Ross ROSS = Recommend OSS · open-source software intelligence for agents

juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application observed · 2026-08-28

github.com/juice-shop/juice-shop · homepage · TypeScript · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 85
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 51.0
  • age_days: 4366
  • days_rel: 23
  • days_push: 9
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

13726 stars · 19339 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the entire OWASP Top Ten plus many other real-world flaws. It is used for security training, awareness demos, CTFs, and as a test target for security tools, with hacking challenges tracked on a scoreboard.

Use cases

  • practice exploiting owasp top 10 vulnerabilities
  • set up a ctf hacking challenge platform
  • train developers in secure coding
  • test security scanners against a javascript-heavy app
  • demo web application security flaws
  • learn penetration testing on a legal target

When to choose

  • you need a realistic, modern vulnerable app for security training or CTFs
  • you want to benchmark pentesting proxies or scanners against REST APIs and SPAs
  • you teach application security and want gamified challenges

When to avoid

  • you need a secure production e-commerce application
  • you want a minimal vulnerable target rather than a full-featured shop
  • you cannot host a deliberately insecure application safely

Facets

application · maturity active

security penetration-testing web-framework developer-tools security penetration-testing web-development education self-hosted cross-platform vulnerable-web-application owasp-top-ten ctf security-training hacking-challenges scoreboard appsec intentionally-insecure nodejs web-server docker

2 sources

Member repositories

RepositoryRoleHealth v2
juice-shop/juice-shopmain94

For agents

markdown · JSON · MCP: product_card(name="juice-shop/juice-shop")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem