#appsec (25 Repositories)
Ranked open-source repositories tagged with #appsec, scored by pull request acceptance likelihood and maintainer engagement velocity.
45.2%
42.8h
25 repositories tagged #appsec
OWASP/www-community
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
awslabs/threat-designer
Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design.
maurosoria/dirsearch
Web path scanner
openziti/ziti
The parent project for OpenZiti. Here you will find the executables for a fully zero-trust, programmable network @OpenZiti
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
OWASP/cornucopia
The source files and tools needed to build the OWASP Cornucopia decks in various languages
aeria-org/aeria
A framework/language to prototype webapps fast so you can touch grass
OWASP/www-project-secure-headers
The OWASP Secure Headers Project
DataDog/dd-trace-php
Datadog PHP Clients
openappsec/openappsec
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
DataDog/dd-trace-go
Datadog Go Library including APM tracing, profiling, and security monitoring.
zaproxy/zaproxy
The ZAP by Checkmarx Core project
openziti/sdk-golang
Ziti SDK for Golang
bountyyfi/lonkero
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
albuch/sbt-dependency-check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). :rainbow:
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Zyrexnn/Cybermes
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
agentgg-dev/agentgg
Open source agentic SAST. The engine behind hundreds of disclosed zero-days. 100+ AI security agents, any repo or PR diff, bring your own model.
silentchainai/SILENTCHAIN
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Checkmarx/2ms
Too many secrets (2MS) helps people protect their secrets on any file or on systems like CMS, chats and git
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
klarna-incubator/gram
Gram is Klarna's own threat model diagramming tool
Eyadkelleh/awesome-skills-security
Security testing toolkit for AI Agent: curated SecLists wordlists, injection payloads, and expert agents for authorized pentesting, CTFs, and bug bounties
andresriancho/w3af
w3af: web application attack and audit framework, the open source web vulnerability scanner.