Skip to content
@OWASP

OWASP

The OWASP Foundation

Popular repositories Loading

  1. CheatSheetSeries CheatSheetSeries Public

    The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

    Python 30.9k 4.3k

  2. mastg mastg Public

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

    Shell 12.6k 2.6k

  3. wstg wstg Public

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    Dockerfile 8.6k 1.5k

  4. Go-SCP Go-SCP Public

    Golang Secure Coding Practices guide

    Go 5.2k 386

  5. Top10 Top10 Public

    Official OWASP Top 10 Document Repository

    HTML 5k 966

  6. Nettacker Nettacker Public

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

    Python 4.6k 944

Repositories

Showing 10 of 1333 repositories
  • mastg Public

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

    OWASP/mastg’s past year of commit activity
    Shell 12,586 CC-BY-SA-4.0 2,582 304 53 Updated Dec 7, 2025
  • threat-dragon Public

    An open source threat modeling tool from OWASP

    OWASP/threat-dragon’s past year of commit activity
    JavaScript 1,258 Apache-2.0 321 94 (6 issues need help) 5 Updated Dec 7, 2025
  • Top10 Public

    Official OWASP Top 10 Document Repository

    OWASP/Top10’s past year of commit activity
    HTML 4,991 966 8 29 Updated Dec 7, 2025
  • www-project-top-ten Public

    OWASP Foundation Web Respository

    OWASP/www-project-top-ten’s past year of commit activity
    HTML 1,306 252 11 17 Updated Dec 8, 2025
  • wrongsecrets Public

    Vulnerable app with examples showing how to not use secrets

    OWASP/wrongsecrets’s past year of commit activity
    Java 1,375 AGPL-3.0 508 24 (9 issues need help) 17 Updated Dec 7, 2025
  • www-project-noir Public

    Attack surface detector that identifies endpoints by static analysis

    OWASP/www-project-noir’s past year of commit activity
    HTML 5 3 0 0 Updated Dec 7, 2025
  • www-chapter-seoul Public

    OWASP Foundation Web Respository

    OWASP/www-chapter-seoul’s past year of commit activity
    HTML 10 4 0 2 Updated Dec 7, 2025
  • ASVS Public

    Application Security Verification Standard

    OWASP/ASVS’s past year of commit activity
    HTML 3,257 CC-BY-SA-4.0 784 80 7 Updated Dec 7, 2025
  • www-chapter-saitama Public

    OWASP Foundation Web Respository

    OWASP/www-chapter-saitama’s past year of commit activity
    HTML 2 1 1 0 Updated Dec 7, 2025
  • mas-website Public

    The OWASP Mobile Application Security Project website is the central hub for industry-leading standards, guides, and resources—helping developers and security professionals build, test, and secure mobile applications.

    OWASP/mas-website’s past year of commit activity
    Dockerfile 4 CC-BY-SA-4.0 4 6 5 Updated Dec 7, 2025