OWASP Juice Shop

An intentionally insecure web shop covering the OWASP Top Ten, used for security training and CTFs.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

About OWASP Juice Shop

OWASP Juice Shop is a deliberately insecure web application built around a fictional online shop. It includes vulnerabilities from the entire OWASP Top Ten along with many other flaws found in real-world applications. It is used in security trainings, awareness demos and CTF events, and as a target for testing security tools.

You can run it from source with Node.js, from packaged distributions, in a Docker container or with Vagrant. The documentation also covers deploying it on cloud providers. Some challenges need an AI or LLM provider, which can be local or cloud-based.

Strengths

  • Covers the full OWASP Top Ten plus many other real-world flaws
  • Several install options, including Docker, Vagrant and packaged distributions
  • Suited to CTF events, training sessions and testing security tools
  • Actively maintained with regular releases

Limitations

  • Some challenges require configuring an AI or LLM provider
  • Intended for authorized practice in a controlled environment
  • Running from source requires a compatible Node.js version

Details

Pricing
FreeFree and open source under the MIT licence.
License
MIT
Developer
The OWASP Juice Shop contributors
Platforms
Self-hosted
How it runs
Self-hosted
Best suited for
Security trainers, CTF organisers and learners practising web application attacks
Last verified
Added
Provenance
Selected from the TechWalrus Resource Hub (Cybersecurity & Pentesting); facts checked against the developer's own pages, 3 sources on file.

Report a wrong fact or a dead link on this listing