35 active products

OWASP

Publisher of Dependency-Track

Consolidated Product Portfolio

Mastg
Mastg

OWASP Mobile Application Security - OWASP Mobile Application Security

Penetration TestingOpen Source
O-Saft

O-Saft - OWASP SSL advanced forensic tool

Digital ForensicsOpen Source
Docker-Security

Getting a handle on container security

Cloud SecurityOpen Source
WSTG
WSTG

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Application Security TestingOpen Source
NodeGoat
NodeGoat

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

Cloud SecurityOpen Source
ASVS
ASVS

Application Security Verification Standard

Cloud SecurityOpen Source
API-Security
API-Security

OWASP API Security Project

Cloud SecurityOpen Source
Go-SCP
Go-SCP

Golang Secure Coding Practices guide

Application Security TestingOpen Source
Dependency-Track

Software Bill of Materials (SBOM) Analysis

Ai Bom TrackingCommercial
JoomScan

OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/

Vulnerability ManagementOpen Source
RailsGoat

A vulnerable version of Rails that follows the OWASP Top 10

Application Security TestingOpen Source
DockSec

AI-Powered Docker Security Analyzer

Vulnerability ManagementOpen Source
Threat Dragon

An open source threat modeling tool from OWASP

Threat ModelingOpen Source
DVSA

a Damn Vulnerable Serverless Application

Serverless ComputingOpen Source
Owasp Istg

OWASP IoT Security Testing Guide | OWASP Foundation

Penetration TestingOpen Source
Nettacker
Nettacker

Automates information gathering, vulnerability scanning and aids penetration testing engagements in general

Penetration TestingOpen Source
APTS

OWASP Autonomous Penetration Testing Standard

Penetration TestingOpen Source
IoTGoat

IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.

Iot PlatformOpen Source
IoT-Security-Verification-Standard-ISVS

OWASP IoT Security Verification Standard (ISVS)

Iot PlatformOpen Source
Pytm

A Pythonic framework for threat modeling

DiagrammingOpen Source
Www Project Kubernetes Top Ten

OWASP Foundation Web Respository

Containerization PlatformOpen Source
Www Project API Security Testing Framework

OWASP Foundation web repository

Cloud SecurityOpen Source
SecurityShepherd

Web and mobile application security training platform

Cloud SecurityOpen Source
Python-Honeypot

OWASP Honeypot, Automated Deception Framework.

Cloud SecurityOpen Source
DevSecOpsGuideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Cloud SecurityOpen Source
Glue

Application Security Automation

Ci CdOpen Source
Rbac

PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest implementation yet.

AuthorizationOpen Source
Raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions.

AuthenticationOpen Source
Www Project Zap

OWASP Zed Attack Proxy project landing page.

Application Security TestingOpen Source
Www Project Top 10 For Large Language Model Applications

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Application Security TestingOpen Source
Www Project Secure Headers

The OWASP Secure Headers Project

Application Security TestingOpen Source
Www Community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Application Security TestingOpen Source
Cve Lite CLI

Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV

Application Security TestingOpen Source
Cornucopia

The source files and tools needed to build the OWASP Cornucopia decks in various languages

Application Security TestingOpen Source
Www Project Agent Memory Guard

OWASP Foundation web repository

Ai Agent PlatformOpen Source

Company Profile & Strategy

OWASP publishes Dependency-Track at owasp.org. Dependency-Track: Software Bill of Materials (SBOM) Analysis. Dependency-Track is the open source platform that over 20,000 organizations use to inventory components, find vulnerabilities, and enforce policy across the software supply chain.

Open-Source Footprint

34 repositories59.8K stars0 contributors

Save & manage the vendor's products in Productapp.

Save and manage this vendor's products in Productapp.

Start free trialWebsite

Quick Links