Skip to main content
buildradar
Sign in
Topic · appsec

appsec

Tracked open-source repos tagged appsec, sorted by stars.

58 repos
  • OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

    1,407+5Star change over the last 7 days
  • OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

    1,383+5Star change over the last 7 days
  • vapi@roottusk

    vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

    1,349+0Star change over the last 7 days
  • leaky-paths@ayoubfathi

    A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

    1,193+0Star change over the last 7 days
  • lonkero@bountyyfi

    Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

    1,074+26Star change over the last 7 days
  • A curated list of tools officially presented at Black Hat events

    980+8Star change over the last 7 days
  • Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.

    957+5Star change over the last 7 days
  • zap-extensions@zaproxy

    ZAP Add-ons

    947+2Star change over the last 7 days
  • railsgoat@OWASP

    A vulnerable version of Rails that follows the OWASP Top 10

    923+1Star change over the last 7 days
  • community-scripts@zaproxy

    A collection of ZAP scripts and tips provided by the community - pull requests very welcome!

    893+0Star change over the last 7 days
  • :warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

    885-2Star change over the last 7 days
  • reaper@ghostsecurity

    Live validation proxy tool for testing web app vulnerabilities

    883+0Star change over the last 7 days
  • dianxing@tianchong-zerotemp

    DianXing - AI-Driven End-to-End Code Security Auditing

    872+1Star change over the last 7 days
  • dd-trace-go@DataDog

    Datadog Go Library including APM tracing, profiling, and security monitoring.

    853+0Star change over the last 7 days
  • badsecrets@blacklanternsecurity

    A library for detecting known secrets across many web frameworks

    823+2Star change over the last 7 days
  • mobsfscan@MobSF

    mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.

    783+2Star change over the last 7 days
  • Spoofy@MattKeeley

    Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.

    772-2Star change over the last 7 days
  • Cybermes@Zyrexnn

    Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.

    759+102Star change over the last 7 days
  • ovaa@oversecured

    Oversecured Vulnerable Android App

    756+2Star change over the last 7 days
  • numasec@FrancescoStabile

    The AI Agent for Cyber Security.

    754+137Star change over the last 7 days
  • Integrates Dependency-Check reports into SonarQube

    694+1Star change over the last 7 days
  • titus@praetorian-inc

    High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

    691+7Star change over the last 7 days
  • cve-lite-cli@OWASP

    Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.

    688+5Star change over the last 7 days
  • privado@Privado-Inc

    Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

    656+2Star change over the last 7 days
  • Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

    630+2Star change over the last 7 days
  • dd-trace-php@DataDog

    Datadog PHP Clients

    558+0Star change over the last 7 days
  • JShunter@cc1a2b

    jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for and bug bounty hunters and security researchers.

    534+1Star change over the last 7 days
  • SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.

    513+3Star change over the last 7 days
← Back to topics