Showing 19 of 19 projects
A Rack-based Ruby library that standardizes multi-provider authentication for web applications.
An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.
A high-performance offensive security tool for reconnaissance, vulnerability scanning, and information gathering.
An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.
A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.
A SpotBugs plugin for detecting security vulnerabilities in Java web and Android applications.
A Go HTTP middleware that provides essential security headers and protections for web applications.
A machine learning security engine that preemptively prevents web app and API threats using supervised and unsupervised models.
A virtual host scanner for penetration testing that performs reverse lookups, detects catch-all scenarios, and works around wildcards and aliases.
A static analysis security scanner for Ruby web applications, supporting Rails, Sinatra, and Padrino frameworks.
A curated collection of CVEs, research, tools, and resources for WebSocket security testing and vulnerability research.
A W3C specification for a Content Security Policy that helps prevent cross-site scripting and other code injection attacks.
A security library for Vert.x applications providing authentication, authorization, and advanced security features via multiple protocols.
A Chromium-based web browser with built-in XSS detection and taint tracking capabilities for security testing.
An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.
Logto .NET Core SDKs for ASP.NET Core authentication and Blazor applications.
A Go library and CLI for encoding and decoding encrypted integer IDs to prevent enumeration and information leakage.
A state-aware fuzzer for testing browser security policies by generating diverse web application responses without database setup.
An Elixir Plug middleware for verifying HTTP requests signed with AWS Signature V4.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.