REPOGEO REPORT · LITE
OWASP/crAPI
Default branch develop · commit 73d309cc · scanned 5/26/2026, 11:41:36 PM
GitHub: 1,513 stars · 571 forks
Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface OWASP/crAPI, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.
Action plan — copy-paste fixes
3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.
- highhomepage#1Add a homepage URL to the repository
Why:
COPY-PASTE FIXhttps://owasp.org/www-project-crapi/
- hightopics#2Refine repository topics for better categorization
Why:
CURRENTapi, apisecurity, hacktoberfest, owasp
COPY-PASTE FIXapi, apisecurity, owasp, vulnerable-api, security-training, microservices, docker
- mediumreadme#3Explicitly mention 'OWASP API Security Top 10' in the README's opening
Why:
CURRENT**c**ompletely **r**idiculous **API** (crAPI) will help you to understand the ten most critical API security risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.
COPY-PASTE FIX**c**ompletely **r**idiculous **API** (crAPI) is an intentionally vulnerable application designed to help you understand and test against the **OWASP API Security Top 10** risks. crAPI is vulnerable by design, but you'll be able to safely run it to educate/train yourself.
Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash
Category visibility — the real GEO test
Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?
Same questions for every model — switch tabs to compare answers and rankings.
- bkimminich/juice-shop · recommended 1×
- WebGoat/WebGoat · recommended 1×
- ethicalhack3r/DVWA · recommended 1×
- erev0s/VAmPI · recommended 1×
- apisecurity/APISecurity.io · recommended 1×
- CATEGORY QUERYWhat are some intentionally vulnerable APIs for practicing common security exploits and training?you: not recommendedAI recommended (in order):
- OWASP Juice Shop (bkimminich/juice-shop)
- OWASP WebGoat (WebGoat/WebGoat)
- DVWA (Damn Vulnerable Web Application) (ethicalhack3r/DVWA)
- VAmPI (Vulnerable API) (erev0s/VAmPI)
- API Security Project (APISecurity.io) (apisecurity/APISecurity.io)
- Mutillidae II (webpwnized/mutillidae)
- Hack The Box (HTB) Labs
AI recommended 7 alternatives but never named OWASP/crAPI. This is the gap to close.
Show full AI answer
- CATEGORY QUERYNeed a platform to understand and test against the OWASP Top 10 API security risks.you: not recommendedAI recommended (in order):
- OWASP Juice Shop
- OWASP API Security Top 10 Project
- Postman
- Newman
- Burp Suite
- ZAP
- APIsec
- Tricentis qTest
- Tosca
AI recommended 9 alternatives but never named OWASP/crAPI. This is the gap to close.
Show full AI answer
Objective checks
Rule-based audits of metadata signals AI engines weight most.
- Metadata completenesswarn
Suggestion:
- README presencepass
Self-mention check
Does AI even know your repo exists when asked about it directly?
- Compared to common alternatives in this category, what is the core differentiator of OWASP/crAPI?passAI named OWASP/crAPI explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- If a team adopts OWASP/crAPI in production, what risks or prerequisites should they evaluate first?passAI named OWASP/crAPI explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- In one sentence, what problem does the repo OWASP/crAPI solve, and who is the primary audience?passAI named OWASP/crAPI explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
Embed your GEO score
Drop this badge into the README of OWASP/crAPI. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.
[](https://repogeo.com/en/r/OWASP/crAPI)<a href="https://repogeo.com/en/r/OWASP/crAPI"><img src="https://repogeo.com/badge/OWASP/crAPI.svg" alt="RepoGEO" /></a>Subscribe to Pro for deep diagnoses
OWASP/crAPI — Lite scans stay free; this card itemizes Pro deep limits vs Lite.
- Deep reports10 / month
- Brand-free category queries5 vs 2 in Lite
- Prioritized action items8 vs 3 in Lite