# juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

Repository: https://github.com/juice-shop/juice-shop
Canonical: https://ross.abutalabs.com/products/juice-shop
Homepage: https://owasp-juice.shop
Language: TypeScript
License: MIT
License Family: permissive
Topics: owasp, javascript, vulnerable, hacking, application-security, owasp-top-10, owasp-top-ten, pentesting, vulnapp, appsec, ctf, hacktoberfest, 24pullrequests, security
Last push: 2026-08-24T19:36:23+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 85, longevity 100
- inputs: {"age_days": 4366, "days_push": 9, "days_rel": 23, "gap_med": 51.0, "n_releases_24m": 13}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 13726, forks 19339 (observed 2026-08-28T04:11:04.673096+00:00)

## What it is
OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the entire OWASP Top Ten plus many other real-world flaws. It is used for security training, awareness demos, CTFs, and as a test target for security tools, with hacking challenges tracked on a scoreboard.

## Use cases
- practice exploiting owasp top 10 vulnerabilities
- set up a ctf hacking challenge platform
- train developers in secure coding
- test security scanners against a javascript-heavy app
- demo web application security flaws
- learn penetration testing on a legal target

## When to choose
- you need a realistic, modern vulnerable app for security training or CTFs
- you want to benchmark pentesting proxies or scanners against REST APIs and SPAs
- you teach application security and want gamified challenges

## When to avoid
- you need a secure production e-commerce application
- you want a minimal vulnerable target rather than a full-featured shop
- you cannot host a deliberately insecure application safely

## Facets
- artifact type: application
- maturity: active
- function: security, penetration-testing, web-framework, developer-tools
- domain: security, penetration-testing, web-development, education
- platform: self-hosted, cross-platform
- tags: vulnerable-web-application, owasp-top-ten, ctf, security-training, hacking-challenges, scoreboard, appsec, intentionally-insecure, nodejs, web-server, docker

## Member repositories
- juice-shop/juice-shop (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:11:04.673096+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:13:05.229882+00:00, confidence not recorded.
  - readme: https://github.com/juice-shop/juice-shop (fetched 2026-08-28T04:11:04.673096+00:00, sha 14649520600e)
  - homepage: https://owasp-juice.shop (fetched 2026-08-29T08:07:48.381036+00:00, sha 56557f240cdd)
- Data as of 2026-08-30T08:39:29.467469+00:00.
