OWASP Coraza WAF is a golang modsecurity compatible firewall library
The SpotBugs plugin for security audits of Java web applications
Scanner detecting the use of JavaScript libraries
The OWASP ZAP core project
O-Saft - OWASP SSL advanced forensic tool
Probably the most modern and sophisticated insecure web application
Harness Open Source is an end-to-end developer platform
Code security scanning tool (SAST) to discover security risks
SonarSource Static Analyzer for Java Code Quality and Security
The OWASP MASVS (Mobile Application Security Verification Standard)
Manual for mobile app security testing and reverse engineering
Manual for mobile app security development and testing
Code security review tool for C/C++, C#, VB, PHP, Java, PL/SQL, COBOL.
Lift Framework
Static Application Security Testing (SAST) engine
The OWASP NodeGoat project
Offensive Web Testing Framework (OWTF), is a framework
Web and mobile application security awareness/training platform
Intentionally vulnerable web services exploitable with XXE
Yet another rugged PHP framework
Open Source Penetration Testing / Ethical Hacking Framework
PHP Role Based Access Control library