The SpotBugs plugin for security audits of Java web applications
Vulnerable app with examples showing how to not use secrets
Probably the most modern and sophisticated insecure web application
OWASP Coraza WAF is a golang modsecurity compatible firewall library
The OWASP ZAP core project
Scanner detecting the use of JavaScript libraries
Handy, High performance, ModSecurity compatible Nginx firewall module
AIAST –An advanced interactive application security tool
Open source OWASP penetration testing tool written in Python 3
Static Application Security Testing (SAST) engine
Extension that allows you to intercept and edit HTTP/HTTPS requests
A simple Web Application Firewall docker image
Offensive Web Testing Framework (OWTF), is a framework
An Application to security test RESTful web APIs.
Web and mobile application security awareness/training platform
Find web application vulnerabilities the easy way!
an extremely buggy web app !
SSL Strength Evaluation and Test Utility
PHP Role Based Access Control library
Free and Open Source Browser based Security Framework