Showing 18 of 54 projects
A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.
A Go-based tool to automatically scan networks for SSH servers with weak passwords and track credential vulnerabilities.
A fast scanning and attack toolkit for identifying and exploiting GitHub Actions vulnerabilities at scale.
An automated API security testing tool that generates and runs fuzzing attacks based on an OpenAPI/Swagger specification.
Tools for vulnerability scanning and compliance auditing of Docker containers and images using OpenSCAP.
A browser extension that aggregates security and quality data to help developers evaluate open source packages on npm, PyPI, and Go registries.
A Django web application for static security analysis (SAST) and malware detection in Android APKs.
A Python tool that analyzes embedded device firmware to identify potential security vulnerabilities and sensitive indicators.
A community-driven web and service fingerprint identification tool written in Rust, supporting version detection and vulnerability validation.
A pentest tool that checks Cloudflare-protected sites for origin IP leaks and misconfigurations.
A Chromium-based web browser with built-in XSS detection and taint tracking capabilities for security testing.
Apache 2-based honeypot and detection module for detecting and blocking the Struts CVE-2017-5638 exploit.
An ESLint plugin that detects potential XSS vulnerabilities in JavaScript code before deployment.
Official Node.js client library for programmatically accessing the OWASP Zed Attack Proxy (ZAP) API.
OWASP's software composition analysis tool that identifies project dependencies and checks for known vulnerabilities.
A GitHub Action that scans Docker images for OS and library vulnerabilities in CI/CD pipelines.
An ESLint plugin that detects vulnerable regular expressions susceptible to ReDoS attacks.
Integrates Bright's DAST security scan engine directly into .NET unit tests to find vulnerabilities early.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.