
RedTeamToolkit
The WASM Based Security Toolkit for the Web First Paradigm

The WASM Based Security Toolkit for the Web First Paradigm

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Policy enforcement, zero-trust identity, execution sandboxing, and audit logging for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10 with…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Vulnerable app with examples showing how to not use secrets

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.


OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

Open source CSPM for Azure - scan for misconfigurations and quantum-unsafe cryptography, map findings to CIS/NIST/ISO27001/SOC2, and fix them with…

Software Component Verification Standard (SCVS)

🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment

Executable security regression testing for agentic applications and MCP-integrated systems.