vuln-bank vs Damn-Vulnerable-RESTaurant-API-Game
Vulnerable security training apps compared
vuln-bank and Damn-Vulnerable-RESTaurant-API-Game are intentionally insecure projects for practicing security testing in controlled environments. vuln-bank centers on banking workflows across web, API, GraphQL, and AI features, while Damn-Vulnerable-RESTaurant-API-Game focuses on API security exercises with interactive game and hacking modes.

vuln-bank: Practice Web, API, and AI Security Testing
Vuln Bank is an intentionally vulnerable banking web app for learning application security testing and secure code review. It offers hands-on scenarios across web, API, GraphQL, and AI features, and should only run in an isolated educational environment.

Damn-Vulnerable-RESTaurant-API-Game: Practice API Security
A deliberately insecure Python API for practicing vulnerability discovery, exploitation, and remediation. Developers, ethical hackers, and security engineers can run it locally with Docker as a controlled training environment.
| vuln-bank | Damn-Vulnerable-RESTaurant-API-Game | |
|---|---|---|
| Language | HTML | Python |
| License | MIT | GPL-3.0 |
| Stars | 960 | 939 |
| Forks | 348 | 192 |
| Last analyzed | Oct 3, 2026 | Oct 3, 2026 |
Key differences
- vuln-bank covers web, API, GraphQL, and AI scenarios; Damn-Vulnerable-RESTaurant-API-Game is focused on API security.
- vuln-bank includes banking workflows such as transfers, loans, and bill payments; Damn-Vulnerable-RESTaurant-API-Game offers a developer game and an ethical hacking challenge.
- vuln-bank is listed with HTML as its language; Damn-Vulnerable-RESTaurant-API-Game uses Python with FastAPI and PostgreSQL.
- vuln-bank uses the MIT license; Damn-Vulnerable-RESTaurant-API-Game uses GPL-3.0.
- vuln-bank documents Docker Compose and a local Python/PostgreSQL installation path; Damn-Vulnerable-RESTaurant-API-Game requires Docker and Docker Compose V2, and also offers Codespaces.
- vuln-bank includes an AI support agent with a real LLM option or mock mode; Damn-Vulnerable-RESTaurant-API-Game describes API documentation through Swagger and Redoc.
Choose vuln-bank if you…
- want to practice security testing across banking workflows, web, API, GraphQL, and AI scenarios.
- need a lab that includes file uploads, transaction logic, payment-related flaws, or AI security exercises.
- prefer a project with an MIT license and a documented local Python/PostgreSQL installation path.
Choose Damn-Vulnerable-RESTaurant-API-Game if you…
- want an API-focused challenge with both interactive vulnerability remediation and privilege-escalation exercises.
- need a Python FastAPI and PostgreSQL project with Swagger and Redoc documentation.
- prefer Docker-based setup with an option to run through Codespaces.
This comparison is generated with AI from the OSRepos analyses of both projects. Always check each project's repository and documentation before choosing.