Matchboxmatchbox
← Back to match

Broken Crystals

Deliberately vulnerable web app for testing and training security scanners and pentesters.

Webfreeglobal

Broken Crystals is an intentionally vulnerable web application built with modern web technologies, used to test security scanners and train security engineers on real vulnerability classes like broken authentication. It runs locally via Docker and exposes REST, GraphQL, and Swagger-documented endpoints riddled with documented flaws to exploit safely. It's aimed at AppSec teams and pentesters who need a realistic benchmark target.

Categories
securitytrainingbenchmarking

Full match profile

Behind the summary, Matchbox keeps a richer profile of Broken Crystals - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether Broken Crystals (or something else) actually fits.