
RiskAssessmentFramework
The Secure Coding Framework

The Secure Coding Framework

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

⚡️ Multiple target ZAP Scanning

Automated Security Testing For REST API's

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Terminal API client for HTTP, GraphQL and gRPC. Plain .http files you can diff and version, with workflows, mocks, profiling, tracing, OpenAPI…

An open source threat modeling tool from OWASP

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Vulnerable app with examples showing how to not use secrets

Next-generation dependency vulnerability scanner with reachability analysis, SBOM generation, license audit, and container image scanning for CI/CD…


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…