
IoTGoat
Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.


The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

A vulnerable version of Rails that follows the OWASP Top 10

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Secure Agent Playbook Project

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

OWASP Foundation Web Respository

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Golang Secure Coding Practices guide

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Application Security Verification Standard