Checkmarx / JS-SCP
JavaScript Secure Coding Practices guide
☆178Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for JS-SCP
- ☆39Updated last year
- Some thoughts on how Node.js might respond to a changing security environment☆172Updated 5 years ago
- The OWASP AppSec Browser Bundle is an open source Linux based penetration testing browser bundle built over Mozilla Firefox. It comes pre…☆93Updated 10 years ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆42Updated 4 months ago
- Curated list of public penetration testing reports released by several consulting firms☆47Updated 6 years ago
- ☆35Updated 3 years ago
- Bodhi - Client-side Vulnerability Playground☆117Updated 3 years ago
- Documentation for Essential Node.js Security☆95Updated last year
- Content released at NorthSec 2018 for my talk on prototype pollution☆515Updated 5 months ago
- eslintrc.js config files for running static analysis on JavaScript to identify security issues.☆62Updated 4 years ago
- A list of ReDoS vulnerabilities in npm modules found by the Software Lab at TU Darmstadt. For each vulnerability, there is a proof-of-con…☆58Updated 6 years ago
- Security Payload Unit Test Repository (SPUTR)☆86Updated last year
- Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website☆136Updated 4 years ago
- Extreme Vulnerable Node Application☆93Updated 6 years ago
- Files for appsecwiki.com☆114Updated 4 years ago
- ☆32Updated last year
- Nodejs application intentionally vulnerable to SSRF☆41Updated last year
- Orchestron is an Application Vulnerability Management and Correlation Tool.Orchestron helps you solve one key problem "Find and fix vulne…☆31Updated last year
- Content for OWASP Summit 2017 site☆128Updated 4 years ago
- Repository for all the workshop content delivered at nullcon X on 1st of March 2019☆81Updated 5 years ago
- Turn your Burp suite into headless active web application vulnerability scanner☆155Updated 6 years ago
- Interactive IPython Notebook to demonstrate OWASP ZAP's API and Scripting Functions - OWASP ZAP 2.8.0☆41Updated last year
- The Pixi module is a MEAN Stack web app with wildly insecure APIs!☆112Updated last year
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 3 years ago
- This repository contains an example Python API that is vulnerable to several different web API attacks.☆27Updated 5 years ago
- OWASP Serverless Top 10☆213Updated 3 years ago
- Code Review Audit Script Scanner☆140Updated last year
- BountyDash is a tool to combine your rewards from all platforms, giving you insights about your progress and bug hunting patterns.☆140Updated last year