erev0s/VAmPI
Vulnerable REST API with OWASP top 10 vulnerabilities for security testing observed · 2026-08-28
Health v2 · maintenance only
66/100
- Activity 76
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2159
- days_rel: n/a
- days_push: 148
- n_releases_24m: 0
Adoption not part of the score
1311 stars · 590 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for evaluating API security testing tools and for learning or teaching API security, with a global switch to toggle vulnerabilities on and off.
Use cases
- test api security scanning tools against known vulnerabilities
- practice exploiting owasp top 10 api vulnerabilities
- train developers on api security flaws
- generate false positive and false negative benchmarks for security tools
- learn rest api security with a safe vulnerable target
- test token-based authentication weaknesses
When to choose
- you need a realistic vulnerable API target for testing security scanners
- you want a controlled environment with a vulnerability on/off switch
- you are teaching or learning OWASP API security concepts
- you need OpenAPI 3 specs and Postman collections for a test API
When to avoid
- you need a production-ready secure API framework
- you want to secure a real application rather than practice on a dummy one
- you need non-REST API types like GraphQL or gRPC test targets
Facets
application · maturity active
security web-framework api-framework testing penetration-testing security apis penetration-testing developer-tools education python self-hosted vulnerable-app owasp-api-top-10 security-training deliberately-vulnerable flask openapi api-security-testing docker web-server
1 source
- readme: https://github.com/erev0s/VAmPI · fetched 2026-08-28 · 6de15e795a21
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| erev0s/VAmPI | main | 66 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem