
opentaint
Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

A static + runtime security scanner for MCP (Model Context Protocol) servers

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

Application Security Verification Standard

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

IaC threat modeler with STRIDE, MITRE ATT&CK, and PASTA frameworks. REST API, GraphQL, and Docker support for Terraform, CloudFormation, and…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

OWASP Secure Agent Playbook Project

Scan codebases and GCP projects for exposed API credentials

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Discover input surfaces and security issues in compiled .NET assemblies — without running them.