Introduction
Owasp.Analyzers is a collection of Roslyn diagnostic analyzers that surface OWASP Top 10 2025 security vulnerabilities as compiler warnings and errors in your C#/.NET projects.
How it works
Roslyn analyzers run inside the compiler pipeline — no external tools, no CI-only scans. Every build checks your code against the rules. Violations appear inline in your IDE (Visual Studio, Rider, VS Code) and as dotnet build output, exactly like ordinary compiler warnings.
warning OWASPA01001: Action 'GetProfile' is not decorated with [Authorize] or [AllowAnonymous]
error OWASPA05001: User-controlled data flows into SQL command without parameterization
Coverage
| Category | Rules | Technique |
|---|---|---|
| A01 Broken Access Control | 8 | Syntax / Semantic / Taint analysis |
| A02 Security Misconfiguration | 6 | Syntax |
| A03 Software Supply Chain Failures | 2 | MSBuild target |
| A04 Cryptographic Failures | 8 | Syntax / Semantic |
| A05 Injection | 6 | Taint analysis |
| A06 Insecure Design | 1 | Syntax |
| A07 Authentication Failures | 5 | Semantic |
| A08 Software or Data Integrity Failures | 4 | Semantic |
| A09 Security Logging and Alerting Failures | 2 | Syntax / Taint analysis |
| A10 Mishandling of Exceptional Conditions | 2 | Syntax |