InsecureShop is an intentionally vulnerable Android application developed in Kotlin that serves as an educational platform for developers and security professionals. The application incorporates real-world vulnerabilities commonly found during mobile penetration tests, providing a controlled environment for learning and testing. Key features include: - Focus on Android Deeplinks and Webviews vulnerabilities - Real-world vulnerability scenarios based on actual mobile pentest findings - Educational platform for understanding modern Android app security issues - Testing environment for Android penetration testing skills development The tool is designed specifically for security education and training purposes, allowing users to practice identifying and exploiting Android application vulnerabilities in a safe, controlled environment.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A PHP port of Rack::Honeypot, a spam trap that detects and blocks spambots
QIRA is a competitor to strace and gdb with MIT license, supporting Ubuntu and Docker for wider compatibility.
A deliberately vulnerable Java web application designed for educational purposes to teach web application security concepts and common vulnerabilities.
Search engine for open-source Git repositories with advanced features like case sensitivity and regular expressions.
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.
GuardDog is a CLI tool that identifies malicious PyPI and npm packages using heuristics-based analysis of source code and metadata.
A technology lookup and lead generation tool that identifies the technology stack of any website and provides features for market research, competitor analysis, and data enrichment.
A comprehensive toolkit for web application security testing, offering a range of products and solutions for identifying vulnerabilities and improving security posture.
A brute-force protection middleware for express routes that rate-limits incoming requests.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.