awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
WebGoat avatar

WebGoat/WebGoat

0
View on GitHub↗
9,160 stars·7,783 forks·JavaScript·15 viewsowasp.org/www-project-webgoat↗

WebGoat

WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems.

The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

The application supports deployment through isolated containers and browser-based desktop virtualization to ensure a consistent attack surface. It includes capabilities for managing lesson availability and tracking user progress across the various vulnerable application components.

Features

  • Vulnerable Web Applications - Ships a deliberately insecure web application designed with security flaws for training and penetration testing.
  • Cybersecurity Training Materials - Provides a risk-free space for students to experiment with web attacks using cybersecurity training materials.
  • Vulnerability Simulations - Implements intentionally broken backend logic to mirror real-world security vulnerabilities within a controlled environment.
  • Vulnerable Lab Environments - Runs isolated, insecure application environments using Docker to study vulnerabilities and their remediation.
  • Container-Based Sandboxes - Wraps vulnerable application environments in isolated containers to prevent host system compromise during exploitation.
  • Penetration Testing and Ethical Hacking - Provides a lab environment for applying hacking techniques and tools against a deliberately insecure application.
  • Containerized Security Environments - Provides a containerized security environment for safely simulating and experimenting with web-based attacks.
  • Curricula Mapping - Maps specific insecure coding patterns to structured lessons for security training and penetration testing practice.
  • Sandbox Deployment Tools - Provides utilities for launching isolated learning sandboxes via Docker or browser-based desktops.
  • Vulnerable Environments - Educational platform for learning web application security.
  • Vulnerable Applications - Deliberately insecure Java application for teaching web security lessons.
  • Vulnerable Test Targets - Interactive platform for learning web application security.
  • Vulnerable Applications - Educational platform for learning web application security.
  • Vulnerable Web Applications - Comprehensive learning platform for teaching OWASP web security vulnerabilities.

Star history

Star history chart for webgoat/webgoatStar history chart for webgoat/webgoat

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to WebGoat

Similar open-source projects, ranked by how many features they share with WebGoat.
  • ethicalhack3r/dvwaethicalhack3r avatar

    ethicalhack3r/DVWA

    13,236View on GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    PHP
    View on GitHub↗13,236
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    View on GitHub↗13,229
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
See all 30 alternatives to WebGoat→

Frequently asked questions

What does webgoat/webgoat do?

WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems.

What are the main features of webgoat/webgoat?

The main features of webgoat/webgoat are: Vulnerable Web Applications, Cybersecurity Training Materials, Vulnerability Simulations, Vulnerable Lab Environments, Container-Based Sandboxes, Penetration Testing and Ethical Hacking, Containerized Security Environments, Curricula Mapping.

What are some open-source alternatives to webgoat/webgoat?

Open-source alternatives to webgoat/webgoat include: ethicalhack3r/dvwa — DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable… digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… rapid7/metasploitable3 — Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with… juice-shop/juice-shop — Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security… audi-1/sqli-labs — sqli-labs is a collection of intentionally vulnerable web applications and sandbox environments designed for… hackademic/hackademic — the main hackademic code repository.