
SecurityShepherd
Web and mobile application security training platform

Web and mobile application security training platform

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

This is a defunct code base. The project is located at: https://github.com/WebGoat

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

Application Security Verification Standard

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.

Golang Secure Coding Practices guide

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest…

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Hands-on AI security lab platform with 50+ scenarios across prompt injection, agentic system exploitation, model manipulation, and MCP trust boundary…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.


Curated collection of payloads for ethical security testing and bug bounty hunting, covering common web vulnerabilities and attack vectors.

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…