WSTG
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
About
Welcome to the official repository for the Open Worldwide Application Security Project® (OWASP®) Web Security Testing Guide (WSTG). The WSTG is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of security professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.
Open Source Health
- Stars
- 9,811
- Forks
- 1,679
- License
- CC-BY-SA-4.0
- Last commit
- 26 days ago
Resources & Links
Related Categories
Vendor
OWASP
Publisher of Dependency-Track
Quick Links
Open Source
More by OWASP
Related Products
Burp AI Agent
Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more
Top category match
Semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
Top category match
Shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
Top category match
Zaproxy
The ZAP by Checkmarx Core project
Top category match
Infer
Infer is a static analysis tool for detecting bugs in Java and C/C++/Objective-C code.
Top category match