
cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

OWASP Certified Secure-Software Developer

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Source code for the Binaries of OWASP WrongSecrets

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

A vulnerable version of Rails that follows the OWASP Top 10

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

OWASP Smart Contract Security (SCS) Project

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…