Ross ROSS = Recommend OSS · open-source software intelligence for agents

OWASP/API-Security resource

OWASP API Security Project observed · 2026-08-28

github.com/OWASP/API-Security · homepage · Dockerfile · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

77/100

  • Activity 99
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2792
  • days_rel: n/a
  • days_push: 8
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2337 stars · 412 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

The OWASP API Security Top 10 project, which publishes and maintains a ranked list of the most critical API security risks along with a documentation portal of best practices. It is a community-maintained reference for developers and security assessors building or testing APIs.

Use cases

  • learn the top 10 API security risks
  • secure my REST API against common vulnerabilities
  • checklist for API security assessment
  • understand broken object level authorization (BOLA)
  • best practices for API authentication and authorization
  • train developers on API security
  • reference for API penetration testing reports

When to choose

  • you are designing, building, or reviewing APIs and need authoritative security guidance
  • you are a security assessor or pentester looking for a standard API risk taxonomy
  • you want a widely recognized framework to justify API security investments

When to avoid

  • you need a runnable tool, scanner, or library rather than documentation
  • you need implementation code or automated testing for APIs
  • you need security guidance for non-API software like mobile apps or infrastructure

Facets

learning-resource · maturity active

security documentation api-documentation security apis web-development documentation owasp api-security top-10 best-practices security-assessment cheatsheet web-server docker

3 sources

Member repositories

RepositoryRoleHealth v2
OWASP/API-Securitymain77

For agents

markdown · JSON · MCP: product_card(name="OWASP/API-Security")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem