Skip to content

OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, it supports analysis by Static (SAST), Dynamic (DAST), and Runtime (IAST) tools that support Java. The idea is that since it is fully runnable and all the vulnerabilities are actually exploitable, it’s a fair test for any kind of vulnerability detection tool. For more details on this project, please see the OWASP Benchmark Project home

active 2025-07-162025-12-03 (UTC)

Partial coverage19,697 / 25,357 hourly files (78%) · 2 absent upstream · 5,657 failed, retryable2023-09-212026-08-12 (UTC)— sampled evenly across the window, so rankings and trends hold; absolute counts scale up.
Events
72
Pushes
18
Pull requests
28
Issues
0
Stars
0
Forks
0

Activity over time

Daily event counts in the loaded window

Line chart, 141 days from 2025-07-16 to 2025-12-03. Pushes: 18 total, peak 6 in a day. Pull requests: 28 total, peak 8 in a day. Issues: 0 total, peak 0 in a day. Comments: 6 total, peak 3 in a day. Stars: 0 total, peak 0 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
FortiLatam4918282
lacework-code-security[bot]4004

Recent activity

Latest issues, pull requests and releases

  • Issue comment#31lacework-code-security[bot]2025-12-03 12:37
    Adding SQL file
  • Pull request#29FortiLatam2025-12-02 23:15
  • Pull request#28FortiLatam2025-12-02 23:12
  • Pull request#27FortiLatam2025-12-02 22:31
  • Pull request#26FortiLatam2025-12-02 22:22
  • Pull request#21FortiLatam2025-09-12 19:29
  • Pull request#19FortiLatam2025-09-12 17:21
  • Pull request#15FortiLatam2025-09-12 17:08
  • Pull request#16FortiLatam2025-09-12 17:08
  • Pull request#17FortiLatam2025-09-12 16:52
  • Pull request#16FortiLatam2025-09-12 16:45
  • Pull request#13FortiLatam2025-09-12 13:14
  • Pull request#13FortiLatam2025-09-12 13:11
  • Pull request#12FortiLatam2025-09-11 21:18
  • Pull request#11FortiLatam2025-09-11 20:45
  • Pull request#11FortiLatam2025-09-11 20:10
  • Pull request#10FortiLatam2025-09-11 19:56
  • Pull request#10FortiLatam2025-09-11 19:40
  • Issue comment#9lacework-code-security[bot]2025-07-17 17:40
    Test dependency for ruleset
  • Issue comment#8FortiLatam2025-07-17 17:18
    Update pom.xml for testing
  • Pull request#8FortiLatam2025-07-17 17:18
  • Issue comment#7FortiLatam2025-07-17 17:18
    Update pom.xml
  • Pull request#7FortiLatam2025-07-17 17:18
  • Pull request#2FortiLatam2025-07-17 17:17
  • Pull request#8FortiLatam2025-07-17 16:16

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.