Vulnerable app with examples showing how to not use secrets
The SpotBugs plugin for security audits of Java web applications
The OWASP ZAP core project
SonarSource Static Analyzer for Java Code Quality and Security
Owasp Zap Live CD
Web and mobile application security awareness/training platform
Find web application vulnerabilities the easy way!
Open Source Penetration Testing / Ethical Hacking Framework