



Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

OWASP Thick Client Application Security Verification Standard

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

A vulnerable version of Rails that follows the OWASP Top 10

A source code static analysis platform for AppSec enthusiasts.

SQL Injection vulnerability discovered in Grocery Store Management System 1.0