Skip to content

Add OWASP WSTG (Web Security Testing Guide) support #15676

Description

@mojtaba13133

DefectDojo currently has no support for OWASP WSTG at all, unlike ASVS which is already integrated as a selectable methodology/checklist.

It would be great to add full WSTG support so that, in the "Web Pentest" section, users could select the WSTG methodology and fill out the checklist per test category, similar to how ASVS works now.

This would help in a few ways:

  • Findings could be mapped directly to WSTG test categories/IDs, making reports more structured and easier to understand.
  • It would give a clearer connection between the actual pentest methodology used and the findings recorded in the system.
  • Reporting and finding management would be much easier, since testers could track coverage against the WSTG checklist directly instead of doing it manually outside DefectDojo.

Ideally the checklist/descriptions would be pulled/linked directly from the official OWASP WSTG source so it stays accurate and up to date:

I know this isn't a small change — WSTG has a lot more test categories/sub-items than ASVS and would need proper data modeling, UI work, and mapping logic. But given how commonly WSTG is used for web pentests, having it as a native methodology (like ASVS) would be a big improvement for reporting and finding management.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions