Skip to content
@OWASP

OWASP

The OWASP Foundation

Popular repositories Loading

  1. CheatSheetSeries CheatSheetSeries Public

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    Python 33.2k 4.6k

  2. mastg mastg Public

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

    Python 13.2k 2.8k

  3. wstg wstg Public

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    Python 9.9k 1.7k

  4. Top10 Top10 Public

    Official OWASP Top 10 Document Repository

    HTML 6.1k 1.1k

  5. Nettacker Nettacker Public

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

    Python 5.6k 1.2k

  6. Go-SCP Go-SCP Public

    Golang Secure Coding Practices guide

    Go 5.3k 406

Repositories

Showing 10 of 1417 repositories
  • owasp-ctf-in-a-box Public

    Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

    OWASP/owasp-ctf-in-a-box's past year of commit activity
    TypeScript 11 MIT 4 15 1 Updated Sep 20, 2026
  • OWASP-CRT Public

    An automated tool to verify contributions and generate verifiable credentials for OWASP community members.

    JavaScript 4 MIT 10 3 (1 issue needs help) 0 Updated Sep 20, 2026
  • www-project-webshield-library Public

    OWASP Foundation web repository

    OWASP/www-project-webshield-library's past year of commit activity
    JavaScript 6 Apache-2.0 8 12 (2 issues need help) 6 Updated Sep 20, 2026
  • openshield Public

    Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with one command

    OWASP/openshield's past year of commit activity
    Python 57 MIT 69 30 13 Updated Sep 21, 2026
  • DockSec Public

    AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

    OWASP/DockSec's past year of commit activity
    Python 484 MIT 99 3 15 Updated Sep 20, 2026
  • wrongsecrets Public

    Vulnerable app with examples showing how to not use secrets

    OWASP/wrongsecrets's past year of commit activity
    HTML 1,467 AGPL-3.0 626 24 (8 issues need help) 4 Updated Sep 20, 2026
  • cornucopia Public

    The source files and tools needed to build the OWASP Cornucopia decks in various languages

    OWASP/cornucopia's past year of commit activity
    Python 146 CC-BY-SA-4.0 99 23 (12 issues need help) 4 Updated Sep 20, 2026
  • cve-lite-cli Public

    Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix, JSON output, and practical remediation guidance.

    OWASP/cve-lite-cli's past year of commit activity
    TypeScript 720 MIT 148 46 (8 issues need help) 21 Updated Sep 20, 2026
  • AISVS Public

    The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to verify the security of AI-driven applications.

    OWASP/AISVS's past year of commit activity
    451 CC-BY-SA-4.0 133 9 3 Updated Sep 20, 2026
  • mastg Public

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

    OWASP/mastg's past year of commit activity
    Python 13,190 CC-BY-SA-4.0 2,806 194 45 Updated Sep 20, 2026