# OWASP/www-project-top-10-for-large-language-model-applications

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

Repository: https://github.com/OWASP/www-project-top-10-for-large-language-model-applications
Canonical: https://ross.abutalabs.com/products/www-project-top-10-for-large-language-model-applications
Homepage: http://genai.owasp.org
Language: Python
License: NOASSERTION
License Family: other
Topics: ai, appsec, llm, llm-security
Last push: 2026-08-05T19:19:48+00:00

## Health v2 (maintenance only)
Score: 74/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 96, release rhythm 40, longevity 86
- inputs: {"age_days": 1205, "days_push": 28, "days_rel": 654, "gap_med": 3.0, "n_releases_24m": 3}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1378, forks 352 (observed 2026-08-28T04:04:33.592671+00:00)

## What it is
The OWASP Top 10 for Large Language Model Applications, a community-driven guide to the most critical security risks facing LLM-powered applications. This repository is now a legacy archive; active development has moved to the OWASP GenAI Security Project's GenAI-LLM-Top10 repository.

## Use cases
- identify the top security risks in LLM applications
- secure my chatbot or AI app against prompt injection
- learn about LLM application vulnerabilities
- checklist for reviewing GenAI app security
- reference for LLM security best practices
- train my team on AI application security risks

## When to choose
- you need authoritative, community-reviewed guidance on LLM application security risks
- you are building a security review or threat model for an LLM-powered product
- you want a widely cited reference for AI/LLM appsec risk categories

## When to avoid
- you need a tool or library that scans or mitigates vulnerabilities rather than documents them
- you want actively maintained content - use the successor GenAI-LLM-Top10 repository instead
- you need application-level security controls like auth or rate limiting

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, documentation
- domain: security, large-language-models, artificial-intelligence, developer-tools
- platform: -
- tags: llm-security, appsec, owasp, top-10, genai, security-guidance, risk-assessment, web-server

## Member repositories
- OWASP/www-project-top-10-for-large-language-model-applications (main) score 74

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:33.592671+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:20.881003+00:00, confidence not recorded.
  - readme: https://github.com/OWASP/www-project-top-10-for-large-language-model-applications (fetched 2026-08-28T04:04:33.592671+00:00, sha 4743d6caaadd)
  - homepage: http://genai.owasp.org (fetched 2026-08-29T11:56:25.367767+00:00, sha a4681ed77b61)
- Data as of 2026-08-30T08:39:29.467469+00:00.
