toolcompass.

Find your next AI tool

Search by product name or task. Press Escape to close.

OWASP Juice Shop

● Identity checked

Code · Vendor site 2026-10-04

OWASP Juice Shop is a deliberately insecure Node.js web application used for security training, CTF events, and tool benchmarking. It bundles challenges spanning the OWASP Top Ten and other real-world flaws, tracks progress on a scoreboard, and ships as open-source software maintained by the OWASP community.

Updated 2026-10-04View sources
Official website
Category
Code
Free access
OWASP Foundation states project resources are free and open to everyone
API access
REST API surface is part of the vulnerable application used in training scenarios

Is OWASP Juice Shop right for you?

A good fit for

AppSec trainers, students, and tool vendors who need a modern JavaScript intentionally vulnerable application.

Before you choose

Juice Shop is for authorized lab use only; running it exposes an intentionally exploitable application.

Intentionally vulnerable app

OWASP Juice Shop gives learners a modern web stack full of exploitable flaws plus a scoreboard to track challenge progress.

What it can do

Features & capabilities

Unknown is different from unavailable. Each fact carries its own evidence.

CapabilityValueEvidenceChecked
Training focusProject page describes Juice Shop for security trainings, awareness demos, and CTFs.Facts sourced2026-10-04
OWASP Top Ten coverageCopy states challenges span the OWASP Top Ten plus additional real-world vulnerability classes.Facts sourced2026-10-04
Open-source stackProject information lists TypeScript, MIT license, and public GitHub resources.Facts sourced2026-10-04

Understand the total cost

OWASP Juice Shop pricing & plans

Free

Free

OWASP Foundation states project resources are free and open to everyone

Access
OWASP Foundation states project resources are free and open to everyone
Explore pricing & history

Alternatives to OWASP Juice Shop

View all ↗

The practical questions

Frequently asked questions

What is OWASP Juice Shop used for?

OWASP Juice Shop is a deliberately insecure Node.js web application used for security training, CTF events, and tool benchmarking. It bundles challenges spanning the OWASP Top Ten and other real-world flaws, tracks progress on a scoreboard, and ships as open-source software maintained by the OWASP community.

Does OWASP Juice Shop have a free plan?

OWASP Foundation states project resources are free and open to everyone. This record lists ongoing free access; check the plan limits before starting.

How much does OWASP Juice Shop cost?

No paid monthly price is listed; this record treats the product as free to start. See the plan cards for entitlements, billing commitments and seat minimums.

Can I use OWASP Juice Shop through an API?

REST API surface is part of the vulnerable application used in training scenarios. API access and subscription access may have different terms; consult the linked sources.

What should I check before choosing it?

Juice Shop is for authorized lab use only; running it exposes an intentionally exploitable application.

Price history

No retained pricing changes yet. A current price alone does not establish a historical trend.

How this profile is supported

Facts apply to the named version and check date. Send a sourced correction if something changed.