
www-community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.


Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

An open source threat modeling tool from OWASP

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The Secure Coding Practices Quick-reference Guide from OWASP

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Vulnerable app with examples showing how to not use secrets

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.