
cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Source code for the Binaries of OWASP WrongSecrets

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Certified Secure-Software Developer

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.


The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

A vulnerable version of Rails that follows the OWASP Top 10

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Application Security Verification Standard

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.