{"owner":"OWASP","github":"https://github.com/OWASP","claimed":false,"inventory":[],"indexed":[{"repo":"OWASP/mastg","github":"https://github.com/OWASP/mastg","description":"The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.","language":"Python","stars":13119,"topics":["mobile-app","pentesting","android-application","ios-app","runtime-analysis","network-analysis","static-analysis","reverse-engineering","dynamic-analysis","mobile-security"],"license":"CC-BY-SA-4.0","category":"security-tools"},{"repo":"OWASP/Nettacker","github":"https://github.com/OWASP/Nettacker","description":"Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management","language":"Python","stars":5513,"topics":["python","penetration-testing","penetration-testing-framework","owasp","automation","portscanner","vulnerability-scanners","information-gathering","bruteforce","security"],"license":"Apache-2.0","category":"security-tools"},{"repo":"OWASP/masvs","github":"https://github.com/OWASP/masvs","description":"The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.","language":"Python","stars":2432,"topics":["masvs","verification","mobile","security","audit","penetration-tests","standard","gitbook","penetration-testing","owasp"],"license":"CC-BY-SA-4.0","category":"security-tools"},{"repo":"OWASP/API-Security","github":"https://github.com/OWASP/API-Security","description":"OWASP API Security Project","language":"Dockerfile","stars":2334,"topics":["api","security","web-api","documentation-portal","owasp-top"],"license":null,"category":"security-tools"},{"repo":"OWASP/crAPI","github":"https://github.com/OWASP/crAPI","description":"completely ridiculous API (crAPI)","language":"Java","stars":1560,"topics":["api","apisecurity","hacktoberfest","owasp"],"license":"Apache-2.0","category":"api-integrations-sdks"},{"repo":"OWASP/wrongsecrets","github":"https://github.com/OWASP/wrongsecrets","description":"Vulnerable app with examples showing how to not use secrets","language":"Java","stars":1457,"topics":["hashicorp-vault","terraform-aws","java","kubernetes","secrets","secrets-management","vault","devsecops","security","aws"],"license":"AGPL-3.0","category":"security-tools"},{"repo":"OWASP/DevSecOpsGuideline","github":"https://github.com/OWASP/DevSecOpsGuideline","description":"The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.","language":"Python","stars":1089,"topics":["devsecops","owasp","shift-left","security"],"license":null,"category":"security-tools"},{"repo":"OWASP/www-project-kubernetes-top-ten","github":"https://github.com/OWASP/www-project-kubernetes-top-ten","description":"OWASP Foundation Web Respository","language":"HTML","stars":616,"topics":["owasp","kubernetes","security"],"license":null,"category":"deployment-docker-iac"},{"repo":"OWASP/Nest","github":"https://github.com/OWASP/Nest","description":"Your gateway to OWASP. Discover, engage, and help shape the future!","language":"Python","stars":425,"topics":["rest","django","react","typescript","typescript-react","gsoc","graphql","python","heroui","nextjs"],"license":"MIT","category":"api-integrations-sdks"},{"repo":"OWASP/D4N155","github":"https://github.com/OWASP/D4N155","description":"OWASP D4N155 - Intelligent and dynamic wordlist using OSINT","language":"Shell","stars":270,"topics":["osint","wordlist","dynamic","crawler","raport","scraping","dorking","google","duckduckgo","tool"],"license":"GPL-3.0","category":"scrapers-browser-automation"},{"repo":"OWASP/cwe-tool","github":"https://github.com/OWASP/cwe-tool","description":"A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.","language":"JavaScript","stars":64,"topics":["cwe","cwe-discovery","json","cli","owasp","cve","vulnerabilities","mitre"],"license":"Apache-2.0","category":"cli-tools"},{"repo":"OWASP/Agent-Security-Regression-Harness","github":"https://github.com/OWASP/Agent-Security-Regression-Harness","description":"Executable security regression testing for agentic applications and MCP-integrated systems.","language":"Python","stars":47,"topics":["agent-security","ai-security","appsec","llm-security","mcp","owasp","python","regression-testing","security-testing"],"license":"Apache-2.0","category":"mcp-servers"},{"repo":"OWASP/www-project-asvs-security-evaluation-templates-with-nuclei","github":"https://github.com/OWASP/www-project-asvs-security-evaluation-templates-with-nuclei","description":"OWASP ASVS Security Evaluation Templates with Nuclei","language":"Python","stars":44,"topics":["asvs","automation","nuclei","nuclei-templates","owasp","pentest","web","wstg"],"license":"MIT","category":"workflow-automation"},{"repo":"OWASP/maswe","github":"https://github.com/OWASP/maswe","description":"The Mobile Application Security Weakness Enumeration (MASWE) is a list of common security and privacy weaknesses in mobile apps. It is intended to be used as a reference for developers, security researchers, and security professionals. It acts as the bridge between the OWASP MASVS and the MASTG.","language":"Python","stars":37,"topics":["mobile-app","mobile-privacy","owasp-mobile","privacy","security","weakness","maswe"],"license":"CC-BY-SA-4.0","category":"security-tools"}],"how_to_buy":"GET /r/OWASP/<repo> (Accept: application/json) for any listed repo here: tree, README, price and the checkout to pay (x402; rehearse first at its test twin, simulated money). Repos under 'indexed' are free: clone them from GitHub."}