The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




Coraza is an open source, enterprise-grade, high performance Web Application Firewall (WAF) ready to protect your beloved applications. It is written in Go, supports ModSecurity SecLang rulesets and is 100% compatible with the OWASP Core Rule Set v4.

Medianova is a global company offering content delivery network (CDN) and cloud security solutions. Recognized by Gartner, the company specializes in areas such as Dynamic Site Caching, Static Content Delivery, Image Optimization, API Caching, Streaming, Hybrid CDN, Cloud Object...




Sn1per Professional is an all-in-one offensive security platform that provides a comprehensive view of your internal and external attack surface and offers an asset risk scoring system to prioritize, reduce, and manage risk.

FortiWeb web application firewall (WAF) protects business-critical web applications from attacks that target known and unknown vulnerabilities.

Dependency-Track is an intelligent Software Supply Chain Component Analysis platform that allows organizations to identify and reduce risk from the use of third-party and open source components.

The OWASP Amass Project has developed a tool to help information security professionals perform network mapping of attack surfaces and perform external asset discovery using open source information gathering and active reconnaissance techniques.
Guardius is a Software as a Service (SaaS) company designed to streamline and automate various IT needs for companies that operate their own websites or manage their own infrastructure. It is crucial for companies to safeguard their websites and infrastructure against potential...




Parasoft is recognized by software development professionals as the leader in software development lifecycle automation. By integrating software development management, quality lifecycle management, and dev/test environment management through service virtualization, regression...

Industry-leading free, high-performance, AI and semantic technology Web Application Firewall and API Security Gateway (WAAP) - UUSEC WAF.

An AI security testing platform for LLM applications that detects prompt injection, jailbreaks, and data leakage using 650+ real-world attack vectors aligned with the OWASP Top 10 for LLMs.


Intelligent Web Application Firewall that protects APIs in real-time against OWASP Top 10 attacks, injection attempts, and SSRF.

open-appsec (openappsec.io) in an open-source initiative that builds on machine learning to provide pre-emptive web app & API threat protection against OWASP-Top-10 and zero-day attacks.

Automated penetration testing platform for web applications, making professional security testing accessible to SMBs from €49/month.

AI Agent Security Testing — 112 attacks across 14 categories. Prompt injection, jailbreaks, MCP poisoning, agency hijacking & more. Test any AI agent in 5 minutes.
