An open API service indexing awesome lists of open source software.

Security

Cybersecurity (security) includes controlling physical access to hardware as well as protection from attacks that come via network access, data injection, and code injection.

https://github.com/plumsydev/neptune-waf.app

Neptune is a Web Application Firewall that you can use to protect your domains against common attacks (XSS, SSRF, SQLI, Path Traversal) and many others, it also can be used to hide your web server backend IP and protect against most DDoS attacks, come visit us !

api api-security application ddos firewall http-proxy letsencrypt neptune neptunewaf owasp security tcp-proxy waap waf web web-application-firewall xss

Last synced: 13 Jan 2026

https://github.com/lazureykis/throttlecrab

High-performance GCRA rate limiter for Rust. Multi-protocol server (HTTP, gRPC, Redis/RESP) with advanced metrics, or embed as a minimal library. Self-tuning memory management 🦀

api-gateway api-protection cloudnative cloudnative-services ddos-protection docker gcra grpc microservices rate-limit rate-limiter rate-limiting rate-limits ratelimit ratelimiter ratelimiting redis rust security throttling

Last synced: 22 Aug 2025

https://github.com/volkansah/implementing-ai-systems-whitepaper

This whitepaper provides best practices and concrete examples for the secure implementation of artificial intelligence in web applications. It covers topics such as security, data protection, ethics, AI models and algorithms, development process, user training, and regulation.

ai api artificial-intelligence artificial-neural-networks chatgpt gpt gpt4 how-to security whitepaper whitepapers

Last synced: 12 Sep 2025

https://github.com/mh37/Argos

A passive WiFi tracking and profiling based on probe request frames.

linux pentesting probe-requests python reconnaissance security sniffing tracking wifi wireless

Last synced: 23 Jul 2025

https://github.com/VolkanSah/Implementing-AI-Systems-Whitepaper

This whitepaper provides best practices and concrete examples for the secure implementation of artificial intelligence in web applications. It covers topics such as security, data protection, ethics, AI models and algorithms, development process, user training, and regulation.

ai api artificial-intelligence artificial-neural-networks chatgpt gpt gpt4 how-to security whitepaper whitepapers

Last synced: 12 May 2025

https://github.com/ongoingai/gateway

Headless, OpenAI-compatible AI gateway in Go. Multi-tenant auth, tracing, cost tracking, rate limits, and optional PII redaction. Single binary, self-hosted, audit-ready by design.

ai-gateway audit-logs cost-tracking go golang llm-gateway observability openai-compatible opentelemetry pii-redaction policy-enforcement privacy rate-limiting security tracing

Last synced: 24 Feb 2026

https://github.com/built-fast/phpstan-sensitive-parameter

PHPStan extension for detecting parameters that should use SensitiveParameter

code-quality php phpstan phpstan-extension security sensitive-parameter static-analysis

Last synced: 13 Jan 2026

https://github.com/denis-g/firefox-user.js

🦊 Firefox user.js – based on arkenfox/user.js with additional UI fixes.

firefox firefox-css firefoxcss ghacks mozilla mozilla-firefox privacy security settings userchrome userchromecss userjs

Last synced: 12 Apr 2025

https://github.com/apocas/wireguarode

Wireguard with ACLs and TOTP 2FA

acls iptables javascript nodejs security vpn wireguard

Last synced: 03 Oct 2025

https://github.com/hexydec/torque

A Wordpress plugin to optimise the transport of your website to the client. Reduce the load on your server and make your Wordpress website fly!

minification optimization performance security wordpress

Last synced: 18 Nov 2025

https://github.com/existenznl/permcheck

PermCheck is a little tool that checks if the files in a PHP project have the executable bit set properly.

executable executable-file php security security-tools security-vulnerability

Last synced: 14 Apr 2025

https://github.com/rodnt/portswiggerlabs

Solutions from @PortSwigger labs

infosec portswigger portswigger-labs security websecurity

Last synced: 25 Jul 2025

https://github.com/krishpranav/sniff

A Simple Golang Tool That Automates OSINT For Threat Intelligence And Mapping Your Attack Surface.

attack attack-defense attack-surface attack-surfaces bugbounty go golang recon reconnaissance scanner security web-security

