web-security
Tracked open-source repos tagged web-security, sorted by stars.
Related topics
Topics that frequently appear alongside web-security on the same repo.
Recent risers
Repos created in the last 90 days, tagged web-security.
- #1
Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.
★ 1,093
- #1
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
★ 22,480+15Star change over the last 7 days - #2
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
★ 21,688+24Star change over the last 7 days - #3★ 14,525+5Star change over the last 7 days
- #4
A list of resources for those interested in getting started in bug bounties
★ 12,218+12Star change over the last 7 days - #5★ 10,895+14Star change over the last 7 days
- #6
A list of web application security
★ 7,256+7Star change over the last 7 days - #7
A curated list of various bug bounty tools
★ 6,230+10Star change over the last 7 days - #8
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
★ 4,118+282Star change over the last 7 days - #9
Awesome Node.js Security resources
★ 3,036+6Star change over the last 7 days - #10
系统性的 PHP 技术面试问答大全(面经)。涵盖 PHP8、MySQL、Redis、Nginx、系统设计、算法、Laravel 源码及高并发架构原理,助你斩获后端研发 Offer。PHP Interview Questions & Answers.
★ 2,959+2Star change over the last 7 days - #11
DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic
★ 2,935+17Star change over the last 7 days - #12★ 1,760-1Star change over the last 7 days
- #13
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
★ 1,677+2Star change over the last 7 days - #14
🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.
★ 1,666+3Star change over the last 7 days - #15
🌐 The all-in-one tool, for keeping track of your domain name portfolio. Got domain names? Get Domain Locker!
★ 1,507+6Star change over the last 7 days - #16
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
★ 1,477+40Star change over the last 7 days - #17
LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/
★ 1,469+0Star change over the last 7 days - #18
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown
★ 1,440+2Star change over the last 7 days - #19
Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.
★ 1,236+2Star change over the last 7 days - #20
A Huge Learning Resources with Labs For Offensive Security Players
★ 1,169+2Star change over the last 7 days - #21
Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.
★ 1,093—Star change over the last 7 days - #22
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
★ 1,074+26Star change over the last 7 days - #23
Modern Python library for HTTP security headers with safe defaults, configurable presets, and first-class ASGI/WSGI middleware (FastAPI, Django, Flask, Shiny, and more).
★ 1,054+2Star change over the last 7 days - #24
JavaSecLab is a comprehensive Java vulnerability platform| JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……
★ 876+1Star change over the last 7 days - #25
Website specification — HTML, accessibility, security, SEO, agent-readiness. Platform-agnostic, sourced, MIT.
★ 849+3Star change over the last 7 days - #26
Caddy WAF (Regex Rules, IP and DNS filtering, Rate Limiting, GeoIP, Tor, Anomaly Detection)
★ 814+6Star change over the last 7 days - #27
面向小白用户的 CTF / 逆向 Skills 整合包:自动分流、头脑风暴、教学模式、比赛模式、只提示模式
★ 800+11Star change over the last 7 days - #28
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.
★ 774+0Star change over the last 7 days - #29★ 754+137Star change over the last 7 days
- #30★ 738+1Star change over the last 7 days