
bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Thick Client Application Security Verification Standard

A vulnerable version of Rails that follows the OWASP Top 10

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)


Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

A scanner that files with compromised or untrusted code signing certificates written in python.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

The dependency-check repository has moved: