awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
OWASP avatar

OWASP/wstg

0
View on GitHub↗
9,473 stars·1,627 forks·CC-BY-SA-4.0·16 viewsowasp.org/www-project-web-security-testing-guide↗

Wstg

The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software.

The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerability classification and modular domain decomposition, splitting the testing process into distinct focus areas such as authentication and input validation.

The framework covers broad capability areas including web application security testing, web service security auditing, and API security testing. It integrates scenario-based security testing and guideline-based remediation mapping to connect identified vulnerabilities to specific mitigation strategies.

Features

  • Web Security Auditing - Provides a comprehensive set of procedures and frameworks for systematically auditing the security of web applications.
  • Security Audit Workflows - Provides structured sequences of verification steps for conducting systematic security audits of web applications.
  • Web Security Audit - Implements a repeatable sequence of discovery and exploitation steps to identify weaknesses in web services.
  • Vulnerability Assessment and Testing - Provides a structured methodology for identifying security gaps through repeatable scenarios and verification steps.
  • API Security Checklists - Provides detailed checklists and methodologies specifically for evaluating the security posture of APIs.
  • Security Testing - Defines specific attack patterns and expected outcomes to verify the security posture of web applications.
  • Vulnerability Assessment Frameworks - Provides a systematic framework to discover and document security risks in web applications.
  • Web Application Penetration Testing - Offers a standardized approach for identifying and validating security flaws in web services.
  • Web Application Security Testing Guides - Provides a comprehensive framework of procedures and best practices for identifying vulnerabilities in web applications and services.
  • API Security Audit Frameworks - Provides a dedicated framework of methodologies and checklists for evaluating API security postures.
  • Remediation Guides - Provides actionable documentation and guidance for resolving identified security vulnerabilities using industry best practices.
  • Software Security Standards - Serves as a community-driven standard for conducting consistent and thorough audits of web-based software.
  • Classification Taxonomies - Uses a hierarchical classification system to organize security tests for systematic auditing.
  • Application Security - Comprehensive guide for testing web application security.
  • Security Testing - Comprehensive guide for web application security testing.

Star history

Star history chart for owasp/wstgStar history chart for owasp/wstg

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Wstg

Similar open-source projects, ranked by how many features they share with Wstg.
  • voorivex/pentest-guideVoorivex avatar

    Voorivex/pentest-guide

    2,761View on GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    View on GitHub↗2,761
  • fallibleinc/security-guide-for-developersFallibleInc avatar

    FallibleInc/security-guide-for-developers

    21,090View on GitHub↗

    This project is a web application security guide and developer training resource. It serves as a secure coding framework and vulnerability remediation manual, providing software engineers with the tools to identify, prioritize, and fix common security holes across different application layers. The resource utilizes a structured verification framework and security audit checklists to systematically find vulnerabilities. It features a technical reference that maps specific security flaws to step-by-step instructions for remediation, supported by vulnerability statistics to help determine which

    View on GitHub↗21,090
  • shieldfy/api-security-checklistshieldfy avatar

    shieldfy/API-Security-Checklist

    23,258View on GitHub↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    apijwtoauth2
    View on GitHub↗23,258
  • daffainfo/allaboutbugbountydaffainfo avatar

    daffainfo/AllAboutBugBounty

    6,644View on GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    View on GitHub↗6,644
See all 30 alternatives to Wstg→

Frequently asked questions

What does owasp/wstg do?

The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software.

What are the main features of owasp/wstg?

The main features of owasp/wstg are: Web Security Auditing, Security Audit Workflows, Web Security Audit, Vulnerability Assessment and Testing, API Security Checklists, Security Testing, Vulnerability Assessment Frameworks, Web Application Penetration Testing.

What are some open-source alternatives to owasp/wstg?

Open-source alternatives to owasp/wstg include: voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… fallibleinc/security-guide-for-developers — This project is a web application security guide and developer training resource. It serves as a secure coding… shieldfy/api-security-checklist — This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a… daffainfo/allaboutbugbounty — AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing.… kathanp19/howtohunt — HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning…