Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can practice web application security legally in a deliberately vulnerable app you run in a controlled environment, or in a hosted lab that explicitly permits testing. For guided lessons, start with OWASP WebGoat or NodeGoat; for challenge-style discovery, try OWASP Juice Shop; for an online option, PortSwigger Web Security Academy. None of these authorizes testing unrelated websites.

Where can you practice web application hacking legally?

Use a training application designed to be vulnerable, follow its current setup and network-exposure guidance, and keep testing within that environment. A lab is not a blanket permission to probe the machine hosting it, other services on your network, or a public demo site. PortSwigger describes its Academy labs as a way to learn in a “safe and legal manner”; OWASP WebGoat likewise warns against searching for vulnerabilities without permission. PortSwigger Web Security Academy and OWASP WebGoat provide those boundaries.

The eight options below differ in how much instruction they provide, the technology they use, and whether you run them yourself or access hosted labs. The OWASP Vulnerable Web Applications directory is a living catalog that includes independently maintained projects as well as OWASP projects, so check each entry’s current status and official instructions before choosing one: OWASP Vulnerable Web Applications Directory.

Compare the eight practice environments

Environment Format and guidance Technology or focus Best fit
OWASP Juice Shop Self-hosted challenge app; CTF-style challenges at varied difficulty Node.js, Express, Angular; web app and REST API flaws Browser-facing and JavaScript-heavy practice
OWASP WebGoat Interactive guided teaching environment Web application security lessons Learning concepts step by step
DVWA Self-hosted vulnerable app PHP-oriented Controlled practice with a locally run target
OWASP Mutillidae Free-form, single-player app; offline availability listed PHP Hands-on exploration without assuming a guided lesson sequence
bWAPP Free-form, single-player app; offline and container modes listed PHP/MySQL Locally controlled practice
NodeGoat Guided lessons; offline app listed Node.js/MongoDB Lessons in a Node.js and MongoDB context
OWASP VulnerableApp Offline app listed; scanner-testing category JavaScript, React, Spring Boot Exercising or comparing security scanners
PortSwigger Web Security Academy Hosted online learning materials and interactive labs Web security topics; Burp Suite tools can be used Starting without installing a vulnerable app

App categories, technology labels, and access modes in the table reflect the OWASP directory; Academy details reflect PortSwigger’s description. They are not a standardized difficulty ranking, and the directory’s availability labels can change. See the OWASP directory and Academy page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

1. OWASP Juice Shop: challenge-based modern web practice

Juice Shop is a deliberately insecure web application used for training, awareness demonstrations, CTFs, and security-tool evaluation. OWASP says its challenges address the OWASP Top Ten as well as additional real-world flaws. It is built with Node.js, Express, and Angular, and challenges range in difficulty. That makes it a useful choice if you want to explore a contemporary JavaScript web stack and REST APIs rather than follow only a linear lesson. OWASP Juice Shop.

Choose it when you want to practice recognizing and investigating issues through challenges. It is less appropriate if your first priority is a guided explanation for every concept; WebGoat or NodeGoat is more explicitly lesson-oriented.

2. OWASP WebGoat: interactive lessons with explicit safety guidance

WebGoat is an interactive teaching environment for web application security. It is a strong starting point when you want instruction alongside practice instead of a free-form target. OWASP’s project guidance is direct: “Even if your intentions are good, we believe you should never attempt to find vulnerabilities without permission.” OWASP WebGoat.

WebGoat’s directory entry says its default configuration binds to localhost and advises disconnecting from the Internet during use. Those are WebGoat-specific cautions, not configuration instructions for every app in this list. Review the current project setup and exposure guidance before starting it. OWASP directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Damn Vulnerable Web Application (DVWA): a self-hosted PHP target

DVWA is an intentionally vulnerable application listed in OWASP’s directory, with offline and container availability shown there. It is a practical candidate when you want to control the target yourself and work with a PHP-oriented application. The directory listing alone does not establish current setup steps or safe configuration for your machine, so consult DVWA’s current official documentation before launching it. OWASP directory; DVWA project documentation.

4. OWASP Mutillidae: free-form PHP practice

OWASP lists Mutillidae as a PHP, free-form, single-player application and shows offline availability. It is suited to learners who want to interact with an intentionally vulnerable target and choose what to investigate, rather than expect the same guided lesson structure as WebGoat. Check the current project documentation for installation and configuration details. OWASP directory.

5. bWAPP: PHP/MySQL app for a controlled local lab

The OWASP directory describes bWAPP as a PHP/MySQL, free-form, single-player application and lists offline and container access. That profile makes it a candidate for a locally controlled practice environment. Do not rely on unverified vulnerability totals or assumed setup defaults; use the current official project instructions and keep the app isolated as those instructions specify. OWASP directory.

6. NodeGoat: guided practice in a Node.js/MongoDB context

NodeGoat is listed in OWASP’s directory as an offline Node.js/MongoDB application with guided lessons. It gives learners a technology-specific alternative to the PHP-oriented apps, while keeping the instruction-led format that helps when studying one topic at a time. Verify its current availability and setup instructions in the directory and project documentation before use. OWASP directory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

7. OWASP VulnerableApp: a scanner-testing option

The directory lists VulnerableApp as an offline Java application using JavaScript, React, and Spring Boot, categorized for scanner testing. Consider it if your goal is to exercise or compare security scanners against a deliberately vulnerable target. The available description does not establish that it is a beginner tutorial, so choose a guided environment instead if you need lesson-by-lesson instruction. OWASP directory.

