Retour au classement

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

best-practicesguideowaspbugbountypenetration-testingpentestingapplication-securitysecurityhacktoberfestappsechacking
Croissance des étoiles
Étoiles
9.6k
Forks
1.6k
Croissance hebdomadaire
Issues
33
5k
juin 2017juin 2020juil. 2023juil. 2026
README

OWASP Web Security Testing Guide

Contributions Welcome OWASP Flagship Twitter Follow

Creative Commons License

Welcome to the official repository for the Open Worldwide Application Security Project® (OWASP®) Web Security Testing Guide (WSTG). The WSTG is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of security professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.

We are currently working on release version 5.0. You can read the current document here on GitHub.

For the last stable release, check release 4.2. Also available online.

How To Reference WSTG Scenarios

Each scenario has an identifier in the format WSTG-<category>-<number>, where: 'category' is a 4 character upper case string that identifies the type of test or weakness, and 'number' is a zero-padded numeric value from 01 to 99. For example:WSTG-INFO-02 is the second Information Gathering test.

The identifiers may change between versions. Therefore, it is preferable that other documents, reports, or tools use the format: WSTG-<version>-<category>-<number>, where: 'version' is the version tag with punctuation removed. For example: WSTG-v42-INFO-02 would be understood to mean specifically the second Information Gathering test from version 4.2.

If identifiers are used without including the <version> element, they should be assumed to refer to the latest Web Security Testing Guide content. As the guide grows and changes this becomes problematic, which is why writers or developers should include the version element.

Linking

Linking to Web Security Testing Guide scenarios should be done using versioned links not stable or latest, which will change with time. However, it is the project team's intention that versioned links do not change. For example: https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/01-Information_Gathering/02-Fingerprint_Web_Server.html. Note: the v42 element refers to version 4.2.

Contributions, Feature Requests, and Feedback

We are actively inviting new contributors! To start, read the contribution guide.

First time here? Here are GitHub's suggestions for first-time contributors to this repository.

This project is only possible thanks to the work of many dedicated volunteers. Everyone is encouraged to help in ways large and small. Here are a few ways you can help:

  • Read the current content and help us fix any spelling mistakes or grammatical errors.
  • Help with translation efforts.
  • Choose an existing issue and submit a pull request to fix it.
  • Open a new issue to report an opportunity for improvement.

To learn how to contribute successfully, read the contribution guide.

Successful contributors appear on the project's list of authors, reviewers, or editors.

Chat With Us

We're easy to find on Slack:

  1. Join the OWASP Group Slack with this invitation link.
  2. Join this project's channel, #testing-guide.

Feel free to ask questions, suggest ideas, or share your best recipes.

You can @ us on 𝕏 (Twitter) @owasp_wstg.

You can also join our Google Group.

Project Leaders

Core Team

Translations


Open Worldwide Application Security Project and OWASP are registered trademarks of the OWASP Foundation, Inc.

Dépôts similaires
goldbergyoni/nodebestpractices

✅ The Node.js best practices list (July 2026)

DockerfileCreative Commons Attribution Share Alike 4.0 Internationalnodejsjavascript
twitter.com/nodepractices/
105.4k10.7k
ryanmcdermott/clean-code-javascript

Clean Code concepts adapted for JavaScript

JavaScriptnpmMIT Licensejavascriptprinciples
94.7k12.5k
shanraisshan/claude-code-best-practice

from vibe coding to agentic engineering - practice makes claude perfect

HTMLMIT Licenseclaude-aiclaude-code
linkedin.com/in/shanraisshan
63.2k6.3k
h5bp/html5-boilerplate

A professional front-end template for building fast, robust, and adaptable web apps or sites.

JavaScriptnpmMIT Licensehtml5-boilerplatehtml5
html5boilerplate.com
57.6k12.3k
OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

PythonPyPICreative Commons Attribution Share Alike 4.0 Internationalowaspcode
cheatsheetseries.owasp.org
32.6k4.5k
GoogleChrome/lighthouse

Automated auditing, performance metrics, and best practices for the web.

JavaScriptnpmApache License 2.0auditbest-practices
developer.chrome.com/docs/lighthouse/overview/
30.6k9.7k
elsewhencode/project-guidelines

A set of best practices for JavaScript projects

JavaScriptnpmMIT Licensebest-practicesmaintainability
29.5k3.2k
futurice/android-best-practices

Do's and Don'ts for Android development, by Futurice developers

Otherbest-practicesandroid-development
20.5k3.3k
inancgumus/learngo

❤️ 1000+ Hand-Crafted Go Examples, Exercises, and Quizzes. 🚀 Learn Go by fixing 1000+ tiny programs.

GoGo ModulesOthergolanggo
twitter.com/inancgumus
20.1k2.7k
zhanymkanov/fastapi-best-practices

FastAPI Best Practices and Conventions we used at our startup

fastapibest-practices
17.7k1.3k
aidenybai/million

Optimizing compiler for React

TypeScriptnpmMIT Licensehacktoberfestmillion
old.million.dev
17.7k598
uber-go/guide

The Uber Go Style Guide.

MakefileApache License 2.0golanggo
17.6k1.8k