OWASP-Testing-Guide-v5

The OWASP Testing Guide includes a "best practice" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes techniques for testing most common web application and web service security issues.

Github星跟蹤圖

OWASP Web Security Testing Guide

Contributions Welcome
OWASP Flagship
Twitter Follow

Creative Commons License

Welcome to the official repository for the Open Web Application Security Project (OWASP) Web Security Testing Guide (WSTG). The WSTG is a comprehensive guide to testing the security of web applications and web services. Created by the collaborative efforts of security professionals and dedicated volunteers, the WSTG provides a framework of best practices used by penetration testers and organizations all over the world.

We are currently working on release version 5.0. You can read the current document here on GitHub.

For the last stable release, view the previous version 4.0.

Contributions, Feature Requests, and Feedback

We are actively inviting new contributors! To start, read the contribution guide.

This project is only possible thanks to the work of many dedicated volunteers. Everyone is encouraged to help in ways large and small. Here are a few ways you can help:

  • Read the current content and help us fix any spelling mistakes or grammatical errors.
  • Choose an existing issue and submit a pull request to fix it.
  • Open a new issue to report an opportunity for improvement.

To learn how to contribute successfully, read the contribution guide.

Successful contributors appear on the project's list of authors, reviewers, or editors.

Chat With Us

We're easy to find on Slack:

  1. Join the OWASP Group Slack with this invitation link.
  2. Join this project's channel, #testing-guide.

Feel free to ask questions, suggest ideas, or share your best recipes.

You can @ us on Twitter @owasp_wstg.

You can also join our Google Group.

Project Leaders

Core Team

主要指標

概覽
名稱與所有者OWASP/wstg
主編程語言Dockerfile
編程語言Dockerfile (語言數: 1)
平台
許可證Creative Commons Attribution Share Alike 4.0 International
所有者活动
創建於2017-05-14 23:20:40
推送於2025-06-06 13:50:08
最后一次提交2025-06-06 09:50:08
發布數3
最新版本名稱20230928 (發布於 )
第一版名稱v4.1 (發布於 )
用户参与
星數8k
關注者數362
派生數1.4k
提交數1.1k
已啟用問題?
問題數360
打開的問題數52
拉請求數772
打開的拉請求數2
關閉的拉請求數76
项目设置
已啟用Wiki?
已存檔?
是復刻?
已鎖定?
是鏡像?
是私有?