
ggshield
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

OpenSSF Scorecard - Security health metrics for Open Source

Django application that performs SAST and Malware Analysis for Android APKs

A vulnerable version of Rails that follows the OWASP Top 10

Go-based CLI tool that scans codebases for launch readiness, detecting missing configuration, security hygiene issues, secret leaks, and integration…

Application Security Verification Standard

Stored XSS via Location Title in DPCalendar Free

Xyntia, the black-box deobfuscator

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Automatic SSTI detection tool with interactive interface

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Pishi is a code coverage tool like kcov for macOS.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)