- Home
- Application Security
- Static Application Security Testing
- Securibench Micro
Securibench Micro
A collection of vulnerable web application test cases designed to benchmark and evaluate the effectiveness of static security analyzers and penetration testing tools.

Securibench Micro
A collection of vulnerable web application test cases designed to benchmark and evaluate the effectiveness of static security analyzers and penetration testing tools.
Securibench Micro Description
Securibench Micro is a collection of small test cases designed to evaluate static security analyzers and runtime security testing tools. The tool provides a series of vulnerable web applications that can be deployed on standard application servers like Tomcat. Each test case includes a known answer, enabling straightforward comparison and validation of security analysis results. The test cases contain various security vulnerabilities including: - SQL injection attacks - Cross-site scripting (XSS) attacks - HTTP splitting attacks - Path traversal attacks - Additional common web application vulnerabilities Originally developed and hosted at Stanford University, the project has transitioned to GitHub for continued development and community access. The tool serves as a benchmark for comparing the effectiveness of different security testing approaches, including both static analysis tools and dynamic penetration testing techniques.
Securibench Micro FAQ
Common questions about Securibench Micro including features, pricing, alternatives, and user reviews.
Securibench Micro is A collection of vulnerable web application test cases designed to benchmark and evaluate the effectiveness of static security analyzers and penetration testing tools.. It is a Application Security solution designed to help security teams with SQL Injection, Vulnerable Apps, Security Testing.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox