Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Web Security

Web Security

169 projects

Showing 36 of 157 projects

nosurf
nosurfGo

A CSRF protection middleware for Go that prevents Cross-Site Request Forgery attacks in any HTTP application.

#http-handler#web-security#breach-mitigation
Stars1.7k
Forks127
Last commit1 year ago
HtmlSanitizer
HtmlSanitizerC#

A .NET library for cleaning HTML fragments and documents to prevent XSS attacks using a robust HTML parser.

#web-security#xss#sanitizer
Stars1.7k
Forks223
Last commit9 days ago
LunaSec
LunaSecTypeScript

Open-source supply chain security scanner that automatically detects vulnerabilities like Log4Shell in dependencies and notifies via GitHub pull requests.

#supply-chain-security#zero-trust#web-security
Stars1.5k
Forks167
Last commit2 years ago
Captcha
CaptchaJavaScript

A curated list of awesome CAPTCHA libraries for generation and tools for cracking them.

#web-security#authentication#captcha-image
Stars1.4k
Forks125
Last commit1 month ago
XSRFProbe
XSRFProbePython

An advanced Cross-Site Request Forgery (CSRF) audit and exploitation toolkit for security testing.

#python-tool#csrf-attacks#owasp
Stars1.3k
Forks218
Last commit4 days ago
Security
SecurityC#

Security and authorization middleware for ASP.NET Core web applications.

#web-security#authentication#aspnet-product
Stars1.3k
Forks579
Last commit7 years ago
csrf
csrfGo

A Go middleware library providing CSRF protection for web applications with support for HTML forms and JavaScript frameworks.

#http-handler#web-security#csrf-protection
Stars1.2k
Forks169
Last commit1 year ago
Artemis
ArtemisPython

A modular vulnerability scanner that checks website security and automatically generates easy-to-read reports for organizations.

#modular-architecture#web-security#automated-reporting
Stars1.2k
Forks139
Last commit2 days ago
Friend
FriendClojure

An extensible authentication and authorization library for Clojure Ring web applications and services.

#functional-programming#web-security#authentication
Stars1.2k
Forks121
Last commit5 years ago
captcha
captchaPython

A Python library for generating audio and image CAPTCHAs with custom voice and font support.

#bot-protection#web-security#python-library
Stars1.1k
Forks189
Last commit7 months ago
mod_auth_openidc
mod_auth_openidcC

An OpenID Connect and FAPI 2 Relying Party module for Apache HTTPd, enabling standards-based authentication and authorization.

#reverse-proxy#openidconnect-client#web-security
Stars1.1k
Forks334
Last commit2 days ago
xss-filters
xss-filtersJavaScript

Context-sensitive output filters for preventing XSS attacks with minimal encoding.

#web-security#output-sanitization#html5
Stars1.1k
Forks137
Last commit9 years ago
Lonkero
LonkeroRust

A professional-grade web security scanner for penetration testing with intelligent, context-aware scanning and proof-based vulnerability detection.

#sql-injection#web-security#security-automation
Stars922
Forks69
Last commit2 days ago
wreq
wreqRust

An ergonomic Rust HTTP client with advanced TLS and HTTP/2 fingerprinting for browser emulation.

#bot-protection#web-security#browser-emulation
Stars840
Forks109
Last commit2 days ago
SecurityHeaders
SecurityHeadersC#

A small ASP.NET Core middleware package for adding and customizing security headers to protect websites.

#csp#hacktoberfest#owasp
Stars839
Forks87
Last commit25 days ago
FastAPI Login
FastAPI LoginPython

A FastAPI extension providing user session management and authentication similar to Flask-Login.

#fastapi#web-security#oauth2
Stars824
Forks68
Last commit1 year ago
FastAPI Guard
FastAPI GuardPython

A security middleware library for FastAPI providing IP control, rate limiting, penetration detection, and security headers.

#fastapi#rest#web-security
Stars788
Forks40
Last commit3 days ago
Javascript Mallware Collection
Javascript Mallware CollectionJavaScript

A collection of nearly 40,000 JavaScript malware samples for security research and analysis.

#malware-dataset#web-security#malware-samples
Stars760
Forks243
Last commit
AntiXSS
AntiXSSPHP

A PHP library that sanitizes user input to prevent Cross-Site Scripting (XSS) attacks.

#data-cleaning#hacktoberfest#php-security
Stars709
Forks117
Last commit9 days ago
uxss-db
uxss-dbHTML

A curated database of Universal Cross-Site Scripting (UXSS) vulnerabilities and browser security research resources.

#cve#vulnerability#web-security
Stars702
Forks83
Last commit5 years ago
markupsafe
markupsafePython

A Python library that escapes HTML/XML characters to safely include untrusted strings in markup.

#web-security#template-safety#markupsafe
Stars691
Forks179
Last commit8 months ago
bXSS
bXSSJavaScript

A utility for bug hunters and organizations to identify Blind Cross-Site Scripting vulnerabilities via customizable payloads and notifications.

#web-security#xss#cross-site-scripting
Stars573
Forks65
Last commit3 years ago
Securimage
SecurimagePHP

A PHP class for generating and validating CAPTCHA images and audio with extensive customization options.

#web-security#php-captcha#audio-captcha
Stars573
Forks197
Last commit2 years ago
Secure Headers
Secure HeadersPHP

A PHP package to add security-related HTTP response headers with Laravel integration.

#csp#lumen#web-security
Stars549
Forks47
Last commit2 months ago
NWebsec
NWebsecC#

Security libraries for ASP.NET applications that help implement HTTP security headers and other web security best practices.

#owasp#web-security#asp-net-core
Stars548
Forks74
Last commit3 years ago
JShell
JShellPython

A tool that creates a JavaScript shell payload for exploiting XSS vulnerabilities to execute code in a victim's browser.

#web-security#javascript-shell#penetration-testing
Stars532
Forks133
Last commit7 years ago
Strong node.js
Strong node.jsJavaScript

An exhaustive security checklist for Node.js web services, focused on Express and Hapi frameworks.

#secure-coding#vulnerability-assessment#owasp
Stars509
Forks28
Last commit2 years ago
DNS Rebind Toolkit
DNS Rebind ToolkitJavaScript

A frontend JavaScript framework for developing DNS rebinding exploits against vulnerable LAN devices and IoT products.

#iot#javascript-framework#web-security
Stars501
Forks84
Last commit4 years ago
site_encrypt
site_encryptElixir

Integrated Let's Encrypt certification for Elixir-powered sites without requiring external processes.

#elixir#web-security#phoenix-framework
Stars495
Forks36
Last commit3 months ago
dref
drefJavaScript

A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.

#iot#iot-security-testing#web-security
Stars493
Forks70
Last commit5 years ago
js-nacl
js-naclJavaScript

A pure-JavaScript high-level API wrapper for Emscripten-compiled libsodium cryptographic routines.

#web-security#encryption#nodejs
Stars493
Forks47
Last commit4 years ago
Snare
SnarePython

A web application honeypot sensor that clones websites to attract and analyze malicious attacks.

#hacktoberfest#sensor#honeypot
Stars479
Forks136
Last commit2 years ago
Juice Shop CTF
Juice Shop CTFTypeScript

A CLI tool to export OWASP Juice Shop security challenges into CTFd, RootTheBox, or FBCTF compatible formats.

#security-training#owasp#web-security
Stars473
Forks137
Last commit1 month ago
captcha
captchaJavaScript

A lightweight pure JavaScript CAPTCHA generator for Node.js with no external dependencies.

#bot-protection#gif-generation#web-security
Stars466
Forks47
Last commit2 years ago
Laravel Application Honeypot
Laravel Application HoneypotPHP

A Laravel package that prevents spam using honeypot fields and form submission timing validation.

#bot-protection#web-security#laravel
Stars437
Forks44
Last commit1 month ago
phauxth
phauxthElixir

A secure, extensible authentication library for Phoenix and other Plug-based Elixir web applications.

#elixir#library#web-security
Stars402
Forks20
Last commit4 years ago
PreviousPage 3 of 5

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
1 year ago
Next
#Security59
#Penetration Testing46
#Authentication38
#Middleware25
#Go19
#Python18
#Captcha16
#Owasp15
#Docker14
#Session Management13
#Security Tools13
#Nodejs13