Vulnerable Nodejs — a real shop (NodeBazaar) intentionally full of security bugs. 14 labs, OWASP Top 10:2025, SAST benchmark. Node.js port of DVWA.
-
Updated
Sep 8, 2026 - JavaScript
Vulnerable Nodejs — a real shop (NodeBazaar) intentionally full of security bugs. 14 labs, OWASP Top 10:2025, SAST benchmark. Node.js port of DVWA.
OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.
one-stop resource for all things offensive security.
CLI component of OWASP PurpleTeam
Mobile application security testing toolkit for Android, iOS & Flutter — ready-to-use FRIDA scripts (SSL pinning, root & anti-debug bypass, crypto monitoring), a full testing methodology, and hands-on guides.
A quick and easy to use security reconnaissance webapp tool, does OSINT, analysis and red-teaming in both passive and active mode. Written in nodeJS and Electron.
NexusBrute: A modular Node.js toolkit for ethical security testing. Features Smart Brute, API Fuzzer, Session Logger, and more ... Use responsibly! 🌌
Modern supply chain security for the npm ecosystem. Static + behavioral analysis that catches what npm audit, Snyk, and Socket miss — obfuscated payloads, credential stealers, conditional triggers, sandbox evasion, and worm-like propagation.
Application scanning component of OWASP PurpleTeam
Integrate static security testing with HCL AppScan on Cloud using GitHub Actions
TLS scanning component of OWASP PurpleTeam
API Testing & Pentesting Inside Chrome DevTools.
Orchestrator component of OWASP PurpleTeam
CSINT Research side project for static and staging-safe security regression checks of n8n AI workflows.
Server scanning component of OWASP PurpleTeam
Demo of API key cracking using a timing attack
Testing framework for firestore and firebase storage security rules.
A Chrome Plugin to Bypass jQuery Real Person Captcha
is a Node.js tool designed to validate the functionality of various types of proxy servers, including HTTP, HTTPS, SOCKS4, and SOCKS5. It reads a list of proxies from a file, checks each proxy's connectivity using the specified protocol, and logs the results.
⚡ Rust-powered HTTP/HTTPS intercepting proxy for penetration testing. Modern Burp Suite alternative with Vue.js UI. Real-time traffic analysis, fuzzing & request repeater.
To associate your repository with the security-testing topic, visit your repo's landing page and select "manage topics."