OWASP / NodeGoat
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
☆1,943Updated 11 months ago
Alternatives and similar repositories for NodeGoat
Users that are interested in NodeGoat are comparing it to the libraries listed below
Sorting:
- Awesome Node.js Security resources☆2,813Updated last week
- Web and mobile application security training platform☆1,380Updated 10 months ago
- Delightful Node.js packages useful for penetration testing, exploiting, reverse engineer, cryptography ...☆425Updated 3 years ago
- scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.☆3,832Updated 2 months ago
- nodejsscan is a static security code scanner for Node.js applications.☆2,469Updated this week
- Damn Vulnerable NodeJS Application☆728Updated last year
- A very vulnerable web site written in NodeJS with the purpose of have a project with identified vulnerabilities to test the quality of se…☆466Updated 8 months ago
- This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory☆879Updated 6 months ago
- ESLint rules for Node Security☆2,275Updated this week
- node security platform command-line tool☆1,665Updated 7 years ago
- OWASP Web Application Security Testing Checklist☆1,896Updated 2 years ago
- Security Knowledge Framework (SKF) Python Flask / Angular project☆819Updated last year
- OWASP API Security Project☆2,161Updated 4 months ago
- The OWASP Developer Guide☆2,070Updated this week
- Application Security Verification Standard☆3,002Updated this week
- A collection of ZAP scripts and tips provided by the community - pull requests very welcome!☆827Updated last month
- Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.o…☆1,865Updated last month
- More than 100 security checks for your Node.js API☆507Updated last year
- Getting a handle on container security☆651Updated last year
- njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.☆399Updated 6 months ago
- Application Security Automation☆528Updated last year
- A curated list of threat modeling resources (Books, courses - free and paid, videos, tools, tutorials and workshops to practice on ) for …☆1,534Updated 9 months ago
- ZAP Add-ons☆868Updated last week
- grep rough audit - source code auditing tool☆1,606Updated 3 weeks ago
- A minimal port of the old, publicly archived "owasp-esapi-js" (Enterprise Security API for JavaScript) encoder.☆136Updated 2 years ago
- Antora/Asciidoc content for Bjoern Kimminich's free eBook "Pwning OWASP Juice Shop"☆226Updated 3 weeks ago
- ☆1,402Updated 4 years ago
- This project is about creating and publishing threat model examples.☆419Updated 3 years ago
- You Don't Know Node.js☆1,540Updated 6 years ago
- A collected list of awesome security talks☆4,109Updated 4 years ago