Skip to main content
buildradar
Sign in
Topic · web-security

web-security

Tracked open-source repos tagged web-security, sorted by stars.

Repos
44
Total stars
137,401
Avg. stars
3,123
Share
0.01%

Topics that frequently appear alongside web-security on the same repo.

Recent risers

Repos created in the last 90 days, tagged web-security.

  • open-reverselab@LING71671

    Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.

    1,093
  • SafeLine@chaitin

    SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

    22,480+15Star change over the last 7 days
  • Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

    21,688+24Star change over the last 7 days
  • hacker101@Hacker0x01

    Source code for Hacker101.com - a free online web and mobile security class.

    14,525+5Star change over the last 7 days
  • A list of resources for those interested in getting started in bug bounties

    12,218+12Star change over the last 7 days
  • bunkerweb@bunkerity

    🛡️ Open-source and cloud-native Web Application Firewall (WAF)

    10,895+14Star change over the last 7 days
  • A list of web application security

    7,256+7Star change over the last 7 days
  • A curated list of various bug bounty tools

    6,230+10Star change over the last 7 days
  • Claude-BugHunter@elementalsouls

    A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.

    4,118+282Star change over the last 7 days
  • Awesome Node.js Security resources

    3,036+6Star change over the last 7 days
  • PHP-Interview-QA@colinlet

    系统性的 PHP 技术面试问答大全(面经)。涵盖 PHP8、MySQL、Redis、Nginx、系统设计、算法、Laravel 源码及高并发架构原理,助你斩获后端研发 Offer。PHP Interview Questions & Answers.

    2,959+2Star change over the last 7 days
  • DDoS-Ripper@palahsu

    DDos Ripper a Distributable Denied-of-Service (DDOS) attack server that cuts off targets or surrounding infrastructure in a flood of Internet traffic

    2,935+17Star change over the last 7 days
  • JYso@qi4L

    JNDIExploit or a ysoserial.

    1,760-1Star change over the last 7 days
  • A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

    1,677+2Star change over the last 7 days
  • GitHacker@WangYihang

    🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

    1,666+3Star change over the last 7 days
  • domain-locker@lissy93

    🌐 The all-in-one tool, for keeping track of your domain name portfolio. Got domain names? Get Domain Locker!

    1,507+6Star change over the last 7 days
  • burp-ai-agent@six2dez

    Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

    1,477+40Star change over the last 7 days
  • lunasec@lunasec-io

    LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and Builds. Protect yourself in 30 seconds with the LunaTrace GitHub App: https://github.com/marketplace/lunatrace-by-lunasec/

    1,469+0Star change over the last 7 days
  • Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown

    1,440+2Star change over the last 7 days
  • cherrybomb@blst-security

    Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

    1,236+2Star change over the last 7 days
  • A Huge Learning Resources with Labs For Offensive Security Players

    1,169+2Star change over the last 7 days
  • open-reverselab@LING71671

    Agent-native reverse-engineering lab with a 197-article knowledge base, MCP tools, and CTF/APK/PE automation workflows.

    1,093Star change over the last 7 days
  • lonkero@bountyyfi

    Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

    1,074+26Star change over the last 7 days
  • secure@TypeError

    Modern Python library for HTTP security headers with safe defaults, configurable presets, and first-class ASGI/WSGI middleware (FastAPI, Django, Flask, Shiny, and more).

    1,054+2Star change over the last 7 days
  • JavaSecLab@whgojp

    JavaSecLab is a comprehensive Java vulnerability platform|​ JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……

    876+1Star change over the last 7 days
  • specification.website@jdevalk

    Website specification — HTML, accessibility, security, SEO, agent-readiness. Platform-agnostic, sourced, MIT.

    849+3Star change over the last 7 days
  • caddy-waf@fabriziosalmi

    Caddy WAF (Regex Rules, IP and DNS filtering, Rate Limiting, GeoIP, Tor, Anomaly Detection)

    814+6Star change over the last 7 days
  • ctf-super-hub@asdfgh1445

    面向小白用户的 CTF / 逆向 Skills 整合包:自动分流、头脑风暴、教学模式、比赛模式、只提示模式

    800+11Star change over the last 7 days
  • lookyloo@Lookyloo

    Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.

    774+0Star change over the last 7 days
  • numasec@FrancescoStabile

    The AI Agent for Cyber Security.

    754+137Star change over the last 7 days
  • aaWAF@aaPanel

    aawaf 是一款基于语义分析的Web应用防火墙

    738+1Star change over the last 7 days
← Back to topics