Ross ROSS = Recommend OSS · open-source software intelligence for agents

digininja/DVWA

Damn Vulnerable Web Application (DVWA) observed · 2026-08-28

github.com/digininja/DVWA · PHP · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 98
  • Release rhythm 16
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 127
  • age_days: 4872
  • days_rel: 581
  • days_push: 14
  • n_releases_24m: 2

Full methodology

Adoption not part of the score

13551 stars · 5065 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application intentionally riddled with common web vulnerabilities at multiple difficulty levels. It provides a legal, controlled environment for security professionals, developers, and students to practice exploitation and defense techniques.

Use cases

  • practice exploiting sql injection in a safe lab
  • learn web application security hands-on
  • train security professionals in a legal environment
  • test web vulnerability scanning tools
  • teach students about common web vulnerabilities
  • set up a deliberately vulnerable target for pentest practice

When to choose

  • you want a realistic, intentionally vulnerable web app for security training or tool testing
  • you are teaching or learning web exploitation techniques like SQL injection or XSS
  • you need a legal target environment for practicing penetration testing skills

When to avoid

  • you need a secure production web application - DVWA is intentionally vulnerable
  • you cannot isolate it in a VM or container, since exposing it publicly will get the host compromised
  • you want automated vulnerability assessment rather than a hands-on practice target

Facets

application · maturity active

security penetration-testing web-framework database security penetration-testing web-development education php self-hosted vulnerable-app security-training sql-injection ctf learning-lab intentionally-vulnerable web-server linux docker

1 source

Member repositories

RepositoryRoleHealth v2
digininja/DVWAmain70

For agents

markdown · JSON · MCP: product_card(name="digininja/DVWA")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem