← All repos

WebGoat

WebGoat is a deliberately insecure application

Browse cluster: Lean4 Formal Verification & Cryptography
3,222commits
183contributors
6languages

Tech stack & purpose

WebGoat is a deliberately insecure web application maintained by OWASP designed to teach web application security lessons through demonstrations of common server-side application flaws and penetration testing techniques. Built in Java with the Spring Boot framework, it can be run via Docker, as a standalone jar file, or from source code. The project is intended for educational purposes to help people learn about application security vulnerabilities in a controlled environment.

Languages

JavaScript
48.7%
Java
35.3%
HTML
12.1%
CSS
3.7%
Dockerfile
0.1%
Shell
0.0%

Contributors (top 30 of 183)