Skip to content
CAI
Software that uses CAICheck a score

zhuifengshaonianhanlu/pikachu

32.0

Weak · 19 September 2026

7.6k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Pikachu is a vulnerable web application designed for web security training and penetration testing practice. It provides a PHP-based environment with Docker support that simulates various attack vectors, including XSS, SQL injection, CSRF, and brute-force attacks. The system includes dedicated modules for managing XSS testing scenarios and interactive labs for practicing authentication bypasses and request forgery exploits.

Features

Added brute-force and CSRF vulnerability labs

New interactive security training modules have been added to the vul directory, covering brute-force attack vectors (including form-based, client-side CAPTCHA bypass, server-side CAPTCHA bypass, and token-based protections) and Cross-Site Request Forgery (CSRF) scenarios (GET-based, POST-based, and token-protected forms). These files provide the frontend interfaces and backend logic for users to practice identifying and exploiting these specific authentication and request-forgery weaknesses.

vul · high confidence

Initial implementation of core application infrastructure and utilities

This change introduces the foundational \inc\ directory structure, establishing the application's core configuration, database connectivity, and utility functions. It adds \config.inc.php\ to define global settings such as the session start, timezone, character encoding, and MySQL connection parameters (host, user, password, database, port). The \mysql.inc.php\ file provides functions to establish database connections, execute queries, and escape data to prevent SQL injection. Additionally, \function.php\ implements essential helpers including CAPTCHA generation (\vcode\, \vcodex\), CSRF token management, page redirection, and multiple session/cookie-based login verification methods for different application modules. The \showvcode.php\ script handles CAPTCHA display and storage, while \uploadfunction.php\ introduces a suite of file upload handlers with varying levels of validation, from basic MIME checks to strict verification using file extensions, MIME types, \getimagesize\, and size limits.

inc · high confidence

Initial release of Pikachu web security training platform with Docker support

This change introduces the initial version of Pikachu, a vulnerable web application designed for web security training and penetration testing practice. The release includes the core PHP application files (index, install, header, footer) covering vulnerabilities such as brute force, XSS, CSRF, SQL injection, and SSRF. It also adds a Dockerfile