Skip to content

WebGoat is a deliberately insecure application

active 2025-11-042026-01-27 (UTC)

Complete coverage26,736 / 26,736 hourly files (100%) · 2 absent upstream2023-08-152026-09-01 (UTC)
Events
480
Pushes
314
Pull requests
23
Issues
0
Stars
0
Forks
1

Activity over time

Daily event counts in the loaded window

Line chart, 85 days from 2025-11-04 to 2026-01-27. Pushes: 314 total, peak 33 in a day. Pull requests: 23 total, peak 9 in a day. Issues: 0 total, peak 0 in a day. Comments: 98 total, peak 10 in a day. Stars: 0 total, peak 0 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
RohasRedz337314230
sonarqubecloud[bot]980098
github-advanced-security[bot]1000

Recent activity

Latest issues, pull requests and releases

  • Issue comment#68sonarqubecloud[bot]2026-01-27 10:06
    Security Fix: SQL injection, sensitive logging, ReDoS regex, and hard-coded secret remediation
  • Issue comment#68sonarqubecloud[bot]2026-01-21 06:37
    Security Fix: SQL injection, sensitive logging, ReDoS regex, and hard-coded secret remediation
  • Issue comment#68sonarqubecloud[bot]2026-01-21 06:05
    Security Fix: SQL injection, sensitive logging, ReDoS regex, and hard-coded secret remediation
  • Issue comment#66sonarqubecloud[bot]2026-01-20 12:04
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 10:24
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 09:54
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 09:45
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 09:32
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 08:39
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 08:04
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 06:43
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 06:32
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-20 06:20
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#66sonarqubecloud[bot]2026-01-19 13:09
    Security Fix: SQL Injection, Hardcoded Credentials, Logging Exposure, Regex Inefficiency & JWT Handling
  • Issue comment#65sonarqubecloud[bot]2026-01-19 12:48
    Security Fix: SQL injection, hard-coded secret, logging exposure, and ReDoS risks
  • Issue comment#65sonarqubecloud[bot]2026-01-19 12:39
    Security Fix: SQL injection, hard-coded secret, logging exposure, and ReDoS risks
  • Issue comment#65sonarqubecloud[bot]2026-01-19 11:15
    Security Fix: SQL injection, hard-coded secret, logging exposure, and ReDoS risks
  • Issue comment#65sonarqubecloud[bot]2026-01-19 10:45
    Security Fix: SQL injection, hard-coded secret, logging exposure, and ReDoS risks
  • Issue comment#64sonarqubecloud[bot]2026-01-19 06:37
    Security Fix: SQL injection, logging exposure, regex DoS, and JWT hardcoded credential remediation
  • Pull request#64RohasRedz2026-01-16 22:10
  • Issue comment#63sonarqubecloud[bot]2026-01-16 13:31
    Security Fix: SQL injection, logging exposure, regex complexity, and hard-coded password
  • Issue comment#61sonarqubecloud[bot]2026-01-16 11:01
    Security Fix: SQL injection, hard-coded credential, logging exposure, and ReDoS in WebGoat lessons
  • Issue comment#61sonarqubecloud[bot]2026-01-16 10:47
    Security Fix: SQL injection, hard-coded credential, logging exposure, and ReDoS in WebGoat lessons
  • Issue comment#60sonarqubecloud[bot]2026-01-15 15:44
    Security Fix: SQL injection, logging exposure, regex ReDoS, and hard-coded credential remediation
  • Issue comment#60sonarqubecloud[bot]2026-01-15 12:15
    Security Fix: SQL injection, logging exposure, regex ReDoS, and hard-coded credential remediation

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.