
java-html-sanitizer
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

A vulnerable version of Rails that follows the OWASP Top 10

A source code static analysis platform for AppSec enthusiasts.

A scanner and testter of the CVE-2025-11001 of 7-zip

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.


A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…

Documentation and reverse engineering of reCAPTCHA

Gixy-Next: NGINX Configuration Security Scanner & Performance Checker

Script to audit GitHub Action Workflow files for potential vulnerabilities.

A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会

Wireshark-like forensic analysis for Model Context Protocol communications Capture, inspect, and investigate all HTTP requests and responses between…

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers