Ross ROSS = Recommend OSS · open-source software intelligence for agents

rapid7/hackazon

A modern vulnerable web app observed · 2026-08-28

github.com/rapid7/hackazon · HTML · Apache-2.0 (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 4086
  • days_rel: n/a
  • days_push: 2001
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1038 stars · 382 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

Hackazon is a deliberately vulnerable online storefront web application built with PHP, AJAX, and RESTful APIs. It serves as a training and testing ground for IT security professionals to practice discovering vulnerabilities like SQL injection and cross-site scripting.

Use cases

  • practice exploiting sql injection on a realistic web app
  • test web application security scanners against a vulnerable target
  • train security teams on xss and api vulnerabilities
  • test rest api security testing tools
  • set up a safe vulnerable storefront for pentest practice
  • learn to secure shopping cart workflows

When to choose

  • you need a realistic vulnerable web application for security testing or training
  • you want to evaluate web app scanners and DAST tools against AJAX and REST interfaces
  • you are teaching application security with hands-on exploitation exercises

When to avoid

  • you need a production or secure e-commerce platform
  • you require modern PHP versions or actively maintained dependencies
  • you want a currently developed project with recent updates

Facets

application · maturity maintenance

security web-framework http-server security web-development penetration-testing php vulnerable-web-app security-training pentest-target sql-injection xss rest-api deliberately-insecure linux web-server

1 source

Member repositories

RepositoryRoleHealth v2
rapid7/hackazonmain10

For agents

markdown · JSON · MCP: product_card(name="rapid7/hackazon")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem