# tanprathan/OWASP-Testing-Checklist

OWASP based Web Application Security Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases.

Repository: https://github.com/tanprathan/OWASP-Testing-Checklist
Canonical: https://ross.abutalabs.com/products/owasp-testing-checklist
License Family: other
Last push: 2023-02-09T12:19:01+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 3994, "days_push": 1301, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1808, forks 490 (observed 2026-08-28T04:05:39.310529+00:00)

## What it is
An Excel-based web application security testing checklist built on the OWASP Testing Guide v5 (WSTG), used to track completed and pending test cases. It also includes an OWASP Risk Assessment Calculator and a Summary Findings template.

## Use cases
- track web app pentest test case status in a spreadsheet
- build a web application security testing plan based on OWASP WSTG
- map security test cases to CWE identifiers
- assess risk severity for web vulnerabilities during a pentest
- generate summary findings reports for a penetration test engagement

## When to choose
- you need a ready-made OWASP WSTG-aligned checklist for manual web app security testing
- you want to track pentest progress and findings in Excel
- you need a CWE-mapped testing framework for your security team

## When to avoid
- you need automated vulnerability scanning rather than a manual checklist
- you require a tool with an API or programmatic integration
- you need a license-backed software project for commercial redistribution without review

## Facets
- artifact type: dataset
- maturity: maintenance
- function: penetration-testing, security, testing, documentation
- domain: security, penetration-testing, web-development, awesome-lists
- platform: cross-platform
- tags: owasp, wstg, checklist, excel, web-application-security, pentest-tracking

## Member repositories
- tanprathan/OWASP-Testing-Checklist (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:39.310529+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:21:24.275327+00:00, confidence not recorded.
  - readme: https://github.com/tanprathan/OWASP-Testing-Checklist (fetched 2026-08-28T04:05:39.310529+00:00, sha ac89d75e3ec4)
- Data as of 2026-08-30T08:39:29.467469+00:00.
