awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to owasp/wrongsecrets

Open-source alternatives to Wrongsecrets

25 open-source projects similar to owasp/wrongsecrets, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Wrongsecrets alternative.

  • b3nac/injuredandroidB3nac avatar

    B3nac/InjuredAndroid

    751View on GitHub↗

    A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

    Kotlin
    View on GitHub↗751
  • bkimminich/juice-shopB

    bkimminich/juice-shop

    0View on GitHub↗
    View on GitHub↗0
  • bridgecrewio/cfngoatbridgecrewio avatar

    bridgecrewio/cfngoat

    97View on GitHub↗

    Cfngoat is Bridgecrew's "Vulnerable by Design" Cloudformation repository. Cfngoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    View on GitHub↗97
  • bridgecrewio/terragoatbridgecrewio avatar

    bridgecrewio/terragoat

    1,289View on GitHub↗

    TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

    HCLaws-securityazure-securitycloud-security
    View on GitHub↗1,289
  • chromium/badssl.comchromium avatar

    chromium/badssl.com

    3,026View on GitHub↗

    Visit badssl.com for a list of test subdomains, including:

    HTML
    View on GitHub↗3,026
  • chuckfw/owaspbwachuckfw avatar

    chuckfw/owaspbwa

    310View on GitHub↗

    OWASP Broken Web Applications Project

    PHP
    View on GitHub↗310

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • cider-security-research/cicd-goatcider-security-research avatar

    cider-security-research/cicd-goat

    2,274View on GitHub↗

    A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

    Python
    View on GitHub↗2,274
  • defectdojo/django-defectdojoDefectDojo avatar

    DefectDojo/django-DefectDojo

    4,528View on GitHub↗

    DefectDojo is a vulnerability management system and application security orchestration tool. It serves as a centralized platform for importing, deduplicating, and tracking security findings from multiple scanners and tools to manage an organization's overall security posture. The system distinguishes itself by aggregating findings from various security tools into a single report and normalizing that data to prioritize remediation. It provides specific workflows for vulnerability triage and deduplication to reduce noise and redundant manual work across the software development lifecycle. The

    HTMLanalyticsappsecautomation
    View on GitHub↗4,528
  • dineshshetty/android-insecurebankv2dineshshetty avatar

    dineshshetty/Android-InsecureBankv2

    1,444View on GitHub↗

    Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities

    Java
    View on GitHub↗1,444
  • fuzzstati0n/fuzzgoatfuzzstati0n avatar

    fuzzstati0n/fuzzgoat

    207View on GitHub↗

    A vulnerable C program for testing fuzzers.

    C
    View on GitHub↗207
  • hackademic/hackademicHackademic avatar

    Hackademic/hackademic

    325View on GitHub↗

    the main hackademic code repository

    PHP
    View on GitHub↗325
  • jackmannino/owasp-goatdroid-projectjackMannino avatar

    jackMannino/OWASP-GoatDroid-Project

    254View on GitHub↗

    This project is no longer maintained OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and testers on Android security. GoatDroid requires minimal dependencies and is ideal for both Android beginners as well as more advanced users. The project currently includes two applications: FourGoats, a location-based social network, and Herd Financial, a mobile banking application. There are also several feature that greatly simplify usage within a training environment or for absolute beginners who want a good introduction to working with the Androi

    Java
    View on GitHub↗254
  • jaiswalakshansh/vuldroidjaiswalakshansh avatar

    jaiswalakshansh/Vuldroid

    68View on GitHub↗

    Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code

    Java
    View on GitHub↗68
  • juice-shop/juice-shopjuice-shop avatar

    juice-shop/juice-shop

    12,530View on GitHub↗

    Juice Shop is a self-contained web application designed as a platform for cybersecurity education and security training. It functions as a controlled environment containing intentional security flaws, allowing users to practice offensive security techniques and defensive coding practices while tracking their progress through a live scoreboard. The platform serves as an industry-standard benchmark for evaluating the effectiveness and detection accuracy of automated security scanning tools. By hosting a standardized set of known vulnerabilities and common attack patterns, it provides a reliable

    TypeScript24pullrequestsapplication-securityappsec
    View on GitHub↗12,530
  • madhuakula/kubernetes-goatmadhuakula avatar

    madhuakula/kubernetes-goat

    5,686View on GitHub↗

    Kubernetes Goat is a security training environment designed for practicing the identification and exploitation of common vulnerabilities within an intentionally insecure cluster. It provides a controlled setting to simulate system exploitations, including container escapes, role misconfigurations, and server-side requests. The project utilizes scenario-based vulnerability deployment to create specific security flaws. It includes utilities for environment management that allow the cluster to be restored to a clean baseline by removing vulnerable scenarios, service accounts, and role bindings.

    HTML
    View on GitHub↗5,686
  • optiv/insecureshopoptiv avatar

    optiv/insecureshop

    257View on GitHub↗

    An Intentionally designed Vulnerable Android Application built in Kotlin.

    Kotlin
    View on GitHub↗257
  • oversecured/ovaaoversecured avatar

    oversecured/ovaa

    747View on GitHub↗

    Oversecured Vulnerable Android App

    Java
    View on GitHub↗747
  • owasp/nodegoatowasp avatar

    owasp/nodegoat

    2,051View on GitHub↗

    The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

    HTML
    View on GitHub↗2,051
  • owasp/securityshepherdOWASP avatar

    OWASP/SecurityShepherd

    1,448View on GitHub↗

    Web and mobile application security training platform

    Java
    View on GitHub↗1,448
  • payatu/diva-androidpayatu avatar

    payatu/diva-android

    1,115View on GitHub↗

    DIVA Android - Damn Insecure and vulnerable App for Android

    Java
    View on GitHub↗1,115
  • rapid7/metasploitable3rapid7 avatar

    rapid7/metasploitable3

    5,592View on GitHub↗

    Metasploitable3 is an automated virtual machine provisioner designed to build and deploy operating system images with intentional security weaknesses. It functions as a penetration testing lab by creating vulnerable virtual machine targets used for security training, exploit development, and the validation of security tools. The system uses configuration scripts to inject vulnerabilities into Windows and Linux environments. This includes the deployment of insecure applications and services, such as web servers and databases, and the application of misconfigured system permissions to simulate

    HTML
    View on GitHub↗5,592
  • stamparm/dsvwstamparm avatar

    stamparm/DSVW

    869View on GitHub↗

    Damn Small Vulnerable Web

    Python
    View on GitHub↗869
  • stephenbradshaw/vulnserverstephenbradshaw avatar

    stephenbradshaw/vulnserver

    1,120View on GitHub↗

    Vulnerable server used for learning software exploitation

    C
    View on GitHub↗1,120
  • vulhub/vulhubvulhub avatar

    vulhub/vulhub

    20,279View on GitHub↗

    Vulhub is a collection of pre-configured, containerized applications designed to serve as a standardized platform for security research, vulnerability testing, and educational exploitation exercises. It functions as an orchestration framework that enables users to deploy isolated software environments for the purpose of practicing penetration testing and analyzing common security flaws in a controlled setting. The project utilizes an infrastructure-as-code pattern to define complex, multi-service software stacks, ensuring that testing targets remain consistent and reproducible. By leveraging

    Dockerfiledockerdocker-composedockerfile
    View on GitHub↗20,279
  • webgoat/webgoatWebGoat avatar

    WebGoat/WebGoat

    9,160View on GitHub↗

    WebGoat is a deliberately insecure web application designed as an interactive security lab for learning how to identify and exploit common web vulnerabilities. It serves as a containerized sandbox that allows for the simulation and experimentation of web-based attacks and penetration testing techniques without risking production systems. The project functions as a learning lab that maps specific insecure coding patterns to structured lessons. It implements simulated server-side flaws to provide a hands-on environment for studying common security vulnerabilities and defensive coding practices.

    JavaScript
    View on GitHub↗9,160