OWASP Flagship Projects
Eleven of OWASP's flagship projects — the standards, guides and tools that define modern application security. Search or filter by category, then open any card for a detailed bilingual breakdown.
11 project(s)
OWASP Top 10
The data-driven awareness list of the ten most critical web application security risks.
Guides & StandardsOWASP Application Security Verification Standard (ASVS)
A community-driven catalog of testable security requirements for designing, building, and verifying web apps.
Guides & StandardsOWASP Web Security Testing Guide (WSTG)
The premier methodology and checklist for testing the security of web applications and web services.
Guides & StandardsOWASP Mobile Application Security (MAS)
The industry standard for mobile app security: MASVS standard, MASTG testing guide, and MAS Checklist for iOS & Android.
Guides & StandardsOWASP SAMM
An open, measurable framework to assess and improve an organization's secure software development lifecycle.
AI SecurityOWASP GenAI Security Project
Community guidance for securing LLM & generative AI apps, home of the Top 10 for LLM Applications.
AI SecurityOWASP AI Exchange
The world's open-source AI security & privacy guide and connective tissue to global AI standards.
Supply Chain / SBOMOWASP CycloneDX
Full-stack Bill of Materials standard for software supply chain security and risk reduction.
ToolsOWASP Dependency-Track
Continuous SCA platform that consumes CycloneDX SBOMs to cut software supply chain risk across a portfolio.
ToolsOWASP Juice Shop
Probably the most modern and sophisticated insecure web app for security training and CTFs.
ToolsOWASP CRS (Core Rule Set)
Generic, engine-agnostic attack-detection rules that give web app firewalls a first line of defense.