
java-html-sanitizer
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

OWASP Certified Secure-Software Developer

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

A vulnerable version of Rails that follows the OWASP Top 10

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Source code for the Binaries of OWASP WrongSecrets

Application Security Verification Standard


Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.


OWASP Smart Contract Security (SCS) Project