awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to owasp/nodegoat

Open-source alternatives to Nodegoat

30 open-source projects similar to owasp/nodegoat, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Nodegoat alternative.

  • bkimminich/juice-shopB

    bkimminich/juice-shop

    0View on GitHub↗
    View on GitHub↗0
  • cider-security-research/cicd-goatcider-security-research avatar

    cider-security-research/cicd-goat

    2,274View on GitHub↗

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    Python
    View on GitHub↗2,274
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • zaproxy/zaproxyzaproxy avatar

    zaproxy/zaproxy

    15,293View on GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Java
    View on GitHub↗15,293
  • digininja/dvwadigininja avatar

    digininja/DVWA

    13,229View on GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    PHPdvwahackinginfosec
    View on GitHub↗13,229
  • wpscanteam/wpscanwpscanteam avatar

    wpscanteam/wpscan

    9,636View on GitHub↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Ruby
    View on GitHub↗9,636
  • medicean/vulappsMedicean avatar

    Medicean/VulApps

    3,781View on GitHub↗

    VulApps is a vulnerability lab orchestrator that provides managed container environments. It delivers a curated suite of containerized security tools and applications with known security flaws for use in penetration testing sandboxes and exploit research. The project focuses on the rapid deployment of isolated environments designed for practicing security attacks and verifying vulnerability patches. It includes a collection of Docker-based vulnerable application environments and pre-configured toolsets for security auditing. The system covers the orchestration of container deployments to sim

    Shellcvedockerstruts
    View on GitHub↗3,781
  • chromium/badssl.comchromium avatar

    chromium/badssl.com

    3,026View on GitHub↗

    Visit badssl.com for a list of test subdomains, including:

    HTML
    View on GitHub↗3,026
  • ctfd/ctfdCTFd avatar

    CTFd/CTFd

    6,523View on GitHub↗
    Pythonctfctfdeducation
    View on GitHub↗6,523
  • bridgecrewio/terragoatbridgecrewio avatar

    bridgecrewio/terragoat

    1,289View on GitHub↗

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    HCLaws-securityazure-securitycloud-security
    View on GitHub↗1,289
  • defectdojo/django-defectdojoDefectDojo avatar

    DefectDojo/django-DefectDojo

    4,528View on GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    HTMLanalyticsappsecautomation
    View on GitHub↗4,528
  • lirantal/npm-security-best-practiceslirantal avatar

    lirantal/npm-security-best-practices

    1,178View on GitHub↗

    This project provides a comprehensive framework for securing the software supply chain within the Node.js ecosystem. It focuses on mitigating risks associated with third-party dependencies by implementing technical controls and governance policies designed to prevent malicious code injection and ensure the integrity of the development environment. The guide distinguishes itself by offering specific hardening techniques for package management, such as disabling automatic execution of lifecycle scripts and enforcing strict registry-scoped dependency routing to prevent dependency confusion. It e

    awesomeawesome-listbest-practices
    View on GitHub↗1,178
  • dineshshetty/android-insecurebankv2dineshshetty avatar

    dineshshetty/Android-InsecureBankv2

    1,444View on GitHub↗

    Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

    Java
    View on GitHub↗1,444
  • b3nac/injuredandroidB3nac avatar

    B3nac/InjuredAndroid

    751View on GitHub↗

    A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

    Kotlin
    View on GitHub↗751
  • codingo/vhostscancodingo avatar

    codingo/VHostScan

    1,299View on GitHub↗

    A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

    Pythonbugbountyctf-toolsdiscovery-service
    View on GitHub↗1,299
  • fuzzstati0n/fuzzgoatfuzzstati0n avatar

    fuzzstati0n/fuzzgoat

    207View on GitHub↗

    A vulnerable C program for testing fuzzers.

    C
    View on GitHub↗207
  • codingo/nosqlmapcodingo avatar

    codingo/NoSQLMap

    3,304View on GitHub↗

    Automated NoSQL database enumeration and web application exploitation tool.

    Python
    View on GitHub↗3,304
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • hackademic/hackademicHackademic avatar

    Hackademic/hackademic

    325View on GitHub↗

    the main hackademic code repository

    PHP
    View on GitHub↗325
  • hightechsec/git-scannerHightechSec avatar

    HightechSec/git-scanner

    382View on GitHub↗

    A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public

    Shell
    View on GitHub↗382
  • jackmannino/owasp-goatdroid-projectjackMannino avatar

    jackMannino/OWASP-GoatDroid-Project

    254View on GitHub↗

    This project is no longer maintained OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security. GoatDroid requires minimal dependencies and is ideal for both Android beginners as well as more advanced users. The project currently includes two applications: FourGoats, a location-based social network, and Herd Financial, a mobile banking application. There are also several feature that greatly simplify usage within a training environment or for absolute beginners who want a good introduction to working with the Androi

    Java
    View on GitHub↗254
  • jaiswalakshansh/vuldroidjaiswalakshansh avatar

    jaiswalakshansh/Vuldroid

    68View on GitHub↗

    Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code

    Java
    View on GitHub↗68
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
  • kpcyrd/badtouchkpcyrd avatar

    kpcyrd/badtouch

    418View on GitHub↗

    Scriptable network authentication cracker

    Rust
    View on GitHub↗418
  • laxa/hackingtoolsL

    Laxa/HackingTools

    0View on GitHub↗
    View on GitHub↗0
  • ethicalhack3r/dvwaethicalhack3r avatar

    ethicalhack3r/DVWA

    13,236View on GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    PHP
    View on GitHub↗13,236
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • ekreloff/2c44e97183a74c32fdbb7d14aa8b30adE

    ekreloff/2c44e97183a74c32fdbb7d14aa8b30ad

    0View on GitHub↗
    View on GitHub↗0
  • ebookfoundation/free-programming-booksEbookFoundation avatar

    EbookFoundation/free-programming-books

    390,347View on GitHub↗

    This project is a centralized, open-access repository that serves as a structured directory for technical education and professional development. It functions as a community-driven knowledge base, aggregating high-quality learning materials to support global accessibility to computer science and software engineering resources. The platform distinguishes itself through a collaborative governance model that utilizes peer-reviewed workflows for all content additions and modifications. By leveraging structured text files and decentralized version control, the repository maintains a searchable, hu

    Pythonbookseducationhacktoberfest
    View on GitHub↗390,347