The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
Updated
Oct 6, 2026 - JavaScript
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
A curated list of resources for learning about application security
Next generation web scanner
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
Security automation content in SCAP, Bash, Ansible, and other formats
A curated list of awesome Android Reverse Engineering training, resources, and tools.
A modular, stack-agnostic toolkit for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.
Metlo is an open-source API security platform.
XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
Curating the best DevSecOps resources and tooling.
open-appsec is a machine learning security engine that preemptively and automatically prevents threats against Web Application & APIs. This repo include the main code and logic.
Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。
A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
To associate your repository with the application-security topic, visit your repo's landing page and select "manage topics."