
OCSD
OWASP Certified Secure-Software Developer

OWASP Certified Secure-Software Developer

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Golang Secure Coding Practices guide

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Twitter vulnerable snippets

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

OWASP Smart Contract Security (SCS) Project

The Secure Coding Framework

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…


SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)


Automated testing suite with live traffic record and replay

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.