# dolevf/Damn-Vulnerable-GraphQL-Application

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

Repository: https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application
Canonical: https://ross.abutalabs.com/products/damn-vulnerable-graphql-application
Language: JavaScript
License: MIT
License Family: permissive
Topics: vulnerability, graphql, security, penetration-testing, damn-vulnerable, damn-vulnerable-web-application, graphql-security, exploitation
Last push: 2025-05-24T16:38:08+00:00

## Health v2 (maintenance only)
Score: 33/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 23, release rhythm 8, longevity 100
- inputs: {"age_days": 2037, "days_push": 466, "days_rel": 466, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1705, forks 375 (observed 2026-08-28T04:05:24.806645+00:00)

## What it is
Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security attacks. It ships with beginner and expert modes covering reconnaissance, denial of service, injection, code execution, and authorization bypass scenarios.

## Use cases
- practice exploiting graphql vulnerabilities
- learn graphql security concepts
- train a security team on graphql attacks
- test graphql pentesting tools against a safe target
- set up a deliberately vulnerable graphql lab
- learn graphql introspection and dos attacks

## When to choose
- you want a safe, self-hosted target to practice graphql exploitation
- you are teaching or learning graphql security hands-on
- you need a benchmark app to validate graphql security scanners

## When to avoid
- you need a production graphql server or framework
- you want a secure reference implementation to copy
- you are not interested in security training

## Facets
- artifact type: application
- maturity: active
- function: security, penetration-testing, graphql, web-framework
- domain: security, penetration-testing, web-development, education, apis
- platform: python, self-hosted, cross-platform
- tags: graphql-security, vulnerable-app, security-training, ctf, exploitation, learning-by-doing, docker, web-server

## Member repositories
- dolevf/Damn-Vulnerable-GraphQL-Application (main) score 33

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:24.806645+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:37:31.544452+00:00, confidence not recorded.
  - readme: https://github.com/dolevf/Damn-Vulnerable-GraphQL-Application (fetched 2026-08-28T04:05:24.806645+00:00, sha 7a92748aba37)
- Data as of 2026-08-30T08:39:29.467469+00:00.