Last synced: 14 Apr 2025

https://github.com/alphaville/safemsg

SafeMessage - Secure web-based message exchange system

encryption javascript message-exchange secure-by-default security

Last synced: 10 Apr 2025

https://github.com/connorjburton/senvf

A secure & sensible replacement for process.env

javascript nodejs process-env security supply-chain

Last synced: 10 Jul 2025

https://github.com/codestates-seb/seb39_main_013

고오급 남성 쇼핑몰 STATE MALL 입니다 https://statemall.click/

jpa mysql react reactquery security spring-boot styled-components

Last synced: 13 Apr 2025

https://github.com/pforret/bumpkeys

Upgrade your SSH keys for better security

bash bashew crypto ecdsa ed25519 rsa security security-audit ssh ssh-key

Last synced: 10 Apr 2025

https://github.com/mablanco/docker-reconftw

Docker image for reconftw, a simple script intended to perform a full recon on an objective with multiple subdomains

docker pentesting security

Last synced: 11 Jul 2025

https://github.com/sk3pp3r/devsecops-arsenal

A curated hub of DevSecOps tools to secure workflows, optimized for CI/CD and more

cybersecurity devops devsecops devsecops-pipeline infrastructure sdlc security ssdlc

Last synced: 12 Jan 2026

https://github.com/kuntoaji/enkrip

encrypt & decrypt Active Record attributes with Message Encryptor

activemodel activerecord activesupport decryption encryption gem message-encryptor ruby ruby-gem ruby-on-rails security

Last synced: 21 Jun 2025

https://github.com/shayanzare/admin-page-finder

This is a simple script to finding website admin page.

admin-page-finder hacking hacking-tool ruby security

Last synced: 28 Mar 2025

https://github.com/psecio/rift

A vulnerable application for teaching the basics of web application security

application security teaching vulnerability

Last synced: 11 Apr 2025

https://github.com/dominicbreuker/goncat

netcat-like CLI tool with advanced features for bind/reverse shells

bind-shell golang offsensive-security pentesting port-forwarding pty reverse-shell security tunneling

Last synced: 11 Apr 2025

https://github.com/jonhadfield/sts

Simplify working with AWS STS credentials and MFA

2fa aws aws-cli aws-sdk cli golang iam mfa security sts

Last synced: 15 Jul 2025

https://github.com/badchars/cve-mcp

23-tool MCP server for CVE & vulnerability intelligence. NVD, EPSS, CISA KEV, GitHub Advisory, OSV — unified in one server. Risk scoring, bulk triage, exploit search. 2 dependencies, runs with npx.

ai-security cisa claude cve cvss cybersecurity epss ghsa kev mcp model-context-protocol nvd osv pentesting security vulnerability vulnerability-intelligence

Last synced: 30 Jun 2026

https://github.com/badisi/auth-js

🛡️ Authentication and authorization support for web based desktop and mobile applications

angular auth authentication authn authorization capacitor cordova hybrid identity ionic mobile oauth oauth2 oidc openid openidconnect security web

Last synced: 12 Apr 2025

https://github.com/echo-devim/pyjacktrick

Python module hijacking POC

code-execution hijacking python security

Last synced: 27 Mar 2025

https://github.com/actions-rust-lang/audit

Audit Rust Dependencies using the RustSec Advisory DB

cargo-audit ci github-actions hacktoberfest rust rust-lang rustsec security

Last synced: 10 Apr 2025

https://github.com/connectFree/ZigZag

Noise Framework implementation in Zig Language for use in EVER/IP and WireGuard

crypto cryptography ever ever-ip everip noise noise-protocol noise-protocol-framework security wireguard zig

Last synced: 06 May 2025

https://github.com/chrissmartin/onvifscout

A comprehensive ONVIF device discovery and analysis tool that helps you find, authenticate, and examine ONVIF-compatible devices on your network.

hacktoberfest home-assistant home-automation onvif onvif-camera onvif-discovery pypi security security-camera

Last synced: 06 Jul 2025

https://github.com/tspascoal/dependabot-alerts-helper

A set of (simple) scripts to help manage dependabot alerts

dependabot scripts-collection security

Last synced: 07 May 2025

https://github.com/zeyu-li/tryhackme

Hacker Man 👨‍💻

hacking security tryhackme vulnversity writeups

Last synced: 19 Mar 2026

https://github.com/tomiok/vaultik

Vaultik is a cloud agnostic secret manager that helps developers to create, read, update and delete variables and easily export to a remote location or any cloud. Avoid using environment variables and these are fully encrypted.

cloud cloud-computing cobra encryption environment-variables go golang secret secret-management secrets secrets-management secure secure-storage security security-tools

Last synced: 28 Oct 2025

https://github.com/samiahmedsiddiqui/prevent-xss-vulnerability

This WordPress plugin enhances website security by preventing Cross-Site Scripting (XSS) vulnerabilities. It blocks and encodes malicious characters in URLs, escapes HTML in `$_GET` variables, and provides customizable settings for website owners.

