Skip to main content

Free 30-min security demo Book Now

Free field kit · DAST evaluation

OWASP Juice Shop DAST Benchmark Kit

A repeatable, vendor-neutral procedure for scoring dynamic application security testing scanners against the same target, the same accounts and the same expected findings. Built from our step-by-step benchmark guide, condensed into a print-ready PDF your team can run in an afternoon.

  • Two runs per scanner (unauthenticated and authenticated) on a pinned Juice Shop image
  • Fifteen expected findings with endpoint and detection method
  • Pass/fail bar plus a 50-point rubric that scores evidence, not rule names
  • Scoresheets for three scanners side by side

Nine pages · PDF · no pricing, no vendor pitch until the last page.

Get the kit by e-mail

We send the PDF link to your inbox within a minute.

We use your address only to send the kit and, if you ask, to arrange a demo. No newsletter.

What is inside

Pinned setup and reset procedure

One Docker image tag for the whole evaluation and a one-line reset between scanners, so stored payloads from scanner A never show up as findings for scanner B.

Authenticated-scan checklist

Login request, JWT and cookie carriers, logout exclusions, re-authentication rule and the three URLs that prove the crawler is really logged in.

15 minimum expected findings

Critical, high and medium findings with the exact endpoint and detection method, plus five scanner-differentiating findings (stored XSS, SSRF, JWT, IDOR).

Pass/fail bar and 50-point rubric

Four mandatory checks a production scanner must pass, then five scored criteria: injection, authentication, headers, crawl coverage and false-positive rate.

Scoresheets for three scanners

Print-ready tables to record both runs per scanner side by side, including evidence quality, report formats and deployment options tested.

Common mistakes that invalidate results

Six ways a benchmark goes wrong, from scanning the public demo server to comparing raw counts instead of verified findings.

Questions

Is the kit vendor-neutral?

Yes. The procedure, expected findings and rubric come from OWASP Juice Shop itself and apply to any DAST scanner. Offensive360 is mentioned once, on the last page, as an optional fourth column.

Which Juice Shop version does it target?

The kit pins a specific Docker image tag and asks you to record it on the scoresheet. The expected findings are stable across recent Juice Shop releases, but pinning keeps every scanner on the same target.

Do I need a business e-mail address?

No. Many evaluations start in a personal lab. We send the PDF link to whichever address you enter and never share it.

Can I share the kit inside my organization?

Yes. The kit is free to use and share internally. Please link to this page rather than re-hosting the PDF so readers always get the current version.

Want a fourth column?

Run the same benchmark with Offensive360 DAST

Headless-browser crawling, 40+ active exploit checks, self-hosted out-of-band detection and request/response proof for every finding. On-premise, Azure or fully air-gapped.