OWASP
OWASP's tracked open-source repos, sorted by stars.
- #1
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
★ 33,054+37Star change over the last 7 days - #2
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
★ 13,152+9Star change over the last 7 days - #3
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
★ 9,779+16Star change over the last 7 days - #4★ 6,038+11Star change over the last 7 days
- #5
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
★ 5,548+6Star change over the last 7 days - #6★ 5,290+5Star change over the last 7 days
- #7★ 3,586+6Star change over the last 7 days
- #8
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
★ 2,441+2Star change over the last 7 days - #9
OWASP API Security Project
★ 2,342+2Star change over the last 7 days - #10★ 2,168-1Star change over the last 7 days
- #11
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
★ 2,062+2Star change over the last 7 days - #12
An open source threat modeling tool from OWASP
★ 1,577+4Star change over the last 7 days - #13★ 1,567+1Star change over the last 7 days
- #14
QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.
★ 1,562+3Star change over the last 7 days - #15
Vulnerable app with examples showing how to not use secrets
★ 1,459+0Star change over the last 7 days - #16
Web and mobile application security training platform
★ 1,456+0Star change over the last 7 days - #17
OWASP Foundation Web Respository
★ 1,435+2Star change over the last 7 days - #18
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
★ 1,407+5Star change over the last 7 days - #19
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
★ 1,383+5Star change over the last 7 days - #20★ 1,196+4Star change over the last 7 days
- #21★ 1,155+0Star change over the last 7 days
- #22
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
★ 1,103+4Star change over the last 7 days - #23
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.
★ 950+1Star change over the last 7 days - #24
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
★ 931+8Star change over the last 7 days - #25★ 923+1Star change over the last 7 days
- #26
:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory
★ 885-2Star change over the last 7 days - #27
OWASP Foundation web repository
★ 796+8Star change over the last 7 days - #28★ 694+2Star change over the last 7 days
- #29
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.
★ 686+5Star change over the last 7 days - #30
The OWASP OFFAT tool autonomously assesses your API for prevalent vulnerabilities, though full compatibility with OAS v3 is pending. The project remains a work in progress, continuously evolving towards completion.
★ 671-1Star change over the last 7 days - #31
OWASP Foundation main site repository
★ 665+1Star change over the last 7 days - #32★ 652+0Star change over the last 7 days
- #33
OWASP Foundation Web Respository
★ 619+1Star change over the last 7 days - #34
The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.
★ 616+2Star change over the last 7 days - #35
The Secure Coding Dojo is a platform for delivering secure coding knowledge.
★ 609+0Star change over the last 7 days - #36
The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting!
★ 541+0Star change over the last 7 days