GitStar
โŒ˜K
GitStar

A ranking dashboard for GitHub momentum, durable repository leaders, package adoption, and editorial context.

Data source ยท GitHub API and package ecosystem snapshots

Home

HomeTrendingMomentumPulseExplore

Discover

CategoriesLanguagesOrganizationsAI / MLMCP

Workflow

CompareWatchlistRandom

Knowledge

InsightGuideMethodology

Support

FAQAbout GitStarContactPrivacyTerms

ยฉ 2026 GitStar. All rights reserved.

Data sourced from GitHub API

TrendingMomentumPulseExplore
  1. Home
  2. Organizations
  3. OWASP
OWASPOrganization

OWASP

@owasp โ€ข The OWASP Foundation. Use this route to separate flagship concentration from portfolio breadth before you treat a publisher as broadly strong.

Portfolio concentration

91%

Top three share

Shows whether the organization is driven by one breakout repo or several visible projects.

Breadth

29 repos

Visible snapshot

29 repositories updated in the last 90 days.

Leading language

Ruby

Portfolio mix

Ruby (14), Unknown (11), Python (3)

Average size

5

Stars per repository

Useful for distinguishing one flagship-heavy publisher from a repeatable portfolio.

Back to organizationsCompare repositories
Updated: 2026-09-09(7d ago)GitHub API fallback29 repositories

Portfolio Shape

91%

of the visible star count comes from this organization's top three repositories.

Average Repository Size

5

stars per repository in this same snapshot.

Current Mix

Ruby

is the most common language here, with 29 repositories updated in the last 90 days.

Why this rank

This organization stands out because one flagship repo drives 60% of its visible star count.

Flagship share 60%Breakout repo: OWASP-MCP-Governance-and-Risk-Project

Organization pages work best when you separate portfolio breadth from flagship concentration. In OWASP's case, the visible top three repositories account for about 91% of total stars in this snapshot, which helps explain whether the organization is known for one breakout project or for a broader repeatable portfolio.

The dominant language mix here is Ruby (14), Unknown (11), Python (3). That makes this page useful not just for popularity checks, but also for seeing what technical shape an organization's public ecosystem actually has.

Source: GitHub API fallback. This is the same cache-first snapshot used by the organization ranking list, so the summary view and the detail view should stay aligned.

Top Repositories

#RepositoryLanguageStars๐Ÿด ForksUpdated
1owasp/OWASP-MCP-Governance-and-Risk-Project

A practical governance framework for organizations adopting the Model Context Protocol (MCP), the open standard that lets AI agents connect to external tools, data sources, and systems.

84131 weeks ago
2owasp/OWASP-Subtractive-Hardening-Top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths.

2824 weeks ago
3owasp/VulnReach

Runtime-aware SCA โ€” proves which CVEs are actually reachable, not just installed.

Python1414 weeks ago
4owasp/OWASP-OpenShield301 months ago
5owasp/Community-Security-PromptsHTML212 days ago
6owasp/www-chapter-garhwalRuby101 weeks ago
7owasp/www-chapter-almatyRuby111 weeks ago
8owasp/www-chapter-iit-gandhinagarRuby101 months ago
9owasp/www-chapter-pamplonaRuby101 weeks ago
10owasp/www-chapter-chandigarh-university-mohaliRuby101 months ago
11owasp/TriSuElla-AIDLCA-Framework

The OWASP TriSuElla-AIDLCA Framework is a production-ready, policy-governed secure software development life cycle (SDF) and autonomous agent governance framework (LLMSecOps) built on the Nordic resilience principles of SISU (hardened architecture), TILLIT (zero-trust verification), and DUGNAD (dual-key human-in-the-loop oversight).

Python102 days ago
12owasp/OWASP-Open-Source-Intelligence-Standard

OOVS, the OWASP OSINT Verification Standard. Ten requirements, one acceptance test each, in prose and machine-readable form.

Python112 weeks ago
13owasp/Citizen-Vibe-Coder-Security-Model101 months ago
14owasp/www-chapter-kinnaurRuby001 weeks ago
15owasp/www-chapter-north-dakota-state-universityRuby00Today
16owasp/www-chapter-kgreddy-college-engineering-technologyRuby001 weeks ago
17owasp/www-chapter-gandhinagarRuby012 weeks ago
18owasp/www-chapter-mendozaRuby00Yesterday
19owasp/www-chapter-windhoekRuby002 weeks ago
20owasp/www-chapter-williamnagarRuby003 weeks ago
21owasp/OWASP-ResolveLabs003 weeks ago
22owasp/www-chapter-valenciaRuby003 weeks ago
23owasp/www-chapter-atme-college-of-engineering-mysuru

ATME College of Engineering, Mysuru

Ruby00Today
24owasp/OWASP-Integrity-Pipeline-Validation-and-Control011 months ago
25owasp/OWASP-Model-Card-Security-Standard011 months ago
26owasp/OWASP-Top-10-AI-Infrastructure-Security-Risks003 weeks ago
27owasp/SCATO001 months ago
28owasp/Offensive-Fraud-Prevention-Testing-Framework001 months ago
29owasp/OWASP-MCP-Threat-Modeling001 months ago

Next step after the organization read

Open a flagship repository, compare a couple of portfolio leaders, or return to the organization map when you want a broader concentration read.
Open flagship repoCompare repositoriesBack to organizations

Learn and methodology

Keep trust-building context reachable, but behind the first data read instead of ahead of it.
GuideMethodologyArticlesWeekly Digest

How to read this organization snapshot

Total stars are useful as a discovery signal, but they do not tell you whether a team maintains every repository equally. Pair this page with release cadence, maintainer activity, and the flagship concentration shown above before making adoption decisions.

For broader background on GitStar's ranking logic and editorial guidance, see Methodology & Editorial Standards.