OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

    652+0Star change over the last 7 days
  • OWASP Foundation Web Respository

    619+1Star change over the last 7 days
  • The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.

    616+2Star change over the last 7 days
  • The Secure Coding Dojo is a platform for delivering secure coding knowledge.

    609+0Star change over the last 7 days
  • The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting!

    541+0Star change over the last 7 days
← Back to owner ranking