Ross ROSS = Recommend OSS · open-source software intelligence for agents

OWASP/wrongsecrets

Vulnerable app with examples showing how to not use secrets observed · 2026-08-28

github.com/OWASP/wrongsecrets · homepage · Java · AGPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 98
  • Release rhythm 84
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 28
  • age_days: 2205
  • days_rel: 106
  • days_push: 16
  • n_releases_24m: 18

Full methodology

Adoption not part of the score

1459 stars · 604 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

OWASP WrongSecrets is a deliberately vulnerable Java application containing 50+ challenges that demonstrate how secrets are commonly misconfigured or wrongly stored across Docker, Kubernetes, Vault, and cloud environments. It can be played as a standalone game, used in security trainings, or serve as a test target for secret-detection tooling.

Use cases

  • learn secrets management best practices through hands-on challenges
  • run a CTF event for security training
  • test secret detection and scanning tools against a vulnerable app
  • practice finding leaked credentials in docker, kubernetes, and cloud setups
  • raise developer awareness about hardcoded secrets
  • evaluate my own secrets management practices

When to choose

  • you want hands-on training or a CTF for secrets management
  • you need a test target for secret-scanning tooling
  • you want to teach developers about misconfigured secrets across Vault, AWS, GCP, Azure, and Kubernetes

When to avoid

  • you need a production secrets management solution
  • you want a general-purpose vulnerable web app not focused on secrets

Facets

application · maturity active

security secrets-management penetration-testing security developer-tools education cloud self-hosted vulnerable-app ctf secrets-management devsecops security-training hashicorp-vault terraform owasp devops docker kubernetes web-server

3 sources

Member repositories

RepositoryRoleHealth v2
OWASP/wrongsecretsmain94

For agents

markdown · JSON · MCP: product_card(name="OWASP/wrongsecrets")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem