
owasp-java-encoder
The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…


Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Source code for the Binaries of OWASP WrongSecrets

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.


Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…