OWASP/Top10

Official OWASP Top 10 Document Repository

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 6 minutes ago
Added to GitGenius on September 11th, 2026
Created on August 30th, 2016
Open Issues & Pull Requests: 57 (+0)
GitHub issues: Enabled
Number of forks: 1,142
Total Stargazers: 6,073 (+0)
Total Subscribers: 302 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 11.0 days
Mean response time: 317.3 days
90th percentile: 1189.9 days
Tracked items: 114

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 10% of issues opened in the past year have been closed. Three people close 92% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 19
New in 7 days: 2
Closed in 7 days: 0
Avg open age: 226 days
Stale 30+ days: 17
Stale 90+ days: 13

Recent activity

Opened in 7 days: 2
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • translations (15)
  • Discussion (7)
  • bug (5)
  • enhancement (4)
  • wiki (3)
  • 2021 (2)
  • Links will be resolved by OSIB (2)
  • +R (1)

Detailed Description

OWASP Top 10 is a reference document that catalogs the most critical security risks in web applications.

The project addresses the need for a shared understanding of the most dangerous application security vulnerabilities. It works by gathering data from security professionals, researchers, and practitioners across the industry to identify and rank the top ten categories of security weaknesses that pose the greatest risk to web applications. The document serves as a consensus-driven baseline for understanding which vulnerabilities deserve the most attention and resources during development and security testing.

Organizations building or securing web applications should use this document as a foundational reference for their security programs. It suits teams at any stage—from those establishing initial security practices to mature organizations refining their vulnerability management priorities. The document provides a common language for discussing application security risks across development teams, security professionals, and business stakeholders, making it particularly valuable for prioritizing which vulnerabilities to address first when resources are limited.

The project maintains multiple versions of the document reflecting different release cycles, with earlier editions preserved for historical reference. The repository accepts feedback and issues from the community, indicating an open channel for practitioners to contribute observations and corrections to the guidance.