Ross ROSS = Recommend OSS · open-source software intelligence for agents

OWASP/crAPI

completely ridiculous API (crAPI) observed · 2026-08-28

github.com/OWASP/crAPI · Java · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

63/100

  • Activity 82
  • Release rhythm 18
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2037
  • days_rel: 337
  • days_push: 111
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1566 stars · 629 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

crAPI (completely ridiculous API) is an intentionally vulnerable web application built by OWASP to demonstrate the OWASP API Security Top 10 risks. It is a microservices-based application designed to be safely self-hosted for security training and practice.

Use cases

  • learn the OWASP API Security Top 10 hands-on
  • practice API penetration testing against a safe target
  • train security teams on API vulnerabilities
  • test API security scanning tools
  • set up a deliberately vulnerable lab environment with docker compose
  • demonstrate API security risks in workshops

When to choose

  • you need a realistic, intentionally vulnerable API for security training or CTF-style challenges
  • you want to evaluate API security tooling against known vulnerabilities
  • you're teaching or learning API security concepts

When to avoid

  • you need a production-ready API framework or boilerplate
  • you want a secure reference implementation to copy into your own project
  • you can't run Docker or don't want to host a vulnerable service

Facets

application · maturity active

security api-framework developer-tools security apis developer-tools education self-hosted windows api-security vulnerable-by-design owasp security-training pentesting-lab microservices docker linux macos

1 source

Member repositories

RepositoryRoleHealth v2
OWASP/crAPImain63

For agents

markdown · JSON · MCP: product_card(name="OWASP/crAPI")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem