
Benchmark
The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Some good resources for getting started with application security

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

WEB SERVICE SECURITY ASSESSMENT TOOL

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…