
vapi
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Automated HTTP Request Repeating With Burp Suite

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

OWASP ZSC - Shellcode/Obfuscate Code Generator https://www.secologist.com/

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

WEB SERVICE SECURITY ASSESSMENT TOOL

OWASP Mth3l3m3nt Framework is a penetration testing aiding tool and exploitation framework. It fosters a principle of attack the web using the web as…

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

Rust-powered HTTP Request Smuggling Scanner.

A scanner that files with compromised or untrusted code signing certificates written in python.

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Collaborative application security testing between humans and agents via CLI and MCP

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Locally-hosted, air-gapped VAPT platform that runs 8 parallel scanning modules, deterministically scores findings with CVSS v3.1, and generates PDF…

OAuth Request Crafter