FreeFungi

Why this exists

A small shop with a big hole in it

There are two kinds of vulnerable app: the enormous one you never finish, and the ancient one nobody wants to look at. FreeFungi is a third kind. Small, current, and actually pleasant to work through.

Every flaw here is one a real developer could ship on a bad Friday. Nothing is signposted with a // hack me comment. That realism is the whole point: it makes the practice carry over to real targets, and it makes the benchmark mean something to a scanner.

Who builds it

FreeFungi is made by Shak Ahmed, who works in offensive security. An honest target with no hints buried in the code, and clear write-ups when you want them, is something I care about getting right. Both for teaching and for measuring the tools that claim to catch this stuff.

Kept neutral on purpose

The project stays personal and MIT-licensed, with no vendor attached. A benchmark is only useful if it is neutral: the moment it becomes anyone’s marketing asset, the numbers stop being trusted. So the scoring is reproducible, every tool is reported the same way, and anyone can re-run it and check.

Use it, fork it, teach with it

MIT licensed. Run it in a workshop, hand it out at a CTF, point your students at it, benchmark your scanner against it. If you build something on top, I’d love to hear about it. The repo is the place.