About WebGoat - Provided by the OWASP Foundation

Thanks for hacking The Goat!

WebGoat is a demonstration of common web application flaws. The associated exercises are intended to provide hands-on experience with techniques aimed at demonstrating and testing application penetration.

From the entire WebGoat team, we appreciate your interest and efforts in making applications not just better, but safer and more secure for everyone. We, as well as our sacrificial goat, thank you.

Version:

Visit our homepage

Active Contributors

  • Nanne Baars (Project lead)
  • René Zubcevic (Developer)
  • Àngel Ollé Blázquez (Developer)

Corporate Sponsorship - Companies that have donated significant time to WebGoat development

  • Aspect Security
  • Ounce Labs


Did we miss you? Our sincere apologies, as we know there have been many contributors over the years. If your name does not appear in any of the lists above, please send us a note. We'll get you added with no further sacrifices required.

Past Contributors

  • Bruce Mayhew (Author / Project lead / Goat herder)
  • Jason White (Architect UX)
  • Doug Morato (Developer & CI)
  • Richard Lawson (Architect)
  • Michael Dever (Developer)
  • Jeff Wayman (Docs)
  • Dave Cowden (Everything)
  • Richard Lawson (Service Layer)
  • Keith Gasser (Survey/Security)
  • Devin Mayhew (Setup/Admin)
  • Li Simon (Developer)
  • Ali Looney (UI Design)
  • David Anderson (Developer/Design)
  • Christopher Blum (Lessons)
  • Laurence Casey (Graphics)
  • Brian Ciomei (Bug fixes)
  • Rogan Dawes (Lessons)
  • Erwin Geirnaert (Solutions)
  • Aung Knant (Documentation)
  • Ryan Knell (Lessons)
  • Christine Koppeit (Build)
  • Sherif Kousa (Lessons/Documentation)
  • Reto Lippuner (Lessons)
  • PartNet (Lessons)
  • Yiannis Pavlosoglou (Lessons)
  • Eric Sheridan (Lessons)
  • Alex Smolen (Lessons)
  • Chuck Willis (Lessons)
  • Marcel Wirth (Lessons)
  • Jeff Williams (Author & Original Idea)