Stars
👓 A curated list of awesome android kotlin apps by open-source contributors.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Algorithms and data structures in Swift, with explanations!
A set of TSLint rules used on some Microsoft projects.
File upload vulnerability scanner and exploitation tool.
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
An OSINT tool that discovers sub-domains by searching Certificate Transparency logs
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
Testing TLS/SSL encryption anywhere on any port
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS Apps
Python AST-based static analyzer from OpenStack Security Group
🐘 SonarPHP: PHP static analyzer for SonarQube & SonarLint
LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help penetration testers and redteamers doing OSINT by gatheri…
Bandit is a tool designed to find common security issues in Python code.
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
Network layer wrapping Alamofire, Rx, OAuth and replay mechanism in a reactive abstract API
A tool to enforce Swift style and conventions.
Collection of the most common vulnerabilities found in iOS applications
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
ESLint rules for Node Security