Why Play Cornucopia?

Welcome! If you're interested in building secure applications, you're at the right place! Playing Cornucopia not only sharpens your own security skills but it will help you transform the way your team approaches secure application development.

Real-World Security Challenges, Game-Style Solutions

Developed by cybersecurity experts, each Cornucopia card describes a real-world security challenge. The game is designed to help software developers to understand advanced security concepts in a fun way.

Continuous Learning, Simplified

We're committed to your growth. Our website is continuously updated with easy to understand guidance for each Cornucopia card. Your feedback is important for us, ensuring the resources we offer meet your needs.

Get Insights from our Blog

Dive into the nitty-gritty of Cornucopia and broader security practices through our blog posts. Got a question? Let us know, and we'll address it for you.

Interactive mapping

The cards provide interactive links to several standards. When possible, we make the links interactive. We have implemented ASVS and CAPEC.

We've also included the complete ASVS 4.0 standard on our website here: https://owasp.cornucopia.org/taxonomy/asvs-4.0.3

Get your Cornucopia Deck Now!

Fast-track your journey to becoming a security-savvy developer with Cornucopia. It's more than a game—it's a new lens through which to view secure application development.

want to get in touch?

Get in touch with us at our Github discussion forum

Good luck in playing cornucopia!

All authors

OWASP Cornucopia

  • OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It is language, platform and technology-agnostic, and is free to use.
  • OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar licence to this one.
  • © 2012-2025 OWASP Foundation. The Open Worldwide Application Security Project (OWASP) is a nonprofit foundation that works to improve the security of software.