OWASP Juice Shop
An intentionally insecure web shop covering the OWASP Top Ten, used for security training and CTFs.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About OWASP Juice Shop
OWASP Juice Shop is a deliberately insecure web application built around a fictional online shop. It includes vulnerabilities from the entire OWASP Top Ten along with many other flaws found in real-world applications. It is used in security trainings, awareness demos and CTF events, and as a target for testing security tools.
You can run it from source with Node.js, from packaged distributions, in a Docker container or with Vagrant. The documentation also covers deploying it on cloud providers. Some challenges need an AI or LLM provider, which can be local or cloud-based.
Strengths
- Covers the full OWASP Top Ten plus many other real-world flaws
- Several install options, including Docker, Vagrant and packaged distributions
- Suited to CTF events, training sessions and testing security tools
- Actively maintained with regular releases
Limitations
- Some challenges require configuring an AI or LLM provider
- Intended for authorized practice in a controlled environment
- Running from source requires a compatible Node.js version
Details
- Pricing
- FreeFree and open source under the MIT licence.
- License
- MIT
- Developer
- The OWASP Juice Shop contributors
- Platforms
- Self-hosted
- How it runs
- Self-hosted
- Best suited for
- Security trainers, CTF organisers and learners practising web application attacks
- Categories
- Learning tools, Security tools
- Last verified
- Added
- Provenance
- Selected from the TechWalrus Resource Hub (Cybersecurity & Pentesting); facts checked against the developer's own pages, 3 sources on file.