8. PortSwigger Web Security Academy: hosted labs, no app installation

Web Security Academy is an online training platform, not an application you install. PortSwigger describes it as free, constantly updated, and composed of learning materials and interactive labs. You can create an account to track progress, and PortSwigger says Burp Suite Community Edition can be used to experiment with tools in the labs. Its stated aim is helping people learn web security in a “safe and legal manner.” PortSwigger Web Security Academy.

Choose Academy when you want hosted exercises and educational material without setting up a vulnerable app locally. Its labs are authorized training targets; that permission does not extend to testing other PortSwigger systems or unrelated sites.

Choose by goal, guidance, and setup preference

If you want guided instruction

Start with WebGoat or NodeGoat, both listed with guided teaching or lessons. Academy also pairs learning material with hosted labs. These formats make it easier to focus on a concept before attempting more independent discovery. OWASP directory; Academy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you want to find issues through challenges

Juice Shop’s CTF-style challenges encourage independent discovery across a modern Node.js, Express, and Angular application. A free-form app such as Mutillidae or bWAPP may also suit you if you prefer choosing what to examine rather than following lessons. These formats do not imply a common difficulty scale. Juice Shop; OWASP directory.

If you need a particular technology

  • Node.js: Juice Shop uses Node.js, Express, and Angular; NodeGoat is listed with Node.js and MongoDB.
  • PHP: DVWA and Mutillidae are PHP-oriented; bWAPP is listed as PHP/MySQL.
  • Java and React: VulnerableApp is listed with JavaScript, React, and Spring Boot.

These are directory descriptions, not a promise that every version or deployment uses an identical stack. Confirm the current project details before you build a lab around a technology requirement. OWASP directory.

If you want to avoid local installation

Use PortSwigger Academy’s hosted labs. If you prefer local control, choose a directory entry with an offline or container mode and follow its own setup guidance. A directory mode label does not itself tell you how to isolate a vulnerable app safely.

Set up a legal practice routine

  1. Pick a contained target. Use one of the intentionally vulnerable apps or a lab whose operator explicitly permits the exercise. Do not substitute a public website or an unapproved demo.
  2. Read current project instructions. Check installation, supported versions, configuration, and network exposure before running a self-hosted app. The OWASP directory is actively maintained, so its entries and availability can change: directory.
  3. Keep scope narrow. Test only the training app and lab functions covered by its permission. Do not treat permission for one lab as permission to scan its host, adjacent services, or other sites.
  4. Match the format to your aim. Use guided lessons to learn a concept, CTF-style challenges to practice discovery, or scanner-oriented targets to exercise a tool.
  5. Stop when scope is unclear. If a target’s authorization or boundary is not explicit, do not test it; ask its operator or use a clearly authorized lab instead.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use screenshots to document your lab work

Capturing a screenshot of your own local lab or an authorized training page can help document a lesson or result. Keep documentation within the same authorization boundary: a screenshot tool does not grant permission to access the page it captures. For a one-call screenshot API and MCP server for developers, ScreenshotNeo is an alternative to try first when you want cookie banners, popups, and chat widgets removed before capture, with bot checks, blank pages, and failed loads not billed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Or skip the browser setup

Use the API only with a URL you are allowed to access. The request below saves a WebP screenshot; the API can also return PNG, JPEG, or PDF. See the ScreenshotNeo API documentation for parameters.

Best Value
Sale
The Web Application Hacker's Handbook: Finding and Exploiting Security Flaws
  • Comes with secure packaging
  • It can be a gift item
  • Easy to read text
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp

ScreenshotNeo accepts consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each cleanup step can be turned off. Bot checks, blank pages, failed loads, timeouts, and cache hits are not billed, and response headers indicate the page verdict and billing status. Its MCP server includes take_screenshot, get_page_info, and capture_pdf for AI agents using Claude, Cursor, or another MCP client. The free plan includes 1,000 shots a month without a card; paid plans start at $5 for 3,000 shots, and yearly billing gives two months free. Every feature is available on every plan. Sign up for 1,000 free screenshots a month with no card.

Common mistakes and how to avoid them

  • Assuming all eight apps are OWASP projects: the OWASP directory catalogs vulnerable apps, including independently maintained projects. Check the project owner and current instructions in each case.
  • Assuming every app is guided: the directory differentiates guided lessons from free-form, CTF, and scanner-testing categories. Select by learning style rather than treating the list as eight interchangeable tutorials.
  • Exposing a vulnerable app without checking its instructions: the WebGoat directory entry specifically notes localhost binding by default and recommends disconnecting from the Internet. Do not assume another app uses the same defaults; inspect its own guidance.
  • Testing beyond permission: lab access is not authorization to probe public sites or other systems. Stop if the scope is uncertain.
  • Trusting stale availability information: the directory is a living catalog. Confirm that the project remains available and consult the current official setup documentation before relying on a download path or deployment mode.

Frequently Asked Questions

Do I need Burp Suite to use Web Security Academy?

PortSwigger says Burp Suite Community Edition can be used to experiment with tools in its labs; it does not describe it as a prerequisite. See the Academy page.

Is the OWASP directory a list of OWASP-maintained apps only?

No. It is a directory of vulnerable web applications and also catalogs independently maintained projects. Check the individual project’s ownership and current status.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I scan a public demo of one of these applications?

Only if the operator has explicitly authorized that activity. Use a controlled local app or a hosted lab whose permission clearly covers the testing you intend to perform.

Quick Recap

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.