Ross ROSS = Recommend OSS · open-source software intelligence for agents

WebGoat/WebGoat resource

WebGoat is a deliberately insecure application observed · 2026-08-28

github.com/WebGoat/WebGoat · homepage · JavaScript · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

79/100

  • Activity 99
  • Release rhythm 40
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 4.5
  • age_days: 4198
  • days_rel: 540
  • days_push: 9
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

9293 stars · 7872 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

OWASP WebGoat is a deliberately insecure web application designed to teach web application security lessons through hands-on exercises. It demonstrates common server-side vulnerabilities in Java-based applications and is intended for learning application security and penetration testing in a safe, legal environment.

Use cases

  • learn web application security hands-on
  • practice penetration testing techniques legally
  • test security scanners against a known-vulnerable app
  • train developers on common vulnerabilities like SQL injection and XSS
  • set up a security lab environment with Docker
  • teach secure coding in classrooms or workshops

When to choose

  • you want an interactive, guided environment for learning web security exploits
  • you need a deliberately vulnerable Java app to test tools like ZAP or Burp
  • you are teaching or studying OWASP-style vulnerability lessons
  • you want a Docker-based security training target that runs locally

When to avoid

  • you need a production or hardened application - WebGoat is intentionally insecure
  • you want to test techniques against systems without authorization
  • you need a non-Java vulnerable target or a real-world codebase to audit
  • your machine cannot be isolated from the internet while running it

Facets

learning-resource · maturity active

security penetration-testing testing security education web-development penetration-testing self-hosted jvm owasp vulnerable-app security-training java web-security deliberately-insecure docker web-server

3 sources

Member repositories

RepositoryRoleHealth v2
WebGoat/WebGoatmain79

For agents

markdown · JSON · MCP: product_card(name="WebGoat/WebGoat")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem