Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and remediation examples in 10+ languages.
40 free, open-source secure coding exercises that teach web application security the way developers learn — by exploiting real vulnerabilities like SQL injection, cross-site scripting (XSS), and broken access control, then writing the fix. Interactive SCORM modules covering the OWASP Top 10 for Web Applications, the OWASP API Security Top 10, Git and CI/CD repository security, and more. Remediation examples in JavaScript, TypeScript, Java, C#, Python, Scala, PHP, Ruby, Go, and Kotlin. Free for individual developers, nonprofits, and small businesses with fewer than 25 employees. Discounted Enterprise pricing for universities and educational institutions.

👥 Talk to the Founders | 🔗 Browse the Full Library | 🎮 Try a live DOM XSS demo
Reading the OWASP Top 10 once a year and passing a multiple-choice quiz does not prevent web application vulnerabilities in production. Developers need to see what a real exploit does — SQL injection dumping a database, cross-site scripting hijacking a session, broken access control exposing another user's data — and then write the secure code that stops it.
Every exercise in this free, open-source secure coding training library follows a three-phase methodology: exploit, trace, remediate.
You run a hands-on penetration test against an intentionally vulnerable application — SQL injection against a database, XSS that fires in a browser, SSRF that reaches the cloud metadata endpoint — then trace exactly how the vulnerability was introduced and apply secure coding best practices to fix it.
Exercises cover:
Every exercise ends with a quiz at a 100% pass threshold. By the time a developer is writing production code, they have already exploited every common web application vulnerability and know the secure coding best practices that prevent it.
Every exercise ships as a SCORM 1.2 .zip — import into any LMS (Moodle, TalentLMS, Docebo, Cornerstone, SAP SuccessFactors, Workday Learning, or anything SCORM-compliant), embed into your secure SDLC or DevSecOps training pipeline, or preview on SCORM Cloud before rollout.
White-labeled — no logos, no backlinks, no attribution required inside the modules, no vendor lock-in. Use them as part of a DevSecOps program, a secure SDLC initiative, developer onboarding, or standalone application security training. Who can use them, and on what terms, is covered in the license section below.
This open-source secure coding training library is published under the RansomLeak Community License (see LICENSE). It is free to use if you are:
Under the free license you can import the modules into any LMS, run them for your engineering team, embed them in your own secure SDLC training program, and use them in workshops you deliver. Redistributing or reselling the content as a standalone product is prohibited, and so is delivering it to third-party clients as a service (see application security training for MSPs & consultancies).
No training budget? If you're above 25 employees but don't have budget for secure coding training, contact us. We regularly agree individual terms in exchange for co-marketing (a case study, a testimonial, a logo on our site, or a review).
A university, school, coding bootcamp, or other educational institution? Institutional use — training staff, faculty, or students at scale — is covered by the Enterprise Plan at an education discount. Contact us with your institution's details for pricing.
25 or more employees, or need a DPA, a vendor contract, always-current content, or exercises built for your stack? The Enterprise Plan is for you. It includes a full commercial license for your headcount plus everything your security and procurement teams will ask for. Drop us a line for pricing.
Earlier releases of this repository were published under CC BY-NC 4.0. Copies obtained under that license remain subject to its terms; everything published from this version onward is under the RansomLeak Community License.
For engineering organizations with 25 or more employees, educational institutions, or any organization that needs more than the free library offers. Beyond the commercial license itself, this is what the Enterprise Plan adds: