Security training for the apps you actually ship. Open your browser and start hacking.
-
Updated
Jul 19, 2026 - TypeScript
Security training for the apps you actually ship. Open your browser and start hacking.
Deliberately vulnerable REST API for OWASP Top 10 (2023) security testing and learning.
Unified penetration testing framework with interactive console. OWASP Top 10, cloud security, web app testing, JWT exploitation, and automated vulnerability scanning. 8 integrated modules for comprehensive security assessments.
Universal security audit skill for Claude Code — OWASP Top 10 (2021) + Russian security standards (ГОСТ Р 56939, ФСТЭК, ФЗ-152) + STRIDE threat modeling. Multi-stack: Node/Python/Go/Rust.
Description about-TheAuthor nd Contact info
Automated web pentesting framework for detecting SQLi, XSS, CSRF, insecure cookies, and SSL misconfigurations.
A detailed security report demonstrating a Blind OS Command Injection vulnerability using output redirection. This report includes the vulnerability analysis, proof of concept (PoC), impact assessment, and recommended remediation steps.
Solo red team web app pentest against OWASP Juice Shop (BeCode Mission 00, May 2026). 15 vulnerabilities documented (3 CRITICAL, 3 HIGH, 5 MEDIUM, 4 LOW) across 7/10 OWASP Top 10 categories. Manual exploitation, CVSS v3.1 + MITRE ATT&CK mapped, 47-page PDF + structured findings index.
Hands-on lab exploring OWASP Top 10 (2025) vulnerabilities: Broken Access Control, Authentication Failures, and Logging & Monitoring Failures.
Educational web app demonstrating OWASP Top 10 vulnerabilities (SQLi, XSS, logging, crypto) using PHP & MySQL.
Add a description, image, and links to the owasp-top10 topic page so that developers can more easily learn about it.
To associate your repository with the owasp-top10 topic, visit your repo's landing page and select "manage topics."