Ross ROSS = Recommend OSS · open-source software intelligence for agents

erev0s/VAmPI

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing observed · 2026-08-28

github.com/erev0s/VAmPI · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

66/100

  • Activity 76
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2159
  • days_rel: n/a
  • days_push: 148
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1311 stars · 590 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for evaluating API security testing tools and for learning or teaching API security, with a global switch to toggle vulnerabilities on and off.

Use cases

  • test api security scanning tools against known vulnerabilities
  • practice exploiting owasp top 10 api vulnerabilities
  • train developers on api security flaws
  • generate false positive and false negative benchmarks for security tools
  • learn rest api security with a safe vulnerable target
  • test token-based authentication weaknesses

When to choose

  • you need a realistic vulnerable API target for testing security scanners
  • you want a controlled environment with a vulnerability on/off switch
  • you are teaching or learning OWASP API security concepts
  • you need OpenAPI 3 specs and Postman collections for a test API

When to avoid

  • you need a production-ready secure API framework
  • you want to secure a real application rather than practice on a dummy one
  • you need non-REST API types like GraphQL or gRPC test targets

Facets

application · maturity active

security web-framework api-framework testing penetration-testing security apis penetration-testing developer-tools education python self-hosted vulnerable-app owasp-api-top-10 security-training deliberately-vulnerable flask openapi api-security-testing docker web-server

1 source

Member repositories

RepositoryRoleHealth v2
erev0s/VAmPImain66

For agents

markdown · JSON · MCP: product_card(name="erev0s/VAmPI")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem