
Go-SCP
Golang Secure Coding Practices guide

Golang Secure Coding Practices guide

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Next generation web scanner

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

An open source threat modeling tool from OWASP

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

The source files and tools needed to build the OWASP Cornucopia decks in various languages

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

The WASM Based Security Toolkit for the Web First Paradigm

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.