WebGoat/WebGoat resource
WebGoat is a deliberately insecure application observed · 2026-08-28
Health v2 · maintenance only
79/100
- Activity 99
- Release rhythm 40
- Longevity 100
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 4.5
- age_days: 4198
- days_rel: 540
- days_push: 9
- n_releases_24m: 3
Adoption not part of the score
9293 stars · 7872 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
OWASP WebGoat is a deliberately insecure web application designed to teach web application security lessons through hands-on exercises. It demonstrates common server-side vulnerabilities in Java-based applications and is intended for learning application security and penetration testing in a safe, legal environment.
Use cases
- learn web application security hands-on
- practice penetration testing techniques legally
- test security scanners against a known-vulnerable app
- train developers on common vulnerabilities like SQL injection and XSS
- set up a security lab environment with Docker
- teach secure coding in classrooms or workshops
When to choose
- you want an interactive, guided environment for learning web security exploits
- you need a deliberately vulnerable Java app to test tools like ZAP or Burp
- you are teaching or studying OWASP-style vulnerability lessons
- you want a Docker-based security training target that runs locally
When to avoid
- you need a production or hardened application - WebGoat is intentionally insecure
- you want to test techniques against systems without authorization
- you need a non-Java vulnerable target or a real-world codebase to audit
- your machine cannot be isolated from the internet while running it
Facets
learning-resource · maturity active
security penetration-testing testing security education web-development penetration-testing self-hosted jvm owasp vulnerable-app security-training java web-security deliberately-insecure docker web-server
3 sources
- readme: https://github.com/WebGoat/WebGoat · fetched 2026-08-28 · 198b3bef756f
- homepage: https://owasp.org/www-project-webgoat/ · fetched 2026-08-29 · 80a87785c453
- site_page: https://owasp.org/about · fetched 2026-08-29 · b21a48297b2d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| WebGoat/WebGoat | main | 79 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem