11/12 free views
Educational Resource
Web Service
Application Security

juice-shop

by juice-shop

12.3Kstars
16.0Kforks
177watchers
Updated 3 months ago
About

OWASP Juice Shop is a modern, intentionally insecure web application designed for security training, awareness, and testing.

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

Primary Use Case

This tool is primarily used by security professionals, educators, and developers to practice identifying and exploiting common web vulnerabilities in a safe environment. It serves as a hands-on training platform for security awareness, Capture The Flag (CTF) challenges, and testing security tools against real-world flaws.

Key Features
  • Includes vulnerabilities from the entire OWASP Top Ten
  • Suitable for security trainings, awareness demos, and CTFs
  • Acts as a guinea pig for security tools and vulnerability scanners
  • Supports multiple installation methods including source, Docker, and Vagrant
  • Modern and sophisticated insecure web application
  • Open source with active CI/CD pipeline and test coverage
  • Comprehensive documentation and official companion guide

Installation

  • Install Node.js according to the Node.js version compatibility guidelines
  • Clone the repository using: git clone https://github.com/juice-shop/juice-shop.git
  • Navigate into the cloned directory
  • Install dependencies and start the application (specific commands not fully provided in snippet)
  • Alternatively, use packaged distributions, Docker container, or Vagrant for setup
  • Refer to the official running documentation for cloud provider setups

Usage

>_ git clone https://github.com/juice-shop/juice-shop.git

Clone the Juice Shop source code repository locally

Security Frameworks
Reconnaissance
Initial Access
Execution
Discovery
Impact
Usage Insights
  • Integrate Juice Shop into security training programs to simulate real-world web attacks safely.
  • Use as a testbed for tuning and validating web application firewalls and vulnerability scanners.
  • Leverage Juice Shop in purple team exercises to improve collaboration between offensive and defensive teams.
  • Automate vulnerability scanning and exploitation workflows by chaining Juice Shop with tools like Metasploit.
  • Incorporate Juice Shop into CI/CD pipelines for continuous security awareness and tool validation.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about juice-shop. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team80%
Blue Team30%
Purple Team50%
Details
LicenseMIT License
LanguageTypeScript
Open Issues919
Topics
owasp
javascript
vulnerable
hacking
application-security
owasp-top-10
owasp-top-ten
pentesting
vulnapp
appsec