Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
You can practice web application security legally in a deliberately vulnerable app you run in a controlled environment, or in a hosted lab whose operator explicitly authorizes testing. For guided lessons, start with OWASP WebGoat or NodeGoat; for challenge-based discovery, try OWASP Juice Shop; for hosted labs, use PortSwigger Web Security Academy. These options differ in format, setup, and technology, so choose for your learning goal rather than assuming one teaches everything.
Where can I practice web application hacking legally?
Use a purpose-built training environment or a target whose owner has clearly authorized your testing. “Legal hacking practice” does not mean probing random public websites, a company’s production service, or a demo you happen to find online. Authorization must cover the target and the activity you plan to perform.
Some apps below are designed to run locally or in a container; PortSwigger Web Security Academy provides hosted labs. Follow the current setup and network-exposure instructions for the specific project. The OWASP Vulnerable Web Applications Directory is a living catalog, and its entries include independently maintained applications as well as projects associated with OWASP; inclusion does not mean every app is an active OWASP project. Check its current listings before choosing or installing an app: OWASP Vulnerable Web Applications Directory.
Compare the eight practice environments
| Environment | Format and access | Technology or learning focus | Good fit when |
|---|---|---|---|
| OWASP Juice Shop | Deliberately insecure application with CTF-style challenges; available as a practice app. | Node.js, Express, Angular, and REST APIs; challenge difficulty varies. | You want browser-facing, JavaScript-heavy practice and independent challenge solving. |
| OWASP WebGoat | Interactive teaching environment; default configuration binds to localhost according to its directory entry. | Guided web-security learning. | You want lessons and a deliberately bounded local practice target. |
| DVWA | Self-hosted application; the directory shows offline/container availability. | PHP-oriented vulnerable web application. | You want to run a local target and are prepared to follow its current setup guidance. |
| OWASP Mutillidae | PHP free-form, single-player application; offline availability is listed. | Hands-on practice without assuming a guided lesson sequence. | You want to explore an intentionally vulnerable target at your own pace. |
| bWAPP | PHP/MySQL free-form, single-player application; listed for offline and container use. | Locally controlled PHP/MySQL practice. | You want a self-hosted target and can verify current documentation before setup. |
| NodeGoat | Offline application with guided lessons in the directory. | Node.js and MongoDB. | You want lessons focused on a Node.js/MongoDB stack. |
| OWASP VulnerableApp | Offline application categorized for scanner testing. | JavaScript, React, and Spring Boot. | You want to exercise or compare security scanners, rather than assume a beginner tutorial. |
| PortSwigger Web Security Academy | Hosted learning materials and interactive labs; account sign-up can track progress. | Web security concepts and practical labs; Burp Suite Community Edition can be used to experiment with tools. | You want hosted practice without installing a vulnerable app locally. |
The OWASP directory lists the app categories, technologies, and access modes for many of the local options; those details and availability can change. Check the relevant entry and the project’s own current installation instructions: directory. PortSwigger describes its Academy as free, constantly updated training with interactive labs intended for practice in a safe and legal manner: Web Security Academy.
#1 Best Overall
Which app should you choose?
For guided learning
Choose WebGoat or NodeGoat if you want a lesson-oriented environment. NodeGoat is a useful fit if you specifically want to learn in a Node.js/MongoDB context. WebGoat offers interactive instruction, but its safety guidance is explicit: do not look for vulnerabilities without permission. Its directory entry says the default configuration binds to localhost and recommends disconnecting from the Internet while using it. Those are WebGoat-specific instructions, not universal settings for the other apps. Read the current project guidance before launch: OWASP WebGoat and directory entry.
For challenges and independent discovery
Juice Shop uses CTF-style challenges covering the OWASP Top Ten and additional real-world flaws, with varying difficulty. Its Node.js, Express, and Angular stack makes it a natural choice for practicing against a modern JavaScript application and REST API. It is a challenge environment, not a guarantee that a learner will cover every application-security topic: OWASP Juice Shop.
For self-hosted, free-form practice
DVWA, Mutillidae, and bWAPP are PHP-oriented options in the OWASP directory. Mutillidae and bWAPP are categorized there as free-form, single-player applications; do not assume they provide the same guided lesson structure as WebGoat. The directory identifies offline/container modes for these entries, but setup, versions, and security configuration should be confirmed in each project’s current documentation. bWAPP’s current vulnerability count is not established here, so use its official documentation rather than relying on an unsourced number. See the directory and DVWA project documentation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
For scanner evaluation
OWASP VulnerableApp is categorized in the directory for scanner testing and is listed with JavaScript, React, and Spring Boot. That makes it a candidate for exercising security scanners; the available evidence does not establish it as a beginner course or a comprehensive scanner benchmark. Use a controlled deployment and define what you are trying to evaluate before interpreting scanner results: OWASP directory.
For hosted labs
Web Security Academy is the choice here that does not require installing a vulnerable app as your target. PortSwigger provides learning material and interactive labs, says the content is constantly updated, and describes the Academy as a safe and legal way to practice. You can create an account to track progress, and Burp Suite Community Edition can be used to experiment with tools in the labs. The Academy page also names The Web Application Hacker’s Handbook by Dafydd Stuttard as an optional related resource; it is not a prerequisite for using the labs. Confirm any book edition and availability with the seller before purchasing: PortSwigger Web Security Academy.
Set up a safe practice routine
- Choose the environment for your goal. Select guided lessons, challenges, a free-form app, scanner testing, or hosted labs rather than trying to make one target serve every purpose.
- Use the current official setup instructions. Verify prerequisites, supported deployment method, and security configuration in the project’s own documentation. A directory listing is useful for comparison, not a substitute for the app’s current install instructions.
- Keep self-hosted targets contained. Know which interface and network the app will bind to before starting it. Do not expose an intentionally vulnerable service to a public network unless the project explicitly supports that configuration and you have secured and authorized the environment.
- Stay within the authorized scope. Test only the lab or system you control or have explicit permission to assess. Do not follow links from a lab into third-party services and treat them as targets.
- Record what you learn without widening the test. Keep notes about the lab, lesson, or challenge and the behavior you observed. If capturing screenshots or other evidence, limit collection to your authorized environment and avoid recording secrets or other people’s data.
WebGoat’s warning is worth applying to all practice: good intentions do not replace permission. Its project goals state, “Even if your intentions are good, we believe you should never attempt to find vulnerabilities without permission.” PortSwigger likewise frames the Academy as learning in a “safe and legal manner.” Those safety statements support bounded lab practice; they are not permission to test unrelated systems: WebGoat and Web Security Academy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Documenting an authorized lab with ScreenshotNeo
ScreenshotNeo is a website screenshot API and MCP server, not a vulnerable application, security scanner, or authorization mechanism. It is an alternative to manual browser setup when you need a screenshot of a page in your own lab or another page you are allowed to capture. Its cleanup can remove cookie/consent banners, newsletter popups, and chat widgets before capture; do not use screenshot capture to access or collect information outside your authorization. Details and supported options are in the ScreenshotNeo overview and API documentation.
A single GET request can return an image or PDF. For example, this cURL call captures a page you control as WebP; replace the example URL with your authorized lab URL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Use an API key from your account and consult the ScreenshotNeo documentation for output format and other parameters. ScreenshotNeo reports page verdict and billing status in response headers: bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits are not billed. Its MCP server provides take_screenshot, get_page_info, and capture_pdf tools for AI agents using Claude, Cursor, or another MCP client. Plans include 1,000 shots per month free with no card; paid plans start at $5 for 3,000 shots. Sign up for ScreenshotNeo and get 1,000 free screenshots a month with no card.
Best Value
- Comes with secure packaging
- It can be a gift item
- Easy to read text
FAQ
Are all eight options current OWASP projects?
No. The OWASP Vulnerable Web Applications Directory catalogs vulnerable applications, including independently maintained ones. Listing is not proof that every app is maintained by OWASP or that its current setup matches an older guide. Check the app’s project page for current status and instructions: OWASP directory.
Which option is the easiest?
No standardized difficulty comparison across these eight is established. Pick by the support you want: guided lessons, challenge prompts, free-form exploration, scanner testing, or hosted labs, then start at a level appropriate to your experience.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Can I practice on a public demo deployment?
Only if its operator explicitly authorizes the testing you intend to do. A site being publicly reachable or labeled a demo does not by itself grant permission.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

