owasp/asvs

Application Security Verification Standard

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 23 minutes ago
Type:Documentation / SpecificationCategory(s):AppSec & Supply ChainSecurity & Privacy
Added to GitGenius on September 19th, 2026
Created on October 30th, 2014
Open Issues & Pull Requests: 111 (+0)
GitHub issues: Enabled
Number of forks: 832
Total Stargazers: 3,611 (+0)
Total Subscribers: 150 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 2.6 hours
Mean response time: 4.2 days
90th percentile: 5.4 days
Tracked items: 694

Most active contributors

Sign in to see contributor activity.

How this project is maintained

About 10% of issues opened in the past year have never received a reply. 72% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Only 35% of issues opened in the past year have been closed. Three people close 92% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 96
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 517 days
Stale 30+ days: 90
Stale 90+ days: 81

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • _5.0 - prep (340)
  • 1) Discussion ongoing (251)
  • 6) PR awaiting review (211)
  • _5.0 - rc1 (127)
  • _5.0 - Not blocker (75)
  • V6 (prev V2) (74)
  • V10 (prev V51) (66)
  • V1 (prev V5) (64)

Most active issues this week

Detailed Description

ASVS is an open application security standard that defines comprehensive security requirements for designing, developing, and testing web applications and services.

The standard addresses the need for a consistent, community-driven framework to verify that applications meet baseline security expectations. It organizes security requirements into categories covering areas such as authentication, session management, access control, input validation, cryptography, and other critical domains. Organizations use ASVS to establish security baselines, guide development practices, and structure security testing efforts across their applications.

Teams should adopt ASVS if they need a structured, widely recognized framework for application security verification. It suits organizations building web applications and services that require formal security validation, whether for internal standards, compliance purposes, or third-party assessments. The standard is particularly valuable for teams seeking alignment with industry best practices and a common language for discussing application security requirements across development, security, and testing functions.

The project maintains active development with ongoing refinement of requirements to reflect current software security advances. The working group regularly incorporates community feedback through issue tracking and pull requests. The project actively seeks translations of the current branch to expand accessibility across languages and regions.