Showing 36 of 73 projects
A commercial remote browser isolation (RBI) platform that streams a full modern browser to any client with low latency and 60 FPS.
A fast, configurable HTML sanitizer for Go that scrubs user-generated content of XSS attacks using an allowlist policy.
A PHP client library for Google's reCAPTCHA service to verify user responses and protect websites from spam.
A standards-compliant HTML filtering library for PHP that removes malicious code while preserving safe markup.
Chrome extension and Express server demonstrating a CSS-based keylogging attack on password inputs.
A Ruby gem for automatically applying security headers with safe defaults to protect web applications from common vulnerabilities.
Cryptographically sign and verify data to safely pass it between trusted and untrusted environments.
A collection of test subdomains with intentionally broken SSL configurations for testing client security behavior.
Open source Runtime Application Self-Protection (RASP) solution that integrates security directly into application servers via instrumentation.
A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.
A configurable Go net/http handler for handling Cross-Origin Resource Sharing (CORS) requests.
A proof-of-concept system that defeats Google's audio reCaptcha with 85% accuracy using speech recognition and browser automation.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
A lightweight, efficient, and secure HTTP session management library for Go applications.
A comprehensive security framework for Java applications, supporting authentication, authorization, and integration with multiple protocols and frameworks.
A Python tool to dump a git repository from a website, even when directory listing is disabled.
A general Rack authentication framework for Ruby web applications providing flexible authentication strategies.
A flexible Go package for generating and verifying captchas as base64-encoded image or audio strings.
A Go HTTP middleware that provides essential security headers and protections for web applications.
A web-based toolkit for XSS (Cross-Site Scripting) testing, encoding/decoding, and payload generation.
A self-hosted, privacy-first CAPTCHA alternative using proof-of-work to protect websites and APIs from spam without tracking.
A comprehensive HTML file enumerating all possible ways a website can leak HTTP requests for security testing.
A Python tool that scans HTTP servers for publicly accessible secret files and security vulnerabilities like git repos and backup files.
A command-line tool for automatic acquisition and renewal of TLS certificates from ACME servers like Let's Encrypt.
A Go package for generating and verifying image and audio CAPTCHAs with built-in storage and HTTP server support.
A vulnerable Node.js web application designed to teach how to identify and fix OWASP Top 10 security vulnerabilities.
Scans websites for publicly known security vulnerabilities in frontend JavaScript libraries using the Snyk database.
A Ruby gem providing helper methods for integrating Google reCAPTCHA and hCaptcha into web applications.
A Laravel service provider for HTMLPurifier, enabling secure HTML filtering and XSS prevention.
Generate SVG-based CAPTCHAs in Node.js without C++ addons, offering lightweight and customizable spam protection.
A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.
A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.
A community-driven checklist of security precautions for Ruby on Rails applications to minimize vulnerabilities.
A PHP library for generating and validating CAPTCHA images to protect forms from bots.
A grammar-based DOM fuzzer that generates HTML, CSS, and JavaScript test cases to find security vulnerabilities in web browsers.
A CSRF protection middleware for Go that prevents Cross-Site Request Forgery attacks in any HTTP application.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.