Ross ROSS = Recommend OSS · open-source software intelligence for agents

dolevf/Damn-Vulnerable-GraphQL-Application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security. observed · 2026-08-28

github.com/dolevf/Damn-Vulnerable-GraphQL-Application · JavaScript · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

33/100

  • Activity 23
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2037
  • days_rel: 466
  • days_push: 466
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

1705 stars · 375 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security attacks. It ships with beginner and expert modes covering reconnaissance, denial of service, injection, code execution, and authorization bypass scenarios.

Use cases

  • practice exploiting graphql vulnerabilities
  • learn graphql security concepts
  • train a security team on graphql attacks
  • test graphql pentesting tools against a safe target
  • set up a deliberately vulnerable graphql lab
  • learn graphql introspection and dos attacks

When to choose

  • you want a safe, self-hosted target to practice graphql exploitation
  • you are teaching or learning graphql security hands-on
  • you need a benchmark app to validate graphql security scanners

When to avoid

  • you need a production graphql server or framework
  • you want a secure reference implementation to copy
  • you are not interested in security training

Facets

application · maturity active

security penetration-testing graphql web-framework security penetration-testing web-development education apis python self-hosted cross-platform graphql-security vulnerable-app security-training ctf exploitation learning-by-doing docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
dolevf/Damn-Vulnerable-GraphQL-Applicationmain33

For agents

markdown · JSON · MCP: product_card(name="dolevf/Damn-Vulnerable-GraphQL-Application")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem