
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

nodejsscan is a static security code scanner for Node.js applications.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…


A static analysis security vulnerability scanner for Ruby on Rails applications

Golang Secure Coding Practices guide

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Application Security Verification Standard


Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

Bleach is an allowed-list-based HTML sanitizing library that escapes or strips markup and attributes

Mind-Maps of Several Things

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.