The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.
-
Updated
Sep 18, 2026 - HTML
The Web Security Testing Guide (WSTG) Project produces the premier cybersecurity testing resource for web application developers and security professionals.
Burp Suite extension (BApp Store) that finds backup, old, temporary and unreferenced files leaking sensitive data on web servers. OWASP WSTG-CONF-04.
OWASP ASVS Security Evaluation Templates with Nuclei
A lab-driven course on breaking web applications and explaining how to fix them — 491 notes, 36 reproducible labs, mapped to OWASP WSTG and the PortSwigger Top 10 Web Hacking Techniques.
OWASP Web Security Testing Guide (fa-IR)
Unified NIST + OWASP security framework MCP server — 36 tools, 3439+ records, live NVD/KEV, PDF reading, STRIDE threat modeling, compliance mapping
Community-maintained Spanish translation of the OWASP Web Security Testing Guide (WSTG). https://github.com/OWASP/wstg#translations.
Actionable, multi-language OWASP Web Security Testing Guide (WSTG) checklists.
Intentionally Vulnerable Pages for OWASP ASVS Security Evaluation Templates with Nuclei Project. https://snbig.github.io/Vulnerable-Pages/
WSTG tells you what to cover. This tells you what the tests inside each line actually are: the procedure, the oracle that separates a real result from the thing that imitates it, and where a success can lead. One offline, self-contained HTML file — no server, no install, no network.
Comprehensive OWASP Web Application Security Testing Checklist aligned with the latest OWASP WSTG. Includes guidance for web, API, and client-side testing.
Generate shareable security evidence reports from GitHub Actions.
Client-side password breach checker using k-anonymity (HIBP Pwned Passwords API). No backend, no full password or hash ever leaves the browser. WSTG-ATHN-07.
AI penetration testing platform with autonomous security agents
PUBLIC | Faculdade de Ciências e Tecnologia da Universidade de Coimbra (FCTUC) - Mestrado em Engenharia Informática (MEI) - Percurso: Engenharia de Software - 2022/2023 | Segurança em Tecnologias da Informação (STI) - Exercícios: OWASP ZAP; GnuPG; OpenVPN; Apache; X.509 certificates; IPTables/Netfilter; Snort; WSTG; ModSecurity; WAF.
OWASP WSTG checklist, passive candidate discovery, evidence verification, and reporting for Caido
Burp Suite extension that automates SQL injection detection (error/boolean/time-based, confidence-scored), WSTG-INPVAL-05. Detection only; exploitation stays manual.
CLI focused web app security scanner aligned with the OWASP Top 10 & WSTG. Safe-by-default, extensible, built in public.
To associate your repository with the wstg topic, visit your repo's landing page and select "manage topics."