OWASP Cheat Sheet Series

OWASP Cheat Sheet Series provides concise, practical application security guidance that developers and defenders can apply in real projects.

Published Cheat Sheets
121
Contributors
456
GitHub Stars
33.1k

About OWASP Cheat Sheet Series

Practical security guidance

The OWASP Cheat Sheet Series is a community-maintained collection of concise, actionable guidance on specific application security topics. It is written for developers and defenders who need advice they can apply in real projects. Read and reference the published cheat sheets on the official website; the Markdown files in GitHub are the working sources.

Mapped to OWASP standards

The repository includes dedicated indexes that connect relevant cheat sheets to OWASP ASVS, OWASP MASVS, the OWASP Top 10, and OWASP Top Ten Proactive Controls. These mappings help teams move from security requirements and risk categories to focused implementation guidance.

Contribute and connect

The project welcomes contributions large and small. Improve wording, work on an approved issue, or propose an enhancement after reading the contribution guide and writing guideline. For questions and ideas, join the OWASP Slack workspace and the #cheatsheets channel.

Project Leaders

Jim Manico

Project Leader

EmailLinkedIn

Jakub Maćkowski

Project Leader

EmailLinkedIn

Gabriel Corona

Project Leader

EmailLinkedIn

Major Contributors

Recognizing key contributors who have made significant impact on this project.

Kevin W. Wall

Core Team

LinkedIn

Shlomo Zalman Heigh

Core Team

LinkedIn

Project Information

Flagship Project
Classification
Documentation
License
Creative Commons Attribution-ShareAlike 4.0 International
Contributors
456
GitHub Stars
33142
Industry Usage
Software DevelopmentApplication SecurityDevSecOpsSecurity Education
Compliance Standards
OWASP ASVSOWASP MASVSOWASP Top 10OWASP Top Ten Proactive Controls
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.
OWASP Cheat Sheet Series | Application Security Guidance