The SpotBugs plugin for security audits of Java web applications
OWASP Coraza WAF is a golang modsecurity compatible firewall library
Scanner detecting the use of JavaScript libraries
The OWASP ZAP core project
O-Saft - OWASP SSL advanced forensic tool
Probably the most modern and sophisticated insecure web application
Harness Open Source is an end-to-end developer platform
Code security scanning tool (SAST) to discover security risks
SonarSource Static Analyzer for Java Code Quality and Security
Code security review tool for C/C++, C#, VB, PHP, Java, PL/SQL, COBOL.
Lift Framework
Static Application Security Testing (SAST) engine
The OWASP NodeGoat project
Offensive Web Testing Framework (OWTF), is a framework
Web and mobile application security awareness/training platform
Intentionally vulnerable web services exploitable with XXE
Open Source Penetration Testing / Ethical Hacking Framework
PHP Role Based Access Control library