Awesome Web Security is a curated list of web security materials and resources for learning penetration testing techniques and vulnerability research.
The project addresses the widespread problem of web vulnerabilities caused by misconfiguration, insufficient security knowledge, and engineering gaps. It compiles learning materials, tools, and references organized by security topic to help developers and security researchers build cutting-edge penetration skills. The list covers areas including XSS, SQL injection, SSRF, JWT, OAuth, reconnaissance, WAF evasion, deserialization, SAML, and CTF write-ups.
This resource suits security practitioners, penetration testers, and developers seeking to deepen their web security knowledge. It works best as a reference guide for those actively studying security topics or preparing for capture-the-flag competitions. The project also integrates with AI assistants through a Claude Code Skill, allowing AI agents to query the latest content at runtime rather than relying on static snapshots, and supports integration with other AI tools like Codex.
The project maintains an actively curated collection with contribution guidelines in place. The tool ships structured data in a machine-readable format alongside the human-readable list, enabling programmatic access for AI assistants and other tools. Development activity includes ongoing maintenance of the resource index and support for multiple integration pathways beyond the core repository.