
WebGoat
This is a defunct code base. The project is located at: https://github.com/WebGoat

This is a defunct code base. The project is located at: https://github.com/WebGoat

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.


Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Twitter vulnerable snippets

A vulnerable version of Rails that follows the OWASP Top 10

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

OWASP Secure Agent Playbook Project

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

OWASP Foundation Web Respository

Application Security Verification Standard