# zhuifengshaonianhanlu/pikachu

一个好玩的Web安全-漏洞测试平台

Repository: https://github.com/zhuifengshaonianhanlu/pikachu
Canonical: https://ross.abutalabs.com/products/pikachu
Language: PHP
License: Apache-2.0
License Family: permissive
Topics: web
Last push: 2026-06-06T07:41:02+00:00

## Health v2 (maintenance only)
Score: 71/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 86, release rhythm 35, longevity 100
- inputs: {"age_days": 2962, "days_push": 88, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4504, forks 797 (observed 2026-08-28T04:08:52.495999+00:00)

## What it is
Pikachu is a deliberately vulnerable PHP/MySQL web application designed as a practice range for learning web security and penetration testing. It contains scenario-based exercises covering common vulnerability classes such as XSS, SQL injection, CSRF, RCE, file inclusion/upload, SSRF, XXE, and privilege escalation.

## Use cases
- practice exploiting sql injection on a safe local target
- learn xss with guided scenarios and hints
- set up a vulnerable web app for security training
- practice csrf and ssrf exploitation in a lab
- teach web penetration testing to students
- test burp suite and other pentest tooling against known flaws

## When to choose
- you are learning web penetration testing and need a hands-on vulnerable target
- you want scenario-based exercises with hints for many vulnerability classes
- you want a quick dockerized security lab

## When to avoid
- you need a modern stack - the author recommends the Java/Spring-based MadRabbit successor instead
- you want a production or real application - it is intentionally insecure
- you cannot run PHP/MySQL locally or in a container

## Facets
- artifact type: application
- maturity: maintenance
- function: security, penetration-testing, web-framework
- domain: security, penetration-testing, web-development, education
- platform: php, self-hosted
- tags: vulnerable-app, ctf, security-training, practice-range, deliberately-insecure, xss, sql-injection, csrf, ssrf, web-server, docker, linux

## Member repositories
- zhuifengshaonianhanlu/pikachu (main) score 71

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:52.495999+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:20:24.052828+00:00, confidence not recorded.
  - readme: https://github.com/zhuifengshaonianhanlu/pikachu (fetched 2026-08-28T04:08:52.495999+00:00, sha 715e9241e460)
- Data as of 2026-08-30T08:39:29.467469+00:00.
