



Find authentication (authn) and authorization (authz) security bugs in web application routes.

Real-time web application weakness monitoring SDK and scanner. Detects XSS, SQL injection, sensitive payloads, and code vulnerabilities via dynamic…

A curated list of awesome iOS application security resources.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Static and dynamic Android application security analysis

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Some good resources for getting started with application security

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

A vulnerable version of Rails that follows the OWASP Top 10

A source code static analysis platform for AppSec enthusiasts.
