Why this exists
A small shop with a big hole in it
There are two kinds of vulnerable app: the enormous one you never finish, and the ancient one nobody wants to look at. FreeFungi is a third kind. Small, current, and actually pleasant to work through.
Every flaw here is one a real developer could ship on a bad Friday. Nothing is
signposted with a // hack me comment. That realism is the whole point:
it makes the practice carry over to real targets, and it makes the
benchmark mean something to a scanner.
Who builds it
FreeFungi is made by Shak Ahmed, who works in offensive security. An honest target with no hints buried in the code, and clear write-ups when you want them, is something I care about getting right. Both for teaching and for measuring the tools that claim to catch this stuff.
Kept neutral on purpose
The project stays personal and MIT-licensed, with no vendor attached. A benchmark is only useful if it is neutral: the moment it becomes anyone’s marketing asset, the numbers stop being trusted. So the scoring is reproducible, every tool is reported the same way, and anyone can re-run it and check.
Use it, fork it, teach with it
MIT licensed. Run it in a workshop, hand it out at a CTF, point your students at it, benchmark your scanner against it. If you build something on top, I’d love to hear about it. The repo is the place.