hatchmoment. scored by care · not by stars

VulnerableApp

OWASP VulnerableApp – modular vulnerable app for scanner benchmarking

VulnerableApp offers a deliberately vulnerable web application that mimics modern attack surfaces, enabling security engineers to benchmark scanners like ZAP or Burp Suite. Its modular design lets users add new vulnerability scenarios without touching core code, ensuring reproducible test results. The project includes Docker images and a standalone JAR for easy deployment, making it suitable for labs, CI pipelines, and teaching environments. Compared to static vulnerable apps, it provides deterministic behavior and extensibility for continuous security testing.

View on GitHub →

ctf-in-a-box-test/VulnerableApp