Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security

Security

955 projects

Showing 36 of 955 projects

django-guardian
django-guardianPython

Adds per-object permissions to Django's authorization system, enabling fine-grained access control.

#authentication#authorization#security
Stars3.9k
Forks589
Last commit4 days ago
PHP Encryption
PHP EncryptionPHP

A secure and easy-to-use PHP library for encrypting data with keys or passwords.

#library#data-protection#file-encryption
Stars3.9k
Forks309
Last commit2 years ago
Stegcloak
StegcloakJavaScript

A pure JavaScript steganography module that hides secrets inside text using invisible unicode characters, secured with passwords and encryption.

#covert-communication#functional-programming#aes-256
Stars3.8k
Forks242
Last commit1 year ago
vulscan
vulscanLua

An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.

#vulnerability-assessment#vulnerability#nmap
Stars3.8k
Forks695
Last commit4 months ago
Figaro
FigaroRuby

Simple, Heroku-friendly Rails app configuration using ENV and a single YAML file.

#rails#environment-variables#yaml
Stars3.7k
Forks280
Last commit11 months ago
scans
scansJavaScript

An open-source Cloud Security Posture Management (CSPM) tool that scans AWS, Azure, GCP, Oracle, and GitHub for security misconfigurations.

#aws-security#compliance-auditing#infrastructure-security
Stars3.7k
Forks744
Last commit3 months ago
node-oidc-provider
node-oidc-providerJavaScript

OpenID Certified OAuth 2.0 Authorization Server implementation for Node.js with extensive spec support.

#authorization-server#openid#openid-provider
Stars3.7k
Forks789
Last commit6 days ago
bluemonday
bluemondayGo

A fast, configurable HTML sanitizer for Go that scrubs user-generated content of XSS attacks using an allowlist policy.

#sanitization#owasp#web-security
Stars3.7k
Forks193
Last commit1 year ago
JWT
JWTRuby

A Ruby implementation of the RFC 7519 OAuth JSON Web Token (JWT) standard for secure token encoding and decoding.

#jwt-token#oauth#authentication
Stars3.7k
Forks375
Last commit11 days ago
sozu
sozuRust

A lightweight, fast, always-up HTTP reverse proxy built in Rust, configurable at runtime without reloading.

#http-proxy#reverse-proxy#http-server
Stars3.7k
Forks212
Last commit1 day ago
SWAG (Secure Web Application Gateway)
SWAG (Secure Web Application Gateway)Dockerfile

A Docker container providing a secure Nginx web server and reverse proxy with automated SSL certificates and fail2ban protection.

#hacktoberfest#reverse-proxy#web-server
Stars3.7k
Forks283
Last commit
Rizin
RizinC

A reverse engineering framework and command-line toolset for binary analysis, disassembly, debugging, and forensic tasks.

#command-line-tools#multi-architecture#scriptable
Stars3.6k
Forks570
Last commit1 day ago
Bouncer
BouncerPHP

An elegant, framework-agnostic package for managing roles and abilities in Laravel using Eloquent models.

#eloquent#auth#laravel
Stars3.6k
Forks335
Last commit2 months ago
oathkeeper
oathkeeperGo

A cloud native Identity & Access Proxy (IAP) and Access Control Decision API that authenticates, authorizes, and mutates HTTP requests.

#api-gateway#hacktoberfest#reverse-proxy
Stars3.6k
Forks410
Last commit3 days ago
recaptcha
recaptchaPHP

A PHP client library for Google's reCAPTCHA service to verify user responses and protect websites from spam.

#web-security#recaptcha#google-recaptcha
Stars3.6k
Forks779
Last commit1 month ago
Chainsaw
ChainsawRust

A fast, standalone tool for rapid threat hunting and forensic analysis of Windows event logs and other forensic artefacts.

#digital-forensics#sigma-rules#forensic-timeline
Stars3.6k
Forks299
Last commit1 month ago
rate-limiter-flexible
rate-limiter-flexibleJavaScript

Atomic and non-atomic counters and rate limiting tools for Node.js, Deno, and browsers to protect from DoS and brute force attacks.

#throttle#dos-protection#redis
Stars3.6k
Forks189
Last commit4 days ago
Bitwarden
BitwardenTypeScript

A cross-platform desktop application for managing passwords and sensitive data, built with Electron and Angular.

#desktop-application#open-source#encryption
Stars3.5k
Forks391
Last commit3 years ago
Coraza
CorazaGo

An open-source, enterprise-grade Web Application Firewall library written in Go, compatible with ModSecurity SecLang rulesets.

#reverse-proxy#waf#owasp
Stars3.5k
Forks322
Last commit1 day ago
rage
rageRust

A Rust implementation of the age file encryption tool, offering simple, secure encryption with small explicit keys and UNIX-style composability.

#secure-by-default#unix-philosophy#curve25519
Stars3.5k
Forks153
Last commit1 month ago
awesome-cve-poc
awesome-cve-poc

A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).

#cve#exploit-development#penetration-testing
Stars3.5k
Forks720
Last commit4 years ago
oso
osoRust

A batteries-included framework for building authorization in your application with a declarative policy language.

#multi-language#declarative-programming#rbac
Stars3.5k
Forks191
Last commit1 year ago
emba
embaShell

An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.

#iot#sbom#embedded-systems
Stars3.5k
Forks305
Last commit1 day ago
KeyBox
KeyBoxJava

A modern, web-based SSH console and key management tool that functions as a secure bastion host.

#bastion-host#devops#ssh-key
Stars3.5k
Forks396
Last commit1 month ago
Anti Corruption Layer Pattern
Anti Corruption Layer Pattern

A collection of reusable, vendor-neutral, and industry-specific solution architecture patterns for building enterprise software systems.

#enterprise-software#api-gateway#architecture-patterns
Stars3.5k
Forks674
Last commit3 years ago
API-led Connectivity pattern
API-led Connectivity pattern

A collection of reusable, vendor-neutral, industry-specific, and vendor-specific solution architecture patterns for building enterprise software systems.

#enterprise-software#api-gateway#architecture-patterns
Stars3.5k
Forks674
Last commit3 years ago
Lighthouse
LighthouseRust

An open-source Ethereum consensus client written in Rust, designed for security and performance on the Ethereum proof-of-stake network.

#open-source#proof-of-stake#cryptocurrency
Stars3.4k
Forks1.0k
Last commit3 days ago
FluentFTP
FluentFTPC#

A fully managed, high-performance FTP and FTPS client library for .NET and .NET Standard, optimized for speed.

#async-await#unix#network-library
Stars3.4k
Forks679
Last commit12 days ago
Deepfence SecretScanner
Deepfence SecretScannerGo

A standalone tool that finds unprotected secrets like passwords and API keys in container images and file systems.

#scanning-tool#container-security#passwords
Stars3.4k
Forks347
Last commit3 months ago
OpenSK
OpenSKRust

An open-source implementation of FIDO2 and U2F security keys written in Rust, enabling custom hardware authentication devices.

#security-key#embedded-systems#tock-os
Stars3.4k
Forks330
Last commit4 days ago
Honggfuzz
HonggfuzzC

A security-oriented, feedback-driven, evolutionary software fuzzer that uses hardware and software code coverage to find bugs.

#software-testing#vulnerability-discovery#oss-fuzz
Stars3.4k
Forks534
Last commit1 month ago
Timesketch
TimesketchPython

An open-source tool for collaborative forensic timeline analysis, enabling teams to organize, annotate, and investigate timelines together.

#digital-forensics#timeline#open-source
Stars3.4k
Forks653
Last commit10 days ago
HTML Purifier
HTML PurifierPHP

A standards-compliant HTML filtering library for PHP that removes malicious code while preserving safe markup.

#web-security#php-library#html-sanitization
Stars3.3k
Forks354
Last commit7 months ago
Notary
NotaryGo

A client and server implementation of The Update Framework (TUF) for securing software distribution and updates.

#tuf-implementation#software-updates#cncf
Stars3.3k
Forks520
Last commit1 year ago
CSS-Keylogging
CSS-KeyloggingCSS

Chrome extension and Express server demonstrating a CSS-based keylogging attack on password inputs.

#express-server#web-security#keylogging
Stars3.2k
Forks429
Last commit8 years ago
svix-webhooks
svix-webhooksRust

An open-source webhooks service that handles deliverability, retries, and security with a single API call.

#api#redis#message-queue
Stars3.2k
Forks250
Last commit3 days ago
PreviousPage 7 of 27Next

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
3 days ago
#Authentication185
#Cryptography133
#Docker110
#Go104
#Encryption87
#Authorization84
#Security Tools84
#Rust83
#Golang77
#Devops76
#Python74
#Self Hosted72