
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Golang Secure Coding Practices guide

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Application Security Verification Standard

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.


Twitter vulnerable snippets


Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Vulnerability Patterns Detector for C# and VB.NET

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A vulnerable version of Rails that follows the OWASP Top 10

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.