# OWASP/SecurityShepherd

Web and mobile application security training platform

Repository: https://github.com/OWASP/SecurityShepherd
Canonical: https://ross.abutalabs.com/products/securityshepherd
Homepage: https://owasp.org/www-project-security-shepherd/
Language: Java
License: GPL-3.0
License Family: copyleft
Last push: 2026-08-12T00:54:18+00:00

## Health v2 (maintenance only)
Score: 66/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 8, longevity 100
- inputs: {"age_days": 4680, "days_push": 22, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1456, forks 510 (observed 2026-08-28T04:04:46.935745+00:00)

## What it is
OWASP Security Shepherd is a self-hosted web and mobile application security training platform built in Java. It presents lessons and challenges covering real, hardened vulnerabilities across the OWASP Top Ten and beyond, letting users practice penetration testing skills safely.

## Use cases
- train developers on web application security
- practice penetration testing on deliberately vulnerable apps
- run a security awareness course for a team
- learn mobile application security testing
- demonstrate OWASP Top Ten risks hands-on
- host a capture-the-flag style security challenge

## When to choose
- you need a safe, self-hosted playground with real (not simulated) vulnerabilities
- you want structured lessons plus challenges for all skill levels
- you need configurable modules for teaching specific security topics

## When to avoid
- you want a quick local vulnerable app without server setup
- you need automated vulnerability scanning rather than training
- you require a commercial LMS with user management integrations out of the box

## Facets
- artifact type: application
- maturity: active
- function: security, penetration-testing
- domain: security, education, web-development, developer-tools
- platform: self-hosted
- tags: security-training, vulnerable-app, ctf, owasp, appsec, learning-platform, education, docker, web-server, linux

## Member repositories
- OWASP/SecurityShepherd (main) score 66

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:46.935745+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:35:35.322968+00:00, confidence not recorded.
  - readme: https://github.com/OWASP/SecurityShepherd (fetched 2026-08-28T04:04:46.935745+00:00, sha 6cae15774398)
  - homepage: https://owasp.org/www-project-security-shepherd/ (fetched 2026-08-29T11:44:33.363416+00:00, sha 03272ef09907)
  - site_page: https://owasp.org/about (fetched 2026-08-29T11:44:33.382836+00:00, sha b21a48297b2d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
