
DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

The source files and tools needed to build the OWASP Cornucopia decks in various languages

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Vulnerable app with examples showing how to not use secrets

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Software Component Verification Standard (SCVS)

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

Executable security regression testing for agentic applications and MCP-integrated systems.