Skip to content
View SachinAditya's full-sized avatar

Block or report SachinAditya

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
SachinAditya/README.md

๐Ÿ‘‹ Hi, I'm Sachin Vishwakarma (SachinAditya)

GitHub followers GSoC

๐ŸŽฏ Aspiring Cybersecurity Engineer | OWASP Contributor | GSoC 2026 Aspirant
๐Ÿ” Focused on Web Security, Open Source & Security Automation


๐Ÿš€ About Me

I am a cybersecurity enthusiast passionate about:

  • Web penetration testing
  • Open-source security tools
  • Writing clear, practical security documentation
  • Automating security testing workflows

I actively contribute to OWASP projects and am preparing for Google Summer of Code (GSoC) 2026 with a strong focus on real-world security tooling.


๐ŸŽฏ GSoC 2026 Focus

I am actively preparing for Google Summer of Code 2026, with a primary interest in:

  • OWASP Dependency-Check
  • OWASP WSTG
  • OWASP tooling & documentation automation

My focus areas:

  • Improving security tooling reliability
  • Documentation โ†’ code alignment
  • Reducing false positives & improving developer experience

I am currently working on issues, PR reviews, and design discussions related to these areas.


๐Ÿ† Open Source Contributions

โœ… OWASP Dependency-Check

  • ๐Ÿ“˜ Documentation: External data sources & hostnames โ€” #8219
  • Documented all external data sources and hostnames contacted by Dependency-Check based on enabled analyzers and configuration
  • Added a clear, auditable table to help organizations with restricted or air-gapped networks create accurate allow-lists
  • Verified hostnames directly from the codebase and clarified indirect vs analyzer-specific network access
  • Improved enterprise adoption and reduced recurring support questions
  • Merged into main and included in release milestone 12.2.1

๐Ÿ”น OWASP ZAP API Docs

  • โœ๏ธ Improve API docs (ToC, guidance) โ€” #247
  • Added general guidance for using the ZAP API with curl, addressing common pitfalls such as parameter encoding and boolean handling
  • Improved API usability without modifying generated or endpoint-specific documentation
  • Incorporated maintainer feedback to keep the change narrowly scoped and maintainable
  • Reduced recurring user errors when interacting with the ZAP API via curl

๐Ÿงช OWASP WSTG (Web Security Testing Guide)

  • ๐Ÿ“ Fixed outdated cache-control security guidance by aligning recommendations with modern browser behavior and current best practices (e.g., Cache-Control: no-store), improving the accuracy of security testing outcomes and reducing tester confusion. #1291

๐ŸŽด OWASP Cornucopia (Mobile App Edition)

๐ŸŽฎ Playful STRIDE-aligned AA4 card description โ€” #2113

  • Authored a humorous, scenario-driven threat description aligned with MASVS and MASTG
  • Followed established STRIDE categorization patterns (AA2/AA3 examples)
  • Reviewed and merged by project maintainers

โš™๏ธ OWASP OWTF (Active Contributions)

  • Platform-related improvements across backend and frontend components
    PRs currently under maintainer review

๐Ÿ“… January 2026: 4 merged PRs across OWASP projects

๐Ÿ› ๏ธ Security Projects & Tools

๐Ÿ”น Repository: security-writeups
Includes:

  • Vulnerability write-ups (PDFs)
  • Header scanning tool
  • URL parameter discovery script
  • OWASP ZAP automation scripts

๐Ÿ”— https://github.com/SachinAditya/security-writeups


๐ŸŽฏ Technical Interests

  • Web Penetration Testing (OWASP Top 10)
  • XSS, SQLi, IDOR, CSRF, SSRF
  • Recon & vulnerability discovery
  • OWASP ZAP automation
  • Secure coding practices

โš–๏ธ Ethics

All security research and testing is performed only on:

  • Legal labs
  • Test environments
  • Systems with explicit permission

No illegal or unauthorized testing.


๐Ÿ“ซ Connect with Me

โญ Always open to collaboration, open-source contributions, and security discussions.


๐Ÿ“Š GitHub Stats

Stats

๐Ÿง  Top Languages

Languages

๐Ÿ”ฅ Contribution Streak

Streak

๐Ÿ›  Skills & Tools

Python Linux Burp Suite OWASP Git


Profile Views

Pinned Loading

  1. security-writeups security-writeups Public

    Write-ups and PoCs for security vulnerabilities and web penetration testing as part of my GSoC 2026 preparation.

    Python 1

  2. DependencyCheck DependencyCheck Public

    Forked from dependency-check/DependencyCheck

    OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

    Java 1

  3. mini-xss-scanner mini-xss-scanner Public

    Lightweight reflected XSS scanner for educational and authorized testing

    Python 1

  4. dependency-check/DependencyCheck dependency-check/DependencyCheck Public

    OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

    Java 7.4k 1.4k

  5. zaproxy/zap-api-docs zaproxy/zap-api-docs Public

    ZAP API Documentation

    JavaScript 39 30