A deliberately vulnerable web application for learning web application security.
☆161Apr 28, 2025Updated last year
Alternatives and similar repositories for OWASPWebGoatPHP
Users that are interested in OWASPWebGoatPHP are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security. G…☆28Sep 25, 2012Updated 13 years ago
- OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws☆330Jul 30, 2024Updated last year
- OWASP WebGoat.NET☆73Aug 20, 2015Updated 10 years ago
- OWASP Findings Format☆19Mar 4, 2021Updated 5 years ago
- OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS☆451Dec 29, 2025Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Repository for OWASP Code Review document☆17Jun 24, 2014Updated 12 years ago
- The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Nod…☆2,055Jun 15, 2024Updated 2 years ago
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner☆12Apr 22, 2018Updated 8 years ago
- Securibench Micro is a benchmark for static analysis tools for security.☆27Jul 26, 2018Updated 7 years ago
- *This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating develo…☆256Jul 29, 2014Updated 11 years ago
- A set of XSS vulnerable PHP scripts for testing☆38Feb 10, 2013Updated 13 years ago
- OWASP Foundation Web Respository☆20Oct 8, 2025Updated 9 months ago
- Priv8 Tools Offensive Security WordPress_AutoExploiter☆29Apr 17, 2022Updated 4 years ago
- The Last Web Recon Tool You'll Need☆17Nov 7, 2020Updated 5 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.☆32Oct 3, 2022Updated 3 years ago
- A honeypot that can be used to observe traffic directed at home routers.☆21Nov 14, 2018Updated 7 years ago
- ☆11Mar 19, 2022Updated 4 years ago
- LAPSE+ is a security scanner, based on the white box analysis of code for detecting vulnerabilities in Java EE Applications.☆27Feb 2, 2018Updated 8 years ago
- flask-webgoat is a deliberately-vulnerable application written with the Flask web framework.☆19Sep 5, 2025Updated 10 months ago
- Accepts a domain name and queries multiple sources to return subdomains. Includes option to scan the returned subdomains to check connect…☆14Aug 9, 2019Updated 6 years ago
- OWASP Serverless Top 10☆217Jul 6, 2021Updated 5 years ago
- This repository holds a target infrastructure you can use for running the nimbostratus tools.☆24Mar 9, 2015Updated 11 years ago
- whois.cynthia.re V2☆14May 23, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This is a defunct code base. The project is located at: https://github.com/WebGoat☆54Jul 20, 2016Updated 10 years ago
- Monitors and curates bug-bounty related repositories weekly (Monday).☆20Updated this week
- a Damn Vulnerable Serverless Application☆545Sep 12, 2023Updated 2 years ago
- apkfram was written in order to help any mobile penetration testers to identify the Framework used to develop the Android application.☆12Oct 9, 2024Updated last year
- Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection☆22Sep 15, 2024Updated last year
- OWASP Python Security Project☆412Nov 23, 2021Updated 4 years ago
- Many companies are utilizing the cloud for their day to day activities. Many big cloud service providers like AWS, Microsoft Azure have b…☆11Nov 13, 2022Updated 3 years ago
- Vulnerable Java based Web Application☆276May 10, 2026Updated 2 months ago
- Run Capture the Flags and Security Trainings with OWASP WrongSecrets☆55Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Handy scripts and one-liners to make life easier☆39Mar 6, 2023Updated 3 years ago
- Fake-Out : Fake-Out is an email spoofing tool created by HackEthics138, with security measures provided by Team Illusion. Thi…☆12Aug 19, 2024Updated last year
- Deliberately vulnerable PHP code examples for testing static analysis tools and security training, covering common vulnerabilities such a…☆15May 1, 2026Updated 2 months ago
- ☆18Sep 18, 2025Updated 10 months ago
- vuln-netframework is a .net-framework 4.7 project that include worst coding practices about common vulnerabilities like Insecure Deserial…☆10Nov 9, 2025Updated 8 months ago
- This is a container of web applications that work with OWASP Bug Bounty for Projects☆34Apr 28, 2025Updated last year
- 12-week Geekwise course on web application security and hardening.☆17Mar 19, 2020Updated 6 years ago