awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
juice-shop avatar

juice-shop/juice-shop

0
View on GitHub↗
12,530 stars·16,485 forks·TypeScript·mit·14 viewsowasp-juice.shop↗

Juice Shop

Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard.

The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable environment for validating the performance of security software and testing the capabilities of various vulnerability assessment tools.

The application manages these security challenges through a modular request-handling pipeline and an object-relational mapping layer that ensures consistent state across user interactions. It maintains a centralized registry of active vulnerabilities and uses event-driven updates to reflect progress in the user interface. The project is distributed as a complete, deployable web environment for training and testing purposes.

Features

  • Vulnerable Web Applications - Provides a deployable, intentionally vulnerable web application for security training and scanner testing.
  • Security Benchmarks - Acts as an industry-standard benchmark for validating the effectiveness of automated security scanning tools.
  • Cybersecurity Training Labs - Serves as a hands-on platform for students and professionals to practice offensive and defensive security techniques.
  • Automated Security Scanners - Provides a standardized environment for benchmarking the accuracy and detection capabilities of automated security scanning tools.
  • Security Challenges - Features an integrated scoreboard that tracks and validates user progress through various security challenges.
  • Hacking Skill Platforms - Platform for testing web security skills through diverse hacking challenges.
  • Security Training Labs - Modern, sophisticated insecure web application for security testing.
  • Vulnerable Applications - Modern web app designed to teach OWASP Top 10 vulnerabilities.
  • Vulnerable Web Applications - Extensive platform for testing web security skills with diverse challenges.
  • Vulnerability Assessment and Testing - Validates security software performance by simulating real-world attack patterns in a controlled environment.
  • Security Vulnerabilities - Hosts a collection of intentional security flaws to facilitate hands-on training and security tool validation.
  • Middleware-Based Request Pipelines - Processes incoming web traffic through a modular pipeline of security-focused middleware components.

Star history

Star history chart for juice-shop/juice-shopStar history chart for juice-shop/juice-shop

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Juice Shop

These projects share indexed features with Juice Shop. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • qazbnm456/awesome-web-securityqazbnm456 avatar

    qazbnm456/awesome-web-security

    13,097View on GitHub↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    awesomeawesome-listlist
    View on GitHub↗13,097
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    View on GitHub↗13,229
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160
  • samsar4/ethical-hacking-labsSamsar4 avatar

    Samsar4/Ethical-Hacking-Labs

    3,397View on GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    ethical-hacking-labshackinglinux
    View on GitHub↗3,397
Compare all 30 related projects→

Frequently asked questions

What does juice-shop/juice-shop do?

Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard.

What are the main features of juice-shop/juice-shop?

The main features of juice-shop/juice-shop are: Vulnerable Web Applications, Security Benchmarks, Cybersecurity Training Labs, Automated Security Scanners, Security Challenges, Hacking Skill Platforms, Security Training Labs, Vulnerable Applications.

Which projects share features with juice-shop/juice-shop?

Projects with overlapping indexed features include: qazbnm456/awesome-web-security — This project serves as a comprehensive cybersecurity training platform and resource repository focused on web… digininja/dvwa — DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws.… webgoat/webgoat — WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to… samsar4/ethical-hacking-labs — Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning… google/google-ctf — This project is a capture the flag platform and cybersecurity training environment. It provides a framework for… trimstray/the-book-of-secret-knowledge — This project serves as a centralized, community-driven repository of technical knowledge and administrative resources.…