In-depth attack surface mapping and asset discovery
Vulnerable app with examples showing how to not use secrets
Probably the most modern and sophisticated insecure web application
The SpotBugs plugin for security audits of Java web applications
OWASP Coraza WAF is a golang modsecurity compatible firewall library
Scanner detecting the use of JavaScript libraries
The OWASP ZAP core project
Probably the most modern and sophisticated insecure web application
Handy, High performance, ModSecurity compatible Nginx firewall module
Code security review tool for C/C++, C#, VB, PHP, Java, PL/SQL, COBOL.
AIAST –An advanced interactive application security tool
Open source OWASP penetration testing tool written in Python 3
Static Application Security Testing (SAST) engine
Extension that allows you to intercept and edit HTTP/HTTPS requests
A simple Web Application Firewall docker image
Offensive Web Testing Framework (OWTF), is a framework
An Application to security test RESTful web APIs.
Web and mobile application security awareness/training platform
Find web application vulnerabilities the easy way!
an extremely buggy web app !
SSL Strength Evaluation and Test Utility
Open Source Penetration Testing / Ethical Hacking Framework
PHP Role Based Access Control library