encoding escape-html reflected-xss-vulnerabilities reflective reflective-injection security security-vulnerability self-xss wordpress xss xss-detection xss-vulnerability

Last synced: 12 Apr 2025

https://github.com/advanced-security/demo-java

GitHub Advanced Security scanning tutorial repository for Java

advanced-security demo devsecops example security static-analysis

Last synced: 12 Apr 2025

https://github.com/manavalan2517/login-and-register-system-in-python

This Python script is a comprehensive solution for managing user authentication, which includes both registration and login functionalities. It utilizes a local JSON file to store user credentials securely.

authentication interactive json py3 python realtime regex security terminal user-management

Last synced: 04 Jul 2025

https://github.com/geritol/write-guard

Github Action to enforce file level write access for monorepos

access-control github-actions monorepos security

Last synced: 14 Jan 2026

https://github.com/andresriancho/dirty-dependency-check

Vulnerability dependency check for Maven projects

dependency-analysis security security-tools

Last synced: 26 Oct 2025

https://github.com/simeononsecurity/apache-web-server-hardening

An collection of example configurations and scripts to aid administrators in configuring a hardened Apache Web Server

apache encryption hardening security ssl-certificates

Last synced: 01 Mar 2026

https://github.com/webinarium/symfony-lazysec

Symfony library with a bunch of security related features.

php security symfony

Last synced: 11 Jun 2025

https://github.com/houarizegai/aes

AES algorithm implementation in Java

aes aes-encryption cryptography information-security security

Last synced: 16 Mar 2026

https://github.com/ryru/hackingexposed

Kurs Hacking Exposed an Juventus Technikerschule HF

education hacking security websecurity

Last synced: 28 Apr 2025

https://github.com/prbinu/zcretshare

A command-line tool for sharing secret/key materials between two (or more) users using SSH keys

encryption golang gpg key-management pgp port-forwarding secret-sharing security security-tool ssh usable-security

Last synced: 29 Jan 2026

https://github.com/dye-tech/gatekey

GateKey is a zero-trust VPN solution that wraps OpenVPN. Users authenticate via their company's identity provider (Okta, Azure AD, etc.) and get short-lived VPN credentials automatically. No passwords to remember, no certificates to manage.

helm identity-management kubernetes oidc openvpn security self-hosted sso vpn wireguard zero-trust

Last synced: 30 May 2026

https://github.com/ypcrts/securemodelines

Secure alternative to Vim modelines. Maintained, active fork.

modeline security vim vim-modelines vim-plugin

Last synced: 09 Apr 2025

https://github.com/olivierlacan/opsec

Operational Security for everyone

educational operational opsec security

Last synced: 12 Feb 2026

https://github.com/nzt48/exploiting-smart-contract-vulnerabilities

Repository for "Exploiting smart contract vulnerabilities" bachelor thesis at School of Electrical Engineering, University of Belgrade. Paper (in Serbian) with 5 examples of vulnerable smart contracts and exploitation of them.

ethereum exploitation hacking security smart-contracts solidity

Last synced: 21 Apr 2026

https://github.com/yasenstar/archimate_sabsa

Learn & Practice of Modeling SABSA with the ArchiMate Specification

archimate architect architecture compliance enterprise model modeling opengroup sabsa security specification

Last synced: 11 Feb 2026

https://github.com/evervault/evervault-js

Evervault JavaScript SDK.

encryption javascript security

Last synced: 13 Feb 2026

https://github.com/markwalet/laravel-hashed-route

A Laravel package that replaces the default route model binding for a safer version.

laravel php php-library security

Last synced: 11 Mar 2026

https://github.com/konstruktoid/docker-covenant

Enforces a basic container argument policy

docker security

Last synced: 11 Mar 2025

https://github.com/riteshpuvvada/anonymous-board

Create a forum, chat or replay anonymously.

anonymous-chat board helmetjs javascript message mocha node-js security

Last synced: 12 Oct 2025

https://github.com/jon-becker/research

This repository contains research papers & studies that I have worked on or am currently working on.

blockchain erc ethereum nft research security security-audit solidity

Last synced: 25 Mar 2025

https://github.com/mishal/jwt

JWT (JSON Web Tokens) for PHP

json jwt php security webtoken

Last synced: 09 Mar 2026

https://github.com/JannisHoch/copro

(ML) model for computing conflict risk from climate, environmental, and societal drivers.

climate conflict environment projection risk security

Last synced: 20 Jul 2025

https://github.com/ancat/equation

Equation exposes a minimal environment to allow safe execution of Ruby code represented via a custom expression language.

expression-language ruby security

Last synced: 05 Oct 2025

https://github.com/qiwi/masker

Composite data masking utility

security

Last synced: 27 Apr 2025

https://github.com/djadmin/fort

macOS CLI: endpoint security audit + SOC 2 readiness reports

cli compliance devops endpoint-security golang hardening iso27001 macos security soc2

Last synced: 11 Jun 2026

https://github.com/ozbillwang/keycloak-compose

Run keycloak and keycloak cluster with docker compose - Up and Running in Seconds

authentication devops docker docker-compose keycloak keycloak-cluster security

Last synced: 25 Apr 2025

https://github.com/cipherstash/protectjs

Encrypt and protect data using industry standard algorithms, field level encryption, a unique data key per record, bulk encryption operations, and decryption level identity verification. Powered by CipherStash Encryption.

data data-security encryption javascript postgres postgresql security typescript

Last synced: 29 Oct 2025

https://github.com/whiteshadow1234/picoctf_writeup

A beginner-friendly picoCTF guide—complete challenges using only the webshell, no Linux or VM needed!

ctf ctf-challenges ctf-solutions ctf-writeups picoctf picoctf-writeups picoctfsolutions security

Last synced: 09 Feb 2026

https://github.com/agrim123/gatekeeper

Authentication and authorization oriented tool allowing users to ssh to a machine without giving them access to private keys.

bastion devops golang security ssh ssh-server

Last synced: 12 Mar 2026

https://github.com/rezmoss/network-vulnerability-scanner

Build a network vulnerability scanner from scratch in Go, port scanning, service detection, and vulnerability identification. Full walkthrough

cybersecurity go golang infosec networking penetration-testing port-scanner security tutorial vulnerability-scanner

Last synced: 12 Jun 2026

https://github.com/anatol/tang.go

Pure Golang implementation of server-side ECMR exchange functionality (Tang server)

clevis security tang

Last synced: 06 Jul 2025

https://github.com/contextforge-org/cpex

A composable enforcement framework for AI agents and toolchains

a2a agents ai extensibility framework hooks library llm mcp plugins safety security tools

Last synced: 27 Jun 2026

https://github.com/fenix-hub/godot-engine.otp

Godot Engine plugin to generate RFC4226 and RFC6238 compliant One Time Passwords in GDScript.

2fa auth gdscript godot godot-engine hotp mfa otp security totp

Last synced: 05 Mar 2026

https://github.com/edvincodes/instagramunfollowers

Instagram Unfollowers 2026: Free Script to see who isn't following you back. Safe, Open Source & No Login required. Works on Mobile & Desktop.

automation instagram instagram-follower instagram-followers instagram-following instagram-tool instagram-unfollowers javascript open-source privacy script security unfollow unfollowers

Last synced: 02 Apr 2026

https://github.com/firesphere/silverstripe-haveibeenpwnd

Check user passwords and emails against the HaveIBeenPwnd database

hacktoberfest haveibeenpwned password security silverstripe silverstripe-4 silverstripe-module

Last synced: 07 Oct 2025

https://github.com/trackit/s3-acl-viewer

Tool to generate a report about AWS S3 bucket permissions. CSV, Excel and Google Spreadsheet output available.

aws aws-s3 security

Last synced: 12 May 2025

https://github.com/spiderpig86/blog

:thought_balloon: Maybe some extraterrestrial will read this someday.

blog blog-theme frontend gatsby security software-engineering tech

Last synced: 30 Aug 2025

https://github.com/m3nu/wp-audit

Audit the versions of your Wordpress sites to find old, vulnerable versions.

golang security security-audit security-tools wordpress

Last synced: 24 Oct 2025

https://github.com/brndnmtthws/protect-yourself

A guide on how to protect your digital assets

digital-assets encryption phone privacy security yubikey

Last synced: 08 Mar 2026

https://github.com/piraces/kube-score-ga

Github action to execute kube-score with selected manifests (YAML, Helm or Kustomize)

analysis automation charts ci github-actions helm kube-score kubernetes linter security static-code-analysis

Last synced: 15 Apr 2025

https://github.com/maulingmonkey/firehazard

Unopinionated low level API bindings focused on soundness, safety, and stronger types over raw FFI.

rust sandbox sandboxing security win32 windows

Last synced: 30 Aug 2025

https://github.com/k4yt3x/ssh_config

K4YT3X's Hardened OpenSSH Client Configuration

hardening linux openssh security ssh

Last synced: 29 Oct 2025