OWASP
Publisher of Dependency-Track
Consolidated Product Portfolio
OWASP Mobile Application Security - OWASP Mobile Application Security
O-Saft - OWASP SSL advanced forensic tool
Getting a handle on container security
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
Application Security Verification Standard
OWASP API Security Project
Golang Secure Coding Practices guide
Software Bill of Materials (SBOM) Analysis
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/
A vulnerable version of Rails that follows the OWASP Top 10
AI-Powered Docker Security Analyzer
An open source threat modeling tool from OWASP
a Damn Vulnerable Serverless Application
OWASP IoT Security Testing Guide | OWASP Foundation
Automates information gathering, vulnerability scanning and aids penetration testing engagements in general
OWASP Autonomous Penetration Testing Standard
IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
OWASP IoT Security Verification Standard (ISVS)
A Pythonic framework for threat modeling
OWASP Foundation Web Respository
OWASP Foundation web repository
Web and mobile application security training platform
OWASP Honeypot, Automated Deception Framework.
The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.
Application Security Automation
PHP-RBAC is an authorization library for PHP. It provides developers with NIST Level 2 Standard Role Based Access Control and more, in the fastest implementation yet.
OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions.
OWASP Zed Attack Proxy project landing page.
OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)
The OWASP Secure Headers Project
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV
The source files and tools needed to build the OWASP Cornucopia decks in various languages
OWASP Foundation web repository
Company Profile & Strategy
OWASP publishes Dependency-Track at owasp.org. Dependency-Track: Software Bill of Materials (SBOM) Analysis. Dependency-Track is the open source platform that over 20,000 organizations use to inventory components, find vulnerabilities, and enforce policy across the software supply chain.
Open-Source Footprint
Related vendors
Save & manage the vendor's products in Productapp.
Save and manage this vendor's products in Productapp.