DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML, and SVG. It's written in JavaScript and works in all modern browsers, ensuring security by sanitizing HTML to prevent XSS attacks. It has automated tests covering 19 different browsers and supports Node.js versions 16.x to 19.x.
FEATURES
ALTERNATIVES
OpenRASP directly integrates its protection engine into the application server by instrumentation, providing context-aware protection and detailed stack trace logging.
ESLint plugin to prevent Trojan Source attacks.
A collection of mobile security resources with tools, white papers, ebooks, and webinars.
WackoPicko is a vulnerable website with known vulnerabilities, now available as a Docker image and included in the OWASP Broken Web Applications Project.
A deliberately weak and insecure implementation of GraphQL for testing and practicing GraphQL security
A script that implements Cognito attacks such as Account Oracle or Priviledge Escalation
A Windows Kernel driver intentionally vulnerable to help improve skills in kernel-level exploitation.
Checkmarx One SAST is a static application security testing tool that combines speed and security to improve developer experience.
PINNED
InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.
Fabric Platform by BlackStork
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Mandos Brief Newsletter
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
RoboShadow
A cybersecurity platform that offers vulnerability scanning, Windows Defender and 3rd party AV management, and MFA compliance reporting, among other features.
Adversa AI
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.