Skip to content
@juice-shop

OWASP Juice Shop

Insecure web application for security trainings, awareness demos, CTFs and as a guinea pig for security tools

Juice Shop Banner

OWASP Juice Shop is probably the most modern and sophisticated insecure web application! It can be used in security trainings, awareness demos, CTFs and as a guinea pig for security tools! Juice Shop encompasses vulnerabilities from the entire OWASP Top Ten along with many other security flaws found in real-world applications!

OWASP Flagship CII Best Practices Contributor Covenant Twitter Follow Subreddit subscribers

OWASP Juice Shop and any contributions are Copyright © by Bjoern Kimminich & the OWASP Juice Shop contributors 2014-2024.

Pinned Loading

  1. juice-shop juice-shop Public

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

    TypeScript 12.7k 17k

  2. multi-juicer multi-juicer Public

    Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

    TypeScript 309 172

  3. pwning-juice-shop pwning-juice-shop Public

    Antora/Asciidoc content for Bjoern Kimminich's free eBook "Pwning OWASP Juice Shop"

    Handlebars 232 157

  4. juice-shop-ctf juice-shop-ctf Public

    Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF

    TypeScript 463 136

  5. juice-shop-tutorials juice-shop-tutorials Public

    Official OWASP Juice Shop tutorials on UI customization and system integration

    10 13

Repositories

Showing 10 of 11 repositories
  • juicy-statistics Public

    Scripts to collect statistics about OWASP Juice Shop

    juice-shop/juicy-statistics’s past year of commit activity
    TypeScript 2 MIT 15 1 (1 issue needs help) 0 Updated Mar 25, 2026
  • juice-shop Public

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

    juice-shop/juice-shop’s past year of commit activity
    TypeScript 12,742 MIT 17,026 10 (2 issues need help) 1 Updated Mar 25, 2026
  • shake-logger Public

    This projects provides a logger and a connected harlem shake js.

    juice-shop/shake-logger’s past year of commit activity
    CSS 20 8 0 0 Updated Mar 24, 2026
  • multi-juicer Public

    Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

    juice-shop/multi-juicer’s past year of commit activity
    TypeScript 309 Apache-2.0 172 11 (7 issues need help) 6 Updated Mar 23, 2026
  • pwning-juice-shop Public

    Antora/Asciidoc content for Bjoern Kimminich's free eBook "Pwning OWASP Juice Shop"

    juice-shop/pwning-juice-shop’s past year of commit activity
    Handlebars 232 157 2 (1 issue needs help) 4 Updated Mar 22, 2026
  • juicy-coupon-bot Public

    Coupon code generator and distribution bot for OWASP Juice Shop

    juice-shop/juicy-coupon-bot’s past year of commit activity
    TypeScript 9 MIT 13 0 2 Updated Mar 1, 2026
  • juicy-chat-bot Public

    Smart, friendly and helpful chat bot for OWASP Juice Shop

    juice-shop/juicy-chat-bot’s past year of commit activity
    TypeScript 11 MIT 13 0 1 Updated Jan 26, 2026
  • juice-shop-ctf Public

    Tool to export Juice Shop challenges and hints in data format compatible with CTFd, RootTheBox or FBCTF

    juice-shop/juice-shop-ctf’s past year of commit activity
    TypeScript 463 MIT 136 1 (1 issue needs help) 5 Updated Jan 21, 2026
  • juice-shop-tutorials Public

    Official OWASP Juice Shop tutorials on UI customization and system integration

    juice-shop/juice-shop-tutorials’s past year of commit activity
    10 13 0 0 Updated Oct 7, 2024
  • .github Public
    juice-shop/.github’s past year of commit activity
    0 2 0 0 Updated Mar 20, 2024

Most used topics

Loading…