
cve-lite-cli
Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Source code for the Binaries of OWASP WrongSecrets

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

OWASP Smart Contract Security (SCS) Project

OWASP Certified Secure-Software Developer

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).