# roottusk/vapi

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

Repository: https://github.com/roottusk/vapi
Canonical: https://ross.abutalabs.com/products/vapi
Language: HTML
License: GPL-3.0
License Family: copyleft
Topics: owasp, api, apitop10, owasp-top-10, owasp-top-ten, vulnerable-application, appsec, appsec-tutorials, bugbounty, hacktoberfest, docker, cors, php, postman, hacktoberfest-accepted, exercises
Last push: 2025-01-10T02:48:25+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2187, "days_push": 600, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1349, forks 338 (observed 2026-08-28T04:04:27.893079+00:00)

## What it is
vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ships with a Postman collection and Docker/Kubernetes deployment options for practicing API security testing.

## Use cases
- practice exploiting OWASP API Top 10 vulnerabilities
- set up a deliberately vulnerable API lab for security training
- learn API security testing with Postman exercises
- train for bug bounty hunting on APIs
- demo API security flaws in appsec workshops

## When to choose
- you want a self-hosted, hands-on target for learning API security
- you need realistic OWASP API Top 10 scenarios for training or workshops
- you want Postman-based guided exercises for API exploitation

## When to avoid
- you need a production-ready secure API framework
- you want automated vulnerability scanning rather than a practice target
- you cannot run PHP/MySQL or Docker in your environment

## Facets
- artifact type: application
- maturity: active
- function: security, penetration-testing, api-framework, self-hosted
- domain: security, penetration-testing, apis, developer-tools, education
- platform: self-hosted, php
- tags: owasp-api-top-10, vulnerable-application, api-security, appsec, bug-bounty, postman, security-training, labs, docker, web-server, kubernetes

## Member repositories
- roottusk/vapi (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:27.893079+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:42:23.074960+00:00, confidence not recorded.
  - readme: https://github.com/roottusk/vapi (fetched 2026-08-28T04:04:27.893079+00:00, sha 1066c6645fd5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
