OWASP FOUNDATION

The nonprofit that stewards the world's application-security vocabulary — put on notice, in writing, by its own founder.

OPERATION
Application-security standards and open-source tools — the OWASP Top 10, ZAP, and hundreds of projects, largely volunteer-built FACT
HABITAT
Every compliance checklist on earth that says "OWASP Top 10"
EVENT
Open letter to the Board, February 2023 — 80+ signatories including OWASP founder Mark Curphey and the leaders of ZAP, SAMM, CycloneDX, Juice Shop, and dependency-check FACT
PATTERN
"Year after year, concerns have been raised and there have been promises of change, but year after year it hasn't happened" — the letter's words FACT
DISPOSITION
FLAGSHIP DEPARTED — ZAP, the world's most-used web app scanner, left OWASP for the Software Security Project, August 2023 FACT

Here is the standards body — the animal that tells the rest of the internet what secure looks like — observed by its own founder failing, "year after year" by its own community's account, to feed the projects that made it famous.

Official channel: @owasp. From the Foundation's formal response to the open letter (Andrew van der Stock, Executive Director, March 10, 2023): "...if it were easy to spend five times our total annual budget on projects alone, it would have already been done."Strategic Plan 2023 — an update for the open letter

OWASP is why application security has a shared language. The Top 10 is cited in contracts, regulations, and compliance regimes worldwide; ZAP was the free scanner every tester reached for. The Foundation behind them runs conferences, chapters, and infrastructure — and its stated model funds that apparatus, not project payroll.

What the archive marks here is not theft — nobody alleges theft — but the gap the community itself documented: the tools that justify the brand ran on nights and weekends while the brand banked the conference revenue. Every claim carries its receipt; the defense gets equal time.

the drama timeline

ACT I — THE LEDGER AND THE LETTER

The complaint did not arrive from outsiders. It arrived signed by the people who built the place, including the man who named it.

  1. FY 2021

    The Foundation's own budget math

    OWASP's published 2021 budget forecasts 68.1% of spend on programming. Community critics would later set that beside cash balances of nearly $3 million and $5,368 of income generated for flagship projects — the projects being the reason anyone funds OWASP at all.

  2. FEB 2023

    The open letter

    More than 80 contributors — including founder Mark Curphey, early advisory board member John Viega, and the leaders of ZAP, SAMM, CycloneDX, Juice Shop, and dependency-check — publish an open letter to the Board: "Year after year, concerns have been raised and there have been promises of change, but year after year it hasn't happened. The gap between what our projects and the community around them want, and the support that OWASP provides, continues to grow wider." The ask: "in the region of five to ten million dollars per year for our projects alone." The deadline: 30 days.

    Observe the rarity. Most institutions are denounced by rivals. This one was denounced by its own founder, in a document engineered to be citable.

ACT II — THE ANSWER (MAR 2023)

The Board answers inside its 30 days. The answer is the defense's best exhibit, so read it whole.

  1. MAR 10 2023

    "Strategic Plan 2023" — the Board responds

    Executive Director Andrew van der Stock publishes the Foundation's response: funding discussions are "in the early stages," and — the load-bearing sentence — "if it were easy to spend five times our total annual budget on projects alone, it would have already been done." The post details reforms already made: project and chapter balances eliminated in 2020–2021, project grants reformed, and in 2022, "for the first time in OWASP's history, projects outspent chapters — and spent nearly double that of chapters."

    Per CSO Online's reporting, a former board member calls the open letter "tone deaf" to OWASP's actual financial situation — the demand exceeded the treasury several times over.

ACT III — THE EXODUS (AUG 2023)

Five months later, the letter's author acts on its warning. The world's most popular web scanner packs its bags.

  1. AUG 1 2023

    ZAP leaves

    The ZAP team — whose founder Simon Bennetts created the open letter — announces ZAP is joining the Software Security Project as a founding project. The stated reason, in the project's own words: OWASP had "struggled to support and invest in projects, especially big projects," while ZAP "competes with commercial projects that have huge investments. We need much more investment in order to thrive." After the move, people work on ZAP full-time — a first in the project's history. "OWASP ZAP" will be known as just "ZAP."

    The costly signal, priced precisely: the maintainers surrendered the most recognizable brand prefix in application security rather than keep the arrangement — and were funded full-time almost immediately, elsewhere.

  2. EPILOGUE

    Still the standard

    OWASP operates today. The Top 10 remains the most-cited document in application security, and the letter's signatories asked for OWASP to evolve, not dissolve. The archive notes both facts without irony. Almost.

both sides, on the record

The starvation ledger (the critics' framing, from OWASP's own numbers): nearly $3 million in cash; $5,368 of income generated for flagship projects; 68.1% of budget to programming [4] [6].

The founder signed the complaint. "Year after year… promises of change, but year after year it hasn't happened" — 80+ signatories, including the man who started OWASP [1].

The flagship left and thrived. ZAP departed citing under-investment, and got its first-ever full-time staffing within the month — elsewhere [3].

The demand exceeded the treasury several times over. The letter asked for $5–10 million a year for projects alone; the Foundation's answer: "if it were easy to spend five times our total annual budget on projects alone, it would have already been done." You cannot misallocate money you do not have [2].

The model funds infrastructure, not payroll — chapters, conferences, community plumbing — and it was already reforming: balances eliminated in 2020–21, grants restructured, and in 2022 projects outspent chapters for the first time in OWASP's history, nearly two-to-one [2].

No misconduct is alleged by anyone. A former board member called the letter "tone deaf" to the actual finances; the dispute is priorities, publicly argued between people who all want OWASP to exist. It remains the industry-standard Top 10 steward [5].

YOU DECIDE

Scoped to the claims. The letter, the budget figures, and the departure are all on the record in the participants' own publications. Whether the story is "a foundation hoarding $3 million while its crown jewels starved" or "a volunteer community demanding ten times the budget that existed" is genuinely contested — and both readings are in evidence above.

Weigh the costly signal: the people who built the most-used tool gave up the brand rather than keep the deal. Weigh the defense the same way: the Foundation published its budgets, answered inside the deadline, and kept the lights on. Institutions rarely fail loudly; this one at least failed in writing, with receipts on both sides.

The archive does not judge. It keeps the correspondence.

evidence locker

PRIMARY & FIRST-PARTY

  1. The open letter to the OWASP Board of Directors (Feb 2023, full text and signatories) FACT — the complaint, in the community's own words. owasp-change.github.io
  2. OWASP Foundation — "Strategic Plan 2023 — an update for the open letter" (Mar 10, 2023) SELF-PUBLISHED — the Board's response and budget rebuttal, verbatim. owasp.org/blog/2023/03/10/strategic-plan-open-letter-update.html
  3. ZAP — "ZAP is Joining the Software Security Project" (Aug 1, 2023) FACT — the departing project's own account of why. zaproxy.org/blog/2023-08-01-zap-is-joining-the-software-security-project/
  4. OWASP Foundation — 2021 budget documentation SELF-PUBLISHED — the 68.1% programming figure, from the source. owasp.org/www-staff/budget/2021

PRESS & ANALYSIS

  1. CSO Online — "Open letter demands OWASP overhaul, warns of mass project exodus" (Feb 2023) ATTRIBUTED — the Bennetts interview, the "tone deaf" former-board-member line, the 68.1% context. csoonline.com/article/574663/…
  2. Security Boulevard — "Is a Project Exodus From OWASP Looming?" (Apr 2023) ATTRIBUTED — the $5,368-vs-$3M reading of OWASP's financial statements. securityboulevard.com/2023/04/is-a-project-exodus-from-owasp-looming/
The standard. Every load-bearing document here is first-party: the community's letter, the Foundation's response, the departing project's own announcement, the Foundation's own budget. The $5,368-vs-$3-million framing is stated as Security Boulevard's reading of those financials, not as our discovery. No fraud, theft, or self-dealing is alleged by anyone in this record, and none is implied by us. The defense — including the budget-scale rebuttal in the Foundation's favor — is presented at full strength. If it couldn't survive a defamation challenge, it wouldn't be on this page.