
bluemonday
bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Some good resources for getting started with application security

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

A vulnerable version of Rails that follows the OWASP Top 10

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Certified Secure-Software Developer

OWASP Secure Agent Playbook Project

OWASP Smart Contract Security (SCS) Project

Source code for the Binaries of OWASP WrongSecrets

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)