
AISVS
The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…


Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Source code for the Binaries of OWASP WrongSecrets

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP Secure Agent Playbook Project

OWASP Certified Secure-Software Developer

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.


Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.