Ross ROSS = Recommend OSS · open-source software intelligence for agents

roottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises. observed · 2026-08-28

github.com/roottusk/vapi · HTML · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

23/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2187
  • days_rel: n/a
  • days_push: 600
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1349 stars · 338 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ships with a Postman collection and Docker/Kubernetes deployment options for practicing API security testing.

Use cases

  • practice exploiting OWASP API Top 10 vulnerabilities
  • set up a deliberately vulnerable API lab for security training
  • learn API security testing with Postman exercises
  • train for bug bounty hunting on APIs
  • demo API security flaws in appsec workshops

When to choose

  • you want a self-hosted, hands-on target for learning API security
  • you need realistic OWASP API Top 10 scenarios for training or workshops
  • you want Postman-based guided exercises for API exploitation

When to avoid

  • you need a production-ready secure API framework
  • you want automated vulnerability scanning rather than a practice target
  • you cannot run PHP/MySQL or Docker in your environment

Facets

application · maturity active

security penetration-testing api-framework self-hosted security penetration-testing apis developer-tools education self-hosted php owasp-api-top-10 vulnerable-application api-security appsec bug-bounty postman security-training labs docker web-server kubernetes

1 source

Member repositories

RepositoryRoleHealth v2
roottusk/vapimain23

For agents

markdown · JSON · MCP: product_card(name="roottusk/vapi")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem