# chromium/badssl.com

:lock: Memorable site for testing clients against bad SSL configs.

Repository: https://github.com/chromium/badssl.com
Canonical: https://ross.abutalabs.com/products/badsslcom
Homepage: https://badssl.com
Language: HTML
License: Apache-2.0
License Family: permissive
Topics: ssl, https, sha1, tls, rcpp, python, testing, browser, chrome, nginx, security, mitm
Last push: 2026-06-01T22:42:57+00:00

## Health v2 (maintenance only)
Score: 70/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 85, release rhythm 35, longevity 100
- inputs: {"age_days": 4166, "days_push": 93, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 3043, forks 205 (observed 2026-08-28T04:07:39.392638+00:00)

## What it is
badssl.com is a hosted collection of test subdomains, each deliberately configured with a broken or unusual TLS/SSL setup (expired certificates, weak ciphers, self-signed certs, mixed content, etc.). It is used to verify how HTTP clients, browsers, and TLS libraries handle bad SSL configurations.

## Use cases
- test how my http client handles expired ssl certificates
- verify browser warnings for self-signed certificates
- check tls library behavior against weak cipher suites like rc4
- test mixed content blocking in a browser
- validate hsts upgrade behavior
- regression-test ssl error handling in an application

## When to choose
- you need realistic bad TLS endpoints to test client certificate validation
- you are building a browser or http library and want to verify ssl error handling
- you want to check mixed-content or hsts behavior against known-bad configs

## When to avoid
- you need a general-purpose TLS testing tool like SSL Labs for auditing your own servers
- you need offline testing without internet access or local hosts setup
- you need fuzzing or penetration testing of your own infrastructure

## Facets
- artifact type: service
- maturity: active
- function: testing, security, http-server
- domain: security, testing, web-development, developer-tools
- platform: browser, cross-platform
- tags: tls, ssl, https, certificate-testing, test-subdomains, browser-testing, web-server, docker

## Member repositories
- chromium/badssl.com (main) score 70

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:39.392638+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T07:29:12.408248+00:00, confidence not recorded.
  - readme: https://github.com/chromium/badssl.com (fetched 2026-08-28T04:07:39.392638+00:00, sha 9b89c07b9922)
  - homepage: https://badssl.com (fetched 2026-08-29T09:44:14.858214+00:00, sha 8c7d3af3f35a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
