application-security
Tracked open-source repos tagged application-security, sorted by stars.
Related topics
Topics that frequently appear alongside application-security on the same repo.
Recent risers
Repos created in the last 90 days, tagged application-security.
- #1
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
★ 10,301 - #2
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
★ 782
- #1
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
★ 33,017+67Star change over the last 7 days - #2
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
★ 22,465+53Star change over the last 7 days - #3
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
★ 13,740+36Star change over the last 7 days - #4
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
★ 10,301+208Star change over the last 7 days - #5
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
★ 9,763+42Star change over the last 7 days - #6
A curated list of resources for learning about application security
★ 7,046+9Star change over the last 7 days - #7★ 6,803+11Star change over the last 7 days
- #8
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
★ 5,050+1Star change over the last 7 days - #9
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 3,836+115Star change over the last 7 days - #10★ 2,794+8Star change over the last 7 days
- #11
A curated list of awesome Android Reverse Engineering training, resources, and tools.
★ 2,680+12Star change over the last 7 days - #12★ 1,783+2Star change over the last 7 days
- #13
Curating the best DevSecOps resources and tooling.
★ 1,720+4Star change over the last 7 days - #14
Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.
★ 1,707+0Star change over the last 7 days - #15
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
★ 1,692+8Star change over the last 7 days - #16
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。
★ 1,200+0Star change over the last 7 days - #17
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
★ 1,169+0Star change over the last 7 days - #18
An AI-powered threat modeling tool that leverages OpenAI's GPT models to generate threat models for a given application based on the STRIDE methodology.
★ 1,109+6Star change over the last 7 days - #19
Mantis is a security framework that automates the workflow of discovery, reconnaissance, and vulnerability scanning.
★ 1,039+1Star change over the last 7 days - #20
A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure code reviews. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn pentesting and secure coding practices.
★ 924+2Star change over the last 7 days - #21
A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
★ 782+17Star change over the last 7 days - #22
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
★ 773+1Star change over the last 7 days - #23
MCP server for JADX-AI Plugin
★ 763+8Star change over the last 7 days - #24
Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.
★ 740+0Star change over the last 7 days - #25
Runtime security for AI apps and agents: prompt injection detection, tool-call authorization, sensitive-data redaction, bot protection, and rate limiting. Drop it into your JS/TS code.
★ 681+0Star change over the last 7 days - #26
A curated list of awesome iOS application security resources.
★ 670+0Star change over the last 7 days - #27
This repository contains a curated list of resources I suggest on LinkedIn and Twitter.📝🌝
★ 669+0Star change over the last 7 days - #28★ 603+1Star change over the last 7 days
- #29
SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.
★ 510+1Star change over the last 7 days