
DOMPurify
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…


Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A fast, simple, recursive content discovery tool written in Rust.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

The Secure CommsOS™ for mission-critical operations

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Official Elastic Skills

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SQL injection and database takeover tool

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

UnboundID LDAP SDK for Java

Open Source Vulnerability Management Platform

A coverage-guided REST API fuzzer developed on top of LibAFL

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…