webappsec-csp

Web security policy

A specification and implementation of the Content Security Policy (CSP) standard to secure web applications

WebAppSec Content Security Policy

GitHub

210 stars
92 watching
78 forks
Language: HTML
last commit: about 1 month ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
gosecure/csp-auditor Analyzes and configures website security policies to prevent malicious scripts from running on user devices. 136
mozilla/django-csp A Django middleware that enables the implementation of Content Security Policy (CSP) headers. 569
nlf/blankie A Hapi plugin that enables Content Security Policy (CSP) security features for web applications. 52
macademy/magento-csp-whitelist-generator Automatically generates a list of URLs to secure with Content Security Policy (CSP) 21
w3c/web-share API for sharing data from a web page to an arbitrary destination. 353
owasp/docker-security A guide to building secure containerized environments using Docker 632
wille/reporting-api Automates configuration of web application security headers to collect and report on policy violations 2
edoardottt/csprecon Tools for discovering new target domains using Content Security Policy 382
zigoo0/jsonbee Automated tool to discover and generate bypass payloads for Content Security Policy (CSP) restrictions on web pages 668
moloch--/csp-bypass Detects vulnerabilities in Content Security Policies 163
w3c/webauthn An API for authenticating web applications using public key credentials 1,186
owasp/owaspwebgoatphp An interactive web application designed to teach web application security through challenges and lessons. 122
aws-solutions/aws-waf-security-automations Automates deployment of AWS WAF security rules to protect against common web-based attacks 857
bepsvpt/secure-headers Adds security headers to HTTP responses to protect against common web vulnerabilities 507
openappsec/openappsec A machine learning-based security engine that protects web applications and APIs from threats. 916