Application Security Open Source Projects

Browse 84 Application Security open source projects, ranked by GitHub stars. Find the most popular Application Security tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 84 projects
32,612 stars

OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Metrics details
Stars32,612
13,520 stars

juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

Metrics details
Stars13,520
9,601 stars

OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Metrics details
Stars9,601
7,115 stars

infoslack/awesome-web-hacking

A list of web application security

Metrics details
Stars7,115
6,994 stars

paragonie/awesome-appsec

A curated list of resources for learning about application security

Metrics details
Stars6,994
6,730 stars

urbanadventurer/WhatWeb

Next generation web scanner

Metrics details
Stars6,730
5,009 stars

jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

Metrics details
Stars5,009
2,769 stars

ComplianceAsCode/content

Security automation content in SCAP, Bash, Ansible, and other formats

Metrics details
Stars2,769
2,540 stars

user1342/Awesome-Android-Reverse-Engineering

A curated list of awesome Android Reverse Engineering training, resources, and tools.

Metrics details
Stars2,540
2,375 stars

payloadbox/command-injection-payload-list

🎯 Command Injection Payload List

Metrics details
Stars2,375
2,144 stars

hahwul/DevSecOps

♾️ Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎

Metrics details
Stars2,144
1,878 stars

m14r41/PentestingEverything

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...

Metrics details
Stars1,878
1,780 stars

metlo-labs/metlo

Metlo is an open-source API security platform.

Metrics details
Stars1,780
1,762 stars

s4n7h0/xvwa

XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.

Metrics details
Stars1,762
1,704 stars

harsh-bothra/learn365

This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.

Metrics details
Stars1,704
1,703 stars

TaptuIT/awesome-devsecops

Curating the best DevSecOps resources and tooling.

Metrics details
Stars1,703
1,680 stars

Safe3/uuWAF

一款社区驱动的免费、高性能、高扩展顶级Web应用和API安全防护产品-南墙

Metrics details
Stars1,680
1,652 stars

openappsec/openappsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

Metrics details
Stars1,652
1,202 stars

Janusec/janusec

JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。

Metrics details
Stars1,202
1,168 stars

Quitten/Autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

Metrics details
Stars1,168
1,163 stars

sh4hin/Androl4b

A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis

Metrics details
Stars1,163
1,036 stars

guardrailsio/awesome-php-security

Awesome PHP Security Resources 🕶🐘🔐

Metrics details
Stars1,036
985 stars

secureCodeBox/secureCodeBox

secureCodeBox (SCB) - continuous secure delivery out of the box

Metrics details
Stars985
952 stars

appsecco/breaking-and-pwning-apps-and-servers-aws-azure-training

Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!

Metrics details
Stars952
942 stars

bloodzer0/ossa

Open-Source Security Architecture | 开源安全架构

Metrics details
Stars942
783 stars

wallarm/awesome-nginx-security

🔥 A curated list of awesome links related to application security related to the environments with NGINX or Kubernetes Ingres Controller (based on NGINX)

Metrics details
Stars783
769 stars

MattKeeley/Spoofy

Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.

Metrics details
Stars769
756 stars

rewanthtammana/Damn-Vulnerable-Bank

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

Metrics details
Stars756
741 stars

olacabs/jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Metrics details
Stars741
689 stars

security-prince/Application-Security-Engineer-Interview-Questions

Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer

Metrics details
Stars689
687 stars

Anof-cyber/Application-Security

Resources for Application Security including Web, API, Android, iOS and Thick Client

Metrics details
Stars687
666 stars

Cy-clon3/awesome-ios-security

A curated list of awesome iOS application security resources.

Metrics details
Stars666
665 stars

brcyrr/PracticalCyberSecurityResources

This repository contains a curated list of resources I suggest on LinkedIn and Twitter.📝🌝

Metrics details
Stars665
596 stars

factionsecurity/faction

Pen Test Report Generation and Assessment Collaboration

Metrics details
Stars596
521 stars

0xn3va/cheat-sheets

A list of cheat sheets for application security

Metrics details
Stars521
500 stars

talsec/Free-RASP-Community

SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.

Metrics details
Stars500
482 stars

SmileZXLee/ZXHookDetection

【iOS应用安全、安全攻防】hook及越狱的基本防护与检测(动态库注入检测、hook检测与防护、越狱检测、签名校验、汇编分析、IDA反编译分析加密协议Demo);【数据传输安全】浅谈http、https与数据加密;代码加密&混淆;防抓包、http-dns解决方案,防止DNS劫持等

Metrics details
Stars482
474 stars

juice-shop/juice-shop-ctf

Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF

Metrics details
Stars474
470 stars

jassics/security-interview-questions

Security interview questions with possible explanation for roles in AppSec, Pentesting, Cloud Security, DevSecOps, Network Security and so on

Metrics details
Stars470
463 stars

enkomio/Taipan

Web application vulnerability scanner

Metrics details
Stars463
432 stars

jassics/security-skills-career-roadmap

Skills and career roadmap for various security roles like appsec, cloud security, devsecops, security engineer, security researchers, pentesting, api security, network security, mobile security and so on.with helpful resources, guidelines

Metrics details
Stars432
431 stars

flipkart-incubator/watchdog

Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.

Metrics details
Stars431
414 stars

paragonie/airship

Secure Content Management for the Modern Web - "The sky is only the beginning"

Metrics details
Stars414
406 stars

lukeFalsina/Grab-n-Run

Grab’n Run, a simple and effective Java Library for Android projects to secure dynamic code loading.

Metrics details
Stars406
401 stars

volkandindar/agartha

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.

Metrics details
Stars401
379 stars

satishpatnayak/AndroGoat

AndroGoat

Metrics details
Stars379
345 stars

tegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

Metrics details
Stars345
339 stars

mishmashclone/swisskyrepo-PayloadsAllTheThings

https://github.com/swisskyrepo/PayloadsAllTheThings

Metrics details
Stars339
337 stars

adeyosemanputra/pygoat

intentionally vuln web Application Security in django

Metrics details
Stars337
329 stars

Autodesk/continuous-threat-modeling

A Continuous Threat Modeling methodology

Metrics details
Stars329
312 stars

SpamScope/spamscope

Fast Advanced Spam Analysis Tool

Metrics details
Stars312
282 stars

we45/ThreatPlaybook

A unified DevSecOps Framework that allows you to go from iterative, collaborative Threat Modeling to Application Security Test Orchestration

Metrics details
Stars282
272 stars

OWASP/RiskAssessmentFramework

The Secure Coding Framework

Metrics details
Stars272
253 stars

Karmaz95/crimson

Web Application Security Testing Tools

Metrics details
Stars253
229 stars

dn0m1n8tor/learn365

This repository is about @AnubhavSingh_'s 365 days of Learning Tweets collection.

Metrics details
Stars229
227 stars

spring-guides/top-spring-security-architecture

Spring Security Architecture:: Topical guide to Spring Security, how the bits fit together and how they interact with Spring Boot

Metrics details
Stars227
224 stars

abhi-r3v0/EVABS

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

Metrics details
Stars224
224 stars

payloadbox/rfi-lfi-payload-list

🎯 RFI/LFI Payload List

Metrics details
Stars224
223 stars

simioni87/auth_analyzer

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Metrics details
Stars223
220 stars

Anof-cyber/PyCript

Burp Suite extension to decrypt/encrypt any encrypted traffic (AES/RSA/Encodings and more) with custom code in any language

Metrics details
Stars220
1-60 of 84 projects
Get A Weekly Email With Trending Application Security Projects
Stay updated on Application Security plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.