Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Web Security

Web Security

169 projects

Showing 36 of 169 projects

VisualCaptcha
VisualCaptcha

A configurable, accessible, and secure visual CAPTCHA solution with support for multiple front-end and back-end frameworks.

#jquery#web-security#anti-bot
Stars400
Forks43
Last commit5 years ago
Git-Scanner
Git-ScannerShell

A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.

#hacking-tools#vulnerability-assessment#pentest-tool
Stars381
Forks93
Last commit6 years ago
Slim CSRF
Slim CSRFPHP

PSR-15 middleware for CSRF protection in Slim Framework applications.

#web-security#form-security#csrf-protection
Stars351
Forks59
Last commit6 months ago
DVCS-Pillage
DVCS-PillageShell

A toolkit to extract code, configs, and information from web-accessible git, hg, and bzr repositories that aren't fully cloneable.

#version-control-security#web-security#information-disclosure
Stars328
Forks58
Last commit
Stealing CSRF tokens with CSS injection (without iFrames)
Stealing CSRF tokens with CSS injection (without iFrames)HTML

A proof-of-concept demonstrating how to steal CSRF tokens via CSS injection without using iFrames, enabling client-side attacks.

#web-security#security-poc#service-workers
Stars323
Forks49
Last commit
OwaspHeaders
OwaspHeadersC#

An ASP.NET Core middleware that injects OWASP-recommended HTTP security headers with a single line of code.

#nuget#owasp#web-security
Stars311
Forks40
Last commit12 days ago
SliderCaptcha
SliderCaptchaJavaScript

A slider-based CAPTCHA library for web applications that supports PC and mobile with server-side verification.

#jquery#web-security#slider
Stars304
Forks84
Last commit2 years ago
html_sanitize_ex
html_sanitize_exElixir

An Elixir library for sanitizing HTML to protect against XSS attacks while allowing safe user-generated content.

#elixir#web-security#user-generated-content
Stars294
Forks73
Last commit20 days ago
javascript-crypto-library
javascript-crypto-libraryJavaScript

A high-performance JavaScript library providing AES-256, Fortuna PRNG, SRP authentication, and SHA-2 cryptographic functions for web applications.

#aes-256#web-security#hashing
Stars284
Forks44
Last commit
MIPT CTF
MIPT CTFPython

A beginner-friendly CTF (Capture The Flag) course covering cybersecurity topics like cryptography, web security, binary exploitation, and reverse engineering.

#beginner-friendly#web-security#cybersecurity-education
Stars280
Forks60
Last commit4 years ago
Symfony HTML Sanitizer
Symfony HTML SanitizerPHP

An object-oriented PHP library for sanitizing untrusted HTML input to prevent XSS and other injection attacks.

#web-security#dom-sanitization#sanitizer
Stars279
Forks13
Last commit2 days ago
aspnetcore-security-headers
aspnetcore-security-headersC#

Middleware for adding Content Security Policy, HSTS, and HPKP security headers to ASP.NET Core applications.

#csp#web-security#security-headers
Stars276
Forks44
Last commit1 year ago
jeff
jeffGo

A simple, stateful session management library for Go with CSRF protection and easy session revocation.

#web-sessions#stateful-sessions#web-security
Stars272
Forks16
Last commit1 year ago
FastAPI Auth
FastAPI AuthPython

A pluggable authentication library for FastAPI supporting OAuth2 password flow with JWT tokens and custom user models.

#fastapi#web-security#oauth2
Stars269
Forks10
Last commit3 years ago
JoomlaScan
JoomlaScanPython

A free and open-source scanner that identifies installed components, extensions, and files in Joomla CMS websites.

#python-tool#web-security#penetration-testing
Stars261
Forks72
Last commit2 years ago
Fingerprinter
FingerprinterRuby

A Ruby script that fingerprints remote applications and third-party scripts to identify their versions for security assessment.

#vulnerability-assessment#web-security#version-detection
Stars258
Forks38
Last commit8 months ago
Reverse-Shell-Manager
Reverse-Shell-ManagerPython

A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.

#exploit#web-security#penetration-testing
Stars246
Forks60
Last commit2 years ago
no-unsanitized
no-unsanitizedJavaScript

ESLint plugin that disallows unsafe innerHTML, outerHTML, and similar DOM manipulation methods without proper sanitization.

#dom-manipulation#sanitization#web-security
Stars245
Forks40
Last commit5 days ago
jwt-auth
jwt-authGo

A JWT authentication middleware for Go HTTP servers with short-lived auth tokens, refresh tokens, and CSRF protection.

#http-server#web-security#go-middleware
Stars238
Forks41
Last commit4 years ago
Any protection against dynamic module import?
Any protection against dynamic module import?HTML

A W3C specification for a Content Security Policy that helps prevent cross-site scripting and other code injection attacks.

#web-security#security-headers#w3c-specification
Stars222
Forks92
Last commit
Block Bad Bot Ruleset
Block Bad Bot Ruleset

A Cloudflare Firewall Rules ruleset to block malicious crawlers, spam referrers, and other bad internet traffic.

#malware-protection#user-agent#web-security
Stars220
Forks29
Last commit6 years ago
padding-oracle-attacker
padding-oracle-attackerTypeScript

A CLI tool and library for executing padding oracle attacks with concurrent network requests and an elegant UI.

#crypto#web-security#encryption-attacks
Stars217
Forks32
Last commit3 years ago
Lorg
LorgHTML

An advanced Apache logfile security analyzer for post-attack forensics, detecting web application attacks using multiple detection techniques.

#apache#web-security#security-analysis
Stars214
Forks47
Last commit7 years ago
Flask-SimpleLogin
Flask-SimpleLoginPython

A minimal Flask extension that adds login and logout routes to web applications with minimal configuration.

#hacktoberfest#flask-plugins#flask-extension
Stars204
Forks43
Last commit1 month ago
wordpot
wordpotCSS

A WordPress honeypot that detects probes for plugins, themes, and common files used to fingerprint WordPress installations.

#jinja2#honeypot#web-security
Stars185
Forks62
Last commit3 years ago
basic_auth
basic_authElixir

An Elixir Plug for adding HTTP basic authentication to web applications with configurable credentials or custom authentication functions.

#elixir#web-security#phoenix
Stars165
Forks26
Last commit6 years ago
captcha
captchaGo

A simple, unopinionated Go package for generating customizable CAPTCHA images with framework independence.

#bot-protection#web-security#authentication
Stars164
Forks23
Last commit9 months ago
observer_ward
observer_wardRust

A community-driven web and service fingerprint identification tool written in Rust, supporting version detection and vulnerability validation.

#web-security#nuclei-integration#redis-task-queue
Stars164
Forks11
Last commit7 days ago
Vapor Security Headers
Vapor Security HeadersSwift

A Vapor middleware library for adding security headers to protect against XSS, click-jacking, and other web vulnerabilities.

#https-enforcement#web-security#xss-protection
Stars153
Forks14
Last commit
verifyfetch
verifyfetchTypeScript

A drop-in library for resumable downloads and streaming integrity verification of large files in the browser.

#supply-chain-security#integrity#streaming-verification
Stars152
Forks1
Last commit2 months ago
DunglasAngularCsrfBundle
DunglasAngularCsrfBundlePHP

Automatic CSRF protection for JavaScript apps using Symfony APIs via cookie-header validation.

#csrf-attacks#cookie-validation#web-security
Stars148
Forks32
Last commit5 years ago
encrypt.to
encrypt.toRuby

Send encrypted PGP messages via a simple web link without signup, using public key servers.

#email-encryption#web-security#secure-messaging
Stars142
Forks28
Last commit8 years ago
hoauth2
hoauth2Haskell

A Haskell library for OAuth2 client authentication with support for multiple identity providers.

#haskell#functional-programming#web-security
Stars135
Forks56
Last commit1 month ago
Awesome CTF Cheatsheet
Awesome CTF Cheatsheet

A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.

#hacking-tools#web-security#ctf-challenges
Stars134
Forks12
Last commit1 year ago
sessionup
sessionupGo

A simple, effective Go package for HTTP session management with customizable stores and OWASP-recommended defaults.

#cookies#owasp#web-security
Stars131
Forks7
Last commit1 year ago
Cyclops
Cyclops

A Chromium-based web browser with built-in XSS detection and taint tracking capabilities for security testing.

#cyclops-browser#vulnerability#web-security
Stars127
Forks13
Last commit1 year ago
PreviousPage 4 of 5

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
9 years ago
8 years ago
10 years ago
1 month ago
1 year ago
Next
#Security59
#Penetration Testing46
#Authentication38
#Middleware25
#Go19
#Python18
#Captcha16
#Owasp15
#Docker14
#Session Management13
#Security Tools13
#Nodejs13