
owasp-scs
OWASP Smart Contract Security (SCS) Project

OWASP Smart Contract Security (SCS) Project

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A vulnerable version of Rails that follows the OWASP Top 10

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Source code for the Binaries of OWASP WrongSecrets

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava