OWASP Juice Shop - Broken access control and input security
Abuse prevention, permissions, and sensitive data
OWASP Juice Shop
Practice safe security-focused QA thinking around auth, input validation, and access control.
Training library
Pick a “How would you test...” prompt, write your answer, and compare your coverage with senior-level checklists.
Missing a scenario?
Tell me what interview prompt, product flow, or API scenario would make this library more useful.
External Practice Labs link to third-party demo/practice sites. Open a lab, explore the target app, then return here to write your test ideas and compare them with a senior QA checklist.
We do not own or host these third-party practice sites.
Recommended first labs:
Beginner Web UI
basic UI elements and beginner-friendly flows
E-commerce Testing
carts, checkout, pricing, orders
Banking / Finance
accounts, transfers, permissions, transaction history
API Testing
REST endpoints, schemas, status codes, negative cases
Automation Practice
locators, waits, dynamic UI, flaky risks
Security Testing
safe educational security test design
Accessibility Testing
keyboard, labels, focus, contrast, screen readers
Performance Testing
journeys, load scenarios, response times, bottlenecks
Exploratory Testing
puzzles, hidden rules, test idea generation
Progress
No local progress yet. Start a challenge to begin tracking in this browser. No signup required.
Abuse prevention, permissions, and sensitive data
OWASP Juice Shop
Practice safe security-focused QA thinking around auth, input validation, and access control.
Abuse prevention, permissions, and sensitive data
Google Gruyere
Use an educational vulnerable app to build safe security test design habits.