Showing 36 of 233 projects
A simple, effective Go package for HTTP session management with customizable stores and OWASP-recommended defaults.
A Chromium-based web browser with built-in XSS detection and taint tracking capabilities for security testing.
An Elixir authentication library for Plug and Phoenix applications that provides a simple API with flexible underlying modules.
An integrated security system for Clojure applications built on Stuart Sierra's component library.
A fully customizable, one-time password input component for Angular applications.
Deterministic password generator using PBKDF2 with domain-specific salts for secure, memorable passwords.
Add HTTP Basic Authentication to static pages using Cloudflare Workers.
A simple Elixir library for integrating Google reCAPTCHA v2 into applications.
A framework for using AFL to fuzz web applications and detect SQL/command injection vulnerabilities.
A penetration testing tool for selectively downloading files from exposed .git repositories on web servers.
Okta ASP.NET middleware enables OAuth 2.0/OIDC authentication and authorization for ASP.NET and ASP.NET Core applications.
A Go middleware for parsing X-Forwarded-For and Forwarded headers to correctly identify client IP addresses behind proxies.
A repository containing Cure53's security audit reports, white papers, academic publications, and security tools.
A Go package for encoding and decoding secure cookies with encryption and authentication, offering high performance and zero heap allocations.
A tool that generates vulnerable web applications for security testing and education, supporting multiple attack modules.
A dead simple, highly performant, highly customizable sessions middleware for Go HTTP servers.
A Crystal HTTP middleware library that protects web applications against common attacks like XSS, clickjacking, and DoS.
A Rack middleware that scans uploaded files for viruses using antivirus software like Avast or F-Secure.
An ESLint plugin that detects potential XSS vulnerabilities in JavaScript code before deployment.
A simple and effective honeypot that mimics phpMyAdmin to detect and log unauthorized access attempts.
A low-interaction client honeypot that detects malicious websites using signature, anomaly, and pattern matching techniques.
A Ruby on Rails gem plugin for deploying a malicious behavior detection and response honeypot in under ten minutes.
A collection of Elixir plugs for HTTP Basic and Token authentication with role-based access control.
A highly flexible Rust library for managing and orchestrating JWT workflows, including login, logout, and token renewal.
A session management library for Kemal web applications in Crystal, supporting multiple storage engines and built-in CSRF protection.
An Angular component library for integrating hCaptcha verification into web applications.
A modular web application honeypot framework written in Go and Gin for detecting web attacks through deceptive applications.
Official Node.js client library for programmatically accessing the OWASP Zed Attack Proxy (ZAP) API.
A minimal vulnerable web application for security training, designed to practice finding and exploiting common web vulnerabilities.
An ICAP server that scans web content and URLs using YARA rules for security filtering.
A simple CAPTCHA service with a single API endpoint that generates captchas and validates answers via MD5 hash.
A comprehensive mind map for understanding and exploring Cross-Site Scripting (XSS) attack vectors and techniques.
Generates Subresource Integrity (SRI) hashes for Ember applications to secure JavaScript and CSS loaded from CDNs.
A hybrid data-driven REST API fuzzer that combines sequence generation, request quality improvement, and parameter error detection.
A Vapor middleware package that protects against CSRF attacks using session-based tokens.
A Cloudflare Worker that handles server-side verification for Google reCAPTCHA v3.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.