Portfolio concentration
91%
Top three share
Shows whether the organization is driven by one breakout repo or several visible projects.
Breadth
29 repos
Visible snapshot
29 repositories updated in the last 90 days.
Leading language
Ruby
Portfolio mix
Ruby (14), Unknown (11), Python (3)
Average size
5
Stars per repository
Useful for distinguishing one flagship-heavy publisher from a repeatable portfolio.
91%
of the visible star count comes from this organization's top three repositories.
5
stars per repository in this same snapshot.
Ruby
is the most common language here, with 29 repositories updated in the last 90 days.
Why this rank
This organization stands out because one flagship repo drives 60% of its visible star count.
Organization pages work best when you separate portfolio breadth from flagship concentration. In OWASP's case, the visible top three repositories account for about 91% of total stars in this snapshot, which helps explain whether the organization is known for one breakout project or for a broader repeatable portfolio.
The dominant language mix here is Ruby (14), Unknown (11), Python (3). That makes this page useful not just for popularity checks, but also for seeing what technical shape an organization's public ecosystem actually has.
| # | Repository | Language | Stars |
|---|---|---|---|
| 1 | owasp/OWASP-MCP-Governance-and-Risk-Project A practical governance framework for organizations adopting the Model Context Protocol (MCP), the open standard that lets AI agents connect to external tools, data sources, and systems. | 84 | |
| 2 | owasp/OWASP-Subtractive-Hardening-Top-10 The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber risk through the elimination of attack paths. | 28 | |
| 3 | owasp/VulnReach Runtime-aware SCA โ proves which CVEs are actually reachable, not just installed. | Python | 14 |
| 4 | owasp/OWASP-OpenShield | 3 | |
| 5 | owasp/Community-Security-Prompts | HTML | 2 |
| 6 | owasp/www-chapter-garhwal | Ruby | 1 |
| 7 | owasp/www-chapter-almaty | Ruby | 1 |
| 8 | owasp/www-chapter-iit-gandhinagar | Ruby | 1 |
| 9 | owasp/www-chapter-pamplona | Ruby | 1 |
| 10 | owasp/www-chapter-chandigarh-university-mohali | Ruby | 1 |
| 11 | owasp/TriSuElla-AIDLCA-Framework The OWASP TriSuElla-AIDLCA Framework is a production-ready, policy-governed secure software development life cycle (SDF) and autonomous agent governance framework (LLMSecOps) built on the Nordic resilience principles of SISU (hardened architecture), TILLIT (zero-trust verification), and DUGNAD (dual-key human-in-the-loop oversight). | Python | 1 |
| 12 | owasp/OWASP-Open-Source-Intelligence-Standard OOVS, the OWASP OSINT Verification Standard. Ten requirements, one acceptance test each, in prose and machine-readable form. | Python | 1 |
| 13 | owasp/Citizen-Vibe-Coder-Security-Model | 1 | |
| 14 | owasp/www-chapter-kinnaur | Ruby | 0 |
| 15 | owasp/www-chapter-north-dakota-state-university | Ruby | 0 |
| 16 | owasp/www-chapter-kgreddy-college-engineering-technology | Ruby | 0 |
| 17 | owasp/www-chapter-gandhinagar | Ruby | 0 |
| 18 | owasp/www-chapter-mendoza | Ruby | 0 |
| 19 | owasp/www-chapter-windhoek | Ruby | 0 |
| 20 | owasp/www-chapter-williamnagar | Ruby | 0 |
| 21 | owasp/OWASP-ResolveLabs | 0 | |
| 22 | owasp/www-chapter-valencia | Ruby | 0 |
| 23 | owasp/www-chapter-atme-college-of-engineering-mysuru ATME College of Engineering, Mysuru | Ruby | 0 |
| 24 | owasp/OWASP-Integrity-Pipeline-Validation-and-Control | 0 | |
| 25 | owasp/OWASP-Model-Card-Security-Standard | 0 | |
| 26 | owasp/OWASP-Top-10-AI-Infrastructure-Security-Risks | 0 | |
| 27 | owasp/SCATO | 0 | |
| 28 | owasp/Offensive-Fraud-Prevention-Testing-Framework | 0 | |
| 29 | owasp/OWASP-MCP-Threat-Modeling | 0 |
Total stars are useful as a discovery signal, but they do not tell you whether a team maintains every repository equally. Pair this page with release cadence, maintainer activity, and the flagship concentration shown above before making adoption decisions.
For broader background on GitStar's ranking logic and editorial guidance, see Methodology & Editorial Standards.