Stars
👓 A curated list of awesome android kotlin apps by open-source contributors.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Algorithms and data structures in Swift, with explanations!
File upload vulnerability scanner and exploitation tool.
Passbolt Community Edition (CE) API. The JSON API for the open source password manager for teams!
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
An OSINT tool that discovers sub-domains by searching Certificate Transparency logs
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
Testing TLS/SSL encryption anywhere on any port
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS Apps
🐘 SonarPHP: PHP static analyzer for SonarQube & SonarLint
LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help penetration testers and redteamers doing OSINT by gatheri…
Bandit is a tool designed to find common security issues in Python code.
The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.
A tool to enforce Swift style and conventions.
Collection of the most common vulnerabilities found in iOS applications
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
ESLint rules for Node Security
Universal code quality CLI: Linting, formatting, security scanning, and metrics
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
A database of PHP security advisories
A cheat sheet for pentesters and researchers about vulnerabilities in well-known monitoring systems.