
O-Saft
O-Saft - OWASP SSL advanced forensic tool

O-Saft - OWASP SSL advanced forensic tool

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…


A scanner that files with compromised or untrusted code signing certificates written in python.


SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)


Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Next generation web scanner

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

Simple JMX RMI scanning tool