
apicheck
Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

OWASP Autonomous Penetration Testing Standard

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

Security standard for agent skills, providing guidelines and best practices to secure AI-driven autonomous agents in cloud and API environments.