Top #owasp Tools & Software
Explore 17 hand-picked tools and software tagged with owasp — ranked by popularity and community signals.
CheatSheetSeries
githubThe OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
juice-shop
githubOWASP Juice Shop: Probably the most modern and sophisticated insecure web application
wstg
githubThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
awesome-appsec
githubA curated list of resources for learning about application security
awesome-web-hacking
githubA list of web application security
WhatWeb
githubNext generation web scanner
Nettacker
githubAutomated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
django-DefectDojo
githubOpen-Source Unified Vulnerability Management, DevSecOps & ASPM
dependency-track
githubDependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
bluemonday
githubbluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
coreruleset
githubOWASP CRS (Official Repository)
awesome-nodejs-security
githubAwesome Node.js Security resources
Astra
githubAutomated Security Testing For REST API's
bearer
githubCode security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
find-sec-bugs
githubThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
masvs
githubThe OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
API-Security
githubOWASP API Security Project