Open source owasp projects

Every project in the registry tagged owasp, ranked by real GitHub adoption.

projects 4 combined stars ★ 56K refresh nightly
01 shannon ★ 48K

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabi

last push9 days ago languageTypeScript licenseAGPL-3.0
02 agent-governance-toolkit ★ 6.3K

AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10

last push9 hours ago languagePython licenseMIT
03 cdxgen ★ 1.1K

Creates CycloneDX Bill of Materials (BOM) for your projects from source and container images. Supports many languages and package managers. Integrate in your CI

last push2 days ago languageJavaScript licenseApache-2.0
04 ship-safe ★ 844

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API

last push2 days ago languageJavaScript licenseMIT

← all tags

Frequently asked questions

How many open source owasp projects are there?

This registry tracks 4 projects tagged owasp, with 56,300 GitHub stars between them. The most-adopted is shannon at 48,105 stars.

Are these owasp projects free to use?

Yes — 4 of the 4 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which owasp project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these owasp projects still maintained?

4 of the 4 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.