Broken Crystals
Deliberately vulnerable web app for testing and training security scanners and pentesters.
Webfreeglobal

Broken Crystals is an intentionally vulnerable web application built with modern web technologies, used to test security scanners and train security engineers on real vulnerability classes like broken authentication. It runs locally via Docker and exposes REST, GraphQL, and Swagger-documented endpoints riddled with documented flaws to exploit safely. It's aimed at AppSec teams and pentesters who need a realistic benchmark target.
Categories
securitytrainingbenchmarking
Something wrong with this listing — dead link, not a real product, wrong info?

