OWASP/mastg resource
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 97
- Release rhythm 90
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 2.5
- age_days: 3624
- days_rel: 64
- days_push: 19
- n_releases_24m: 3
Adoption not part of the score
13137 stars · 2782 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive open-source manual for mobile app security testing and reverse engineering on Android and iOS. It provides technical test cases and processes for verifying OWASP MASWE weaknesses aligned with the MASVS standard, plus downloadable security checklists.
Use cases
- test android app for security vulnerabilities
- perform ios penetration testing
- learn mobile app reverse engineering
- verify app against owasp masvs standard
- create mobile security compliance checklist
- analyze app network traffic and runtime behavior
- audit mobile app cryptography usage
When to choose
- you need authoritative, standards-aligned mobile security testing guidance
- you are pentesting or auditing android or ios applications
- you need checklists for mobile app security compliance
- you want free, community-maintained documentation trusted by industry
When to avoid
- you need an automated scanning tool rather than a manual guide
- you are testing web or desktop applications instead of mobile apps
- you need executable test suites rather than documented procedures
Facets
learning-resource · maturity active
penetration-testing reverse-engineering security testing documentation security mobile-development penetration-testing developer-tools tutorials cross-platform mobile-security owasp masvs maswe pentesting android ios reverse-engineering static-analysis dynamic-analysis checklists
5 sources
- readme: https://github.com/OWASP/mastg · fetched 2026-08-28 · afef5dfc0d4d
- homepage: http://mas.owasp.org/ · fetched 2026-08-29 · 21a2748e1dae
- site_page: https://mas.owasp.org/MASWE/MASVS-CODE/MASWE-0045 · fetched 2026-08-29 · 4f468f1dcb5a
- site_page: https://mas.owasp.org/MASTG/tests/android/MASVS-CODE/MASTG-TEST-0044 · fetched 2026-08-29 · 2a39fcc6e4d3
- site_page: https://mas.owasp.org/MASVS/02-Frontispiece · fetched 2026-08-29 · 7093923b48e4
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| OWASP/mastg | main | 95 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem