


The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

OWASP Smart Contract Security (SCS) Project

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Application Security Verification Standard

Twitter vulnerable snippets

Your gateway to OWASP. Discover, engage, and help shape the future!

The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

Open-source cross-modal and multimodal prompt injection test suite. 250,000+ attack payloads across text, image, document, and audio modalities.…

OWASP top 10 security risks for audio and video communications, documenting common vulnerabilities and threats in modern real-time communication…