Appsec Open Source Projects

Browse 104 Appsec open source projects, ranked by GitHub stars. Find the most popular Appsec tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 104 projects
32,612 stars

OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Metrics details
Stars32,612
15,441 stars

zaproxy/zaproxy

The ZAP by Checkmarx Core project

Metrics details
Stars15,441
14,521 stars

maurosoria/dirsearch

Web path scanner

Metrics details
Stars14,521
13,520 stars

juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

Metrics details
Stars13,520
9,601 stars

OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Metrics details
Stars9,601
7,115 stars

infoslack/awesome-web-hacking

A list of web application security

Metrics details
Stars7,115
6,730 stars

urbanadventurer/WhatWeb

Next generation web scanner

Metrics details
Stars6,730
6,660 stars

infobyte/faraday

Open Source Vulnerability Management Platform

Metrics details
Stars6,660
5,285 stars

OWASP/Go-SCP

Golang Secure Coding Practices guide

Metrics details
Stars5,285
5,009 stars

jassics/security-study-plan

Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...

Metrics details
Stars5,009
4,897 stars

andresriancho/w3af

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Metrics details
Stars4,897
4,843 stars

DefectDojo/django-DefectDojo

Open-Source Unified Vulnerability Management, DevSecOps & ASPM

Metrics details
Stars4,843
4,448 stars

projectdiscovery/interactsh

An OOB interaction gathering server and client library

Metrics details
Stars4,448
4,300 stars

openziti/ziti

The parent project for OpenZiti. Here you will find the executables for a fully zero-trust, programmable network @OpenZiti

Metrics details
Stars4,300
4,022 stars

DependencyTrack/dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.

Metrics details
Stars4,022
3,966 stars

foospidy/payloads

Git All the Payloads! A collection of web attack payloads.

Metrics details
Stars3,966
2,705 stars

Bearer/bearer

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Metrics details
Stars2,705
2,673 stars

Checkmarx/kics

Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

Metrics details
Stars2,673
2,279 stars

cider-security-research/cicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Metrics details
Stars2,279
1,867 stars

trailofbits/publications

Publications from Trail of Bits

Metrics details
Stars1,867
1,773 stars

hysnsec/awesome-threat-modelling

A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for learning Threat modeling and initial phases of security review.

Metrics details
Stars1,773
1,663 stars

summitt/Nope-Proxy

TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.

Metrics details
Stars1,663
1,652 stars

openappsec/openappsec

open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.

Metrics details
Stars1,652
1,501 stars

webpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an easy-to-use web hacking environment designed for labs, security enthusiasts, classrooms, CTF, and vulnerability assessment tool targets.

Metrics details
Stars1,501
1,382 stars

OWASP/www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Metrics details
Stars1,382
1,345 stars

roottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Metrics details
Stars1,345
1,330 stars

OWASP/www-project-top-10-for-large-language-model-applications

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Metrics details
Stars1,330
1,221 stars

Simpsonpt/AppSecEzine

AppSec Ezine Public Repository.

Metrics details
Stars1,221
1,199 stars

httpvoid/writeups

Metrics details
Stars1,199
1,186 stars

ayoubfathi/leaky-paths

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.

Metrics details
Stars1,186
938 stars

zaproxy/zap-extensions

ZAP Add-ons

Metrics details
Stars938
934 stars

Soluto/kamus

An open source, git-ops, zero-trust secret encryption and decryption solution for Kubernetes applications

Metrics details
Stars934
922 stars

OWASP/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

Metrics details
Stars922
884 stars

OWASP/OWASP-VWAD

:warning: This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Metrics details
Stars884
884 stars

ShiftLeftSecurity/sast-scan

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

Metrics details
Stars884
866 stars

numirias/security

Some of my security stuff and vulnerabilities. Nothing advanced. More to come.

Metrics details
Stars866
849 stars

DataDog/dd-trace-go

Datadog Go Library including APM tracing, profiling, and security monitoring.

Metrics details
Stars849
815 stars

blacklanternsecurity/badsecrets

A library for detecting known secrets across many web frameworks

Metrics details
Stars815
769 stars

MattKeeley/Spoofy

Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.

Metrics details
Stars769
752 stars

oversecured/ovaa

Oversecured Vulnerable Android App

Metrics details
Stars752
693 stars

dependency-check/dependency-check-sonar-plugin

Integrates Dependency-Check reports into SonarQube

Metrics details
Stars693
689 stars

security-prince/Application-Security-Engineer-Interview-Questions

Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer

Metrics details
Stars689
687 stars

Anof-cyber/Application-Security

Resources for Application Security including Web, API, Android, iOS and Thick Client

Metrics details
Stars687
651 stars

Privado-Inc/privado

Open Source Static Scanning tool to detect data flows in your code, find data security vulnerabilities & generate accurate Play Store Data Safety Report.

Metrics details
Stars651
634 stars

TheHackerDev/race-the-web

Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.

Metrics details
Stars634
557 stars

DataDog/dd-trace-php

Datadog PHP Clients

Metrics details
Stars557
500 stars

talsec/Free-RASP-Community

SDK providing threat detection & security monitoring for mobile devices. Works with Flutter, React Native, Android and iOS. Shield your app with free RASP. Detect reverse engineering, root (Magisk), jailbreak, Frida, emulators, bots, tampering and integrity issues, obfuscation, VPN usage, malware, and monitor device identification and fingerprint.

Metrics details
Stars500
442 stars

SasanLabs/VulnerableApp

OWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.

Metrics details
Stars442
436 stars

ajinabraham/njsscan

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

Metrics details
Stars436
429 stars

OWASP/threat-model-cookbook

This project is about creating and publishing threat model examples.

Metrics details
Stars429
418 stars

JohnTroony/Blisqy

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

Metrics details
Stars418
418 stars

righettod/poc-graphql

Research on GraphQL from an AppSec point of view.

Metrics details
Stars418
408 stars

mtesauro/owasp-wte

Home of the developement for OWASP WTE - the Web Testing Environment, a collection of pre-packaged Linux AppSec tools, apps and documentation used to create pre-configured VMs or installed ala carte in the Linux of your choice..

Metrics details
Stars408
401 stars

volkandindar/agartha

A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violations. It supports dynamic payload generation, including BCheck syntax, and can automatically generate Bambdas scripts. Additionally, it offers "Copy as JavaScript" to convert HTTP requests for enhanced XSS testing.

Metrics details
Stars401
392 stars

c0rdis/security-champions-playbook

Security Champions Playbook v 2.1

Metrics details
Stars392
366 stars

dub-flow/appsec-challenges

This repo contains the code for my appsec challenges

Metrics details
Stars366
357 stars

ispras/casr

Collect crash (or UndefinedBehaviorSanitizer error) reports, triage, and estimate severity.

Metrics details
Stars357
353 stars

mercedes-benz/sechub

SecHub provides a central API to test software with different security tools.

Metrics details
Stars353
278 stars

Orange-Cyberdefense/grepmarx

A source code static analysis platform for AppSec enthusiasts.

Metrics details
Stars278
274 stars

zaproxy/zap-hud

The ZAP Heads Up Display (HUD)

Metrics details
Stars274
1-60 of 104 projects
Get A Weekly Email With Trending Appsec Projects
Stay updated on Appsec plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.