You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Learn to code securely while having fun through our popular open source in-editor experience, designed for developers, students, and anyone curious about security. Get started for free in under 2 minutes, playing right from your browser.
Claude Code skill for OWASP security best practices (2025-2026). Includes Top 10:2025, ASVS 5.0, Agentic AI security, and 20+ language-specific security quirks.
A client-side web security tool that sanitizes potentially malicious HTML and JavaScript input by stripping unsafe tags and event attributes. Designed to demonstrate XSS prevention concepts, safe input handling, and frontend security practices using pure HTML, CSS, and JavaScript in a beginner-friendly interface.
This extension helps bug bounty hunters and recon specialists quickly search for archived URLs of any domain using the Wayback Machine. One click, instant access to historical data that might expose forgotten paths, juicy parameters, or legacy vulnerabilities.
A CLI tool that processes @pre, @post, and @invariant tags in functions, classes, and methods within a source file. It generates a modified version of the source code that automatically validates input conditions (@pre), result conditions (@post), and invariant conditions (@invariant).
A cybersecurity-themed personal portfolio built with vanilla web technologies. This isn't just a résumé — it's a demonstration of my engineering philosophy: secure by design, performant by default, beautiful by intention.
AI-assisted DevSecOps security lab using GitHub Copilot, GitHub CodeQL, and Advanced CodeQL workflows for vulnerability detection, remediation, and secure software development validation.
CRUXIDE is a track-based developer experience for VS Code that brings curated tooling, AI skills, engineering rules, code review guidance, and orchestration into one secure workspace.
MayaSec is a lightweight, zero-config JavaScript SDK that adds an invisible security layer to any website. It silently monitors user behavior, fingerprints devices, detects bots, and blocks attacks like SQL Injection - all from the browser, without touching your backend code.
Before/after security hardening of an AI-generated Supabase SaaS. 19 findings: service-role key in the browser, no row level security, broken object-level authorization, public storage bucket. Exploit tests on both branches, demonstrating each hole then proving it closed.