Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
-
Updated
Sep 24, 2026 - Java
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
JavaSecLab is a comprehensive Java vulnerability platform| JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……
Integrates Dependency-Check reports into SonarQube
OWASP VulnerableApp Project: Break it. Scan it. Reproduce it. Benchmark against it. Improve it.
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects
Creates CycloneDX Software Bill of Materials (SBOM) from Gradle projects
Java web and command line applications demonstrating various security topics
Burp Suite extension (BApp Store) that finds backup, old, temporary and unreferenced files leaking sensitive data on web servers. OWASP WSTG-CONF-04.
DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers.
End to End testing of Web, API, Cloud, Events and Security
Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.
CycloneDX SBOM Model and Utils for Creating and Validating BOMs
The aim of this project is to protect Java applications against CSRF attacks with the use of Synchronizer Tokens
Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable dependencies are found.
To associate your repository with the owasp topic, visit your repo's landing page and select "manage topics."