
lua-resty-waf
High-performance WAF built on the OpenResty stack

High-performance WAF built on the OpenResty stack

Keep private data, internal infrastructure and secrets out of cloud coding agents without breaking your workflow.

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Security proxy for AI agents. Scans every message for prompt injection, PII, and secrets. Defense-in-depth: Go proxy + iptables firewall + eBPF…

An open source threat modeling tool from OWASP

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

CVE-2020-9483 OR CVE-2020-13921

Browser privacy-leak detector — eight detection modules, risk scoring, and per-account history, all in your browser.

