digininja/dvwa

Damn Vulnerable Web Application (DVWA)

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 43 minutes ago
Added to GitGenius on September 4th, 2026
Created on May 1st, 2013
Open Issues & Pull Requests: 7 (+0)
GitHub issues: Enabled
Number of forks: 5,096
Total Stargazers: 13,623 (+0)
Total Subscribers: 320 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 0.2 hours
Mean response time: 13.0 hours
90th percentile: 10.0 hours
Tracked items: 43

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Only 20% of issues opened in the past year have been closed. Three people close 86% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 1
New in 7 days: 1
Closed in 7 days: 1
Avg open age: 126 days
Stale 30+ days: 1
Stale 90+ days: 0

Recent activity

Opened in 7 days: 1
Closed in 7 days: 1
Comments in 7 days: 0
Events in 7 days: 1

Top labels

  • bug (1)

Most active issues this week

Detailed Description

Damn Vulnerable Web Application (DVWA) is a deliberately vulnerable PHP web application designed for security training and practice.

DVWA addresses the need for a safe, legal environment where security professionals, developers, and students can practice identifying and exploiting common web vulnerabilities. The application intentionally contains both documented and undocumented vulnerabilities across multiple difficulty levels, presented through a straightforward interface. Users are encouraged to discover as many issues as possible, making it suitable for hands-on learning of web application security concepts.

DVWA is intended for use in controlled environments such as virtual machines with isolated networking, not on internet-facing servers or public hosting. It serves security professionals testing tools and techniques, web developers learning to secure applications, and students and instructors in classroom settings. The application is explicitly not recommended for malicious use, and the developers disclaim responsibility for compromises resulting from installation on live servers.

Development of the project reflects broad international engagement, with the README available in multiple languages and a process for community translation contributions that emphasizes human accuracy over automated translation. The codebase is distributed under the GNU General Public License, allowing redistribution and modification.