owasp/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 35 minutes ago
Added to GitGenius on September 6th, 2026
Created on May 14th, 2017
Open Issues & Pull Requests: 31 (+0)
GitHub issues: Enabled
Number of forks: 1,679
Total Stargazers: 9,795 (+1)
Total Subscribers: 414 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 2.1 hours
Mean response time: 156.7 days
90th percentile: 348.4 days
Tracked items: 96

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 50% of open issues come from outside the core team, a mix of external reports and the maintainers' own roadmap. Only 3% of issues opened in the past year have been closed. Three people close 95% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 22
New in 7 days: 2
Closed in 7 days: 3
Avg open age: 1,744 days
Stale 30+ days: 8
Stale 90+ days: 7

Recent activity

Opened in 7 days: 2
Closed in 7 days: 3
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • revise (38)
  • new (29)
  • enhancement (24)
  • help wanted (12)
  • good first issue (10)
  • repo (7)
  • invalid (6)
  • Translation (4)

Detailed Description

The Web Security Testing Guide is a comprehensive reference for security testing of web applications and services.

The guide addresses the need for a structured, standardized approach to identifying security vulnerabilities in web systems. It provides detailed testing methodologies covering the full lifecycle of web application security assessment, from initial reconnaissance through post-exploitation analysis. The guide organizes testing activities into logical categories and offers specific techniques, tools, and procedures that testers can follow to systematically evaluate security posture.

Organizations conducting penetration tests, security audits, or bug bounty programs should consider this guide as a foundational resource. It suits teams building internal security testing programs, developers learning secure coding practices, and security professionals seeking a comprehensive reference to ensure consistent coverage across testing engagements. The guide is particularly valuable for those who need a vendor-neutral, community-maintained standard rather than proprietary methodologies.

The project maintains active community engagement through contributions and updates that reflect evolving web security threats and testing techniques. The repository demonstrates sustained development activity with regular refinements to testing procedures and guidance. The guide continues to incorporate feedback from security practitioners and researchers working across diverse environments and application types.