Ross ROSS = Recommend OSS · open-source software intelligence for agents

OWASP/mastg resource

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS. observed · 2026-08-28

github.com/OWASP/mastg · homepage · Python · CC-BY-SA-4.0 (other) observed · 2026-08-28

Health v2 · maintenance only

95/100

  • Activity 97
  • Release rhythm 90
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 2.5
  • age_days: 3624
  • days_rel: 64
  • days_push: 19
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

13137 stars · 2782 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and reverse engineering on Android and iOS. It provides technical test cases and processes for verifying OWASP MASWE weaknesses aligned with the MASVS standard, plus downloadable security checklists.

Use cases

  • test android app for security vulnerabilities
  • perform ios penetration testing
  • learn mobile app reverse engineering
  • verify app against owasp masvs standard
  • create mobile security compliance checklist
  • analyze app network traffic and runtime behavior
  • audit mobile app cryptography usage

When to choose

  • you need authoritative, standards-aligned mobile security testing guidance
  • you are pentesting or auditing android or ios applications
  • you need checklists for mobile app security compliance
  • you want free, community-maintained documentation trusted by industry

When to avoid

  • you need an automated scanning tool rather than a manual guide
  • you are testing web or desktop applications instead of mobile apps
  • you need executable test suites rather than documented procedures

Facets

learning-resource · maturity active

penetration-testing reverse-engineering security testing documentation security mobile-development penetration-testing developer-tools tutorials cross-platform mobile-security owasp masvs maswe pentesting android ios reverse-engineering static-analysis dynamic-analysis checklists

5 sources

Member repositories

RepositoryRoleHealth v2
OWASP/mastgmain95

For agents

markdown · JSON · MCP: product_card(name="OWASP/mastg")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem