dolevf/Damn-Vulnerable-GraphQL-Application
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security. observed · 2026-08-28
Health v2 · maintenance only
33/100
- Activity 23
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2037
- days_rel: 466
- days_push: 466
- n_releases_24m: 1
Adoption not part of the score
1705 stars · 375 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security attacks. It ships with beginner and expert modes covering reconnaissance, denial of service, injection, code execution, and authorization bypass scenarios.
Use cases
- practice exploiting graphql vulnerabilities
- learn graphql security concepts
- train a security team on graphql attacks
- test graphql pentesting tools against a safe target
- set up a deliberately vulnerable graphql lab
- learn graphql introspection and dos attacks
When to choose
- you want a safe, self-hosted target to practice graphql exploitation
- you are teaching or learning graphql security hands-on
- you need a benchmark app to validate graphql security scanners
When to avoid
- you need a production graphql server or framework
- you want a secure reference implementation to copy
- you are not interested in security training
Facets
application · maturity active
security penetration-testing graphql web-framework security penetration-testing web-development education apis python self-hosted cross-platform graphql-security vulnerable-app security-training ctf exploitation learning-by-doing docker web-server
1 source
- readme: https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application · fetched 2026-08-28 · 7a92748aba37
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| dolevf/Damn-Vulnerable-GraphQL-Application | main | 33 |
For agents
markdown · JSON · MCP: product_card(name="dolevf/Damn-Vulnerable-GraphQL-Application")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem