OWASP
A foundation and open projects for understanding application security, consulting guidance and putting technical risks in context.
Choose the project for the risk being studied
OWASP brings together community projects, documents and tools for software security. For a specific question, choose the relevant project or page and check its scope. A risk list helps structure a review; it is not an audit of your application.
- Selection
- Identify project, version and context.
- Use
- Compare guidance and tools with the studied environment.
- CSV
- Read spreadsheet-specific interpretation and protection limits.
Does mentioning OWASP certify a website?
No. Citing guidance establishes neither implementation nor service security.
Official documentation
Documentation consulted on .
Practical methods for this resource
Questions about OWASP
What does OWASP provide?
A foundation and open projects for understanding application security, consulting guidance and putting technical risks in context.
Which publisher and domain are listed?
OWASP Foundation is the publisher recorded for owasp.org. Follow the official destination and check its current details before acting.
Is inclusion a certification?
This is an editorial selection. It does not certify every statement, service or transaction on the external website.
Does mentioning OWASP certify a website?
No. Citing guidance establishes neither implementation nor service security.
Keep the context for your next step
Record version, download source, licence, required permissions and export method. Test the final file on the recipient’s platform; opening it in the editor does not validate the exchange.
Compare the evidence and resources for this subject →