
OWASP Juice Shop
OWASP Juice Shop is a free open-source deliberately insecure web app used to practice finding and exploiting web flaws for students and security trainers.
0 upvotes · 0 downvotes
No ratings yet
- Categories
- Training & LabsApplication Security
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A fake online store built with Node.js, Express, and Angular that is full of planted flaws, from the OWASP Top Ten to bugs seen in real-world applications. Challenges range from easy to very hard, and a score board tracks progress.
What it helps with
- Practicing web attacks in a safe target before touching real systems
- Running capture the flag events and awareness demos
- Checking how well a scanner or proxy handles a JavaScript-heavy app and REST API
- Teaching developers what common web bugs look like
Who it's for
Students, trainers, and developers learning web security, who should run it only in an isolated lab and never on an internet-facing server.
Worth knowing
It is an OWASP Flagship project. Finding the hidden score board is itself one of the first challenges.
Can it be run in a container?
Yes, an official Docker image is published.
Who leads the project?
Björn Kimminich and Jannik Hollenbach are the project leaders.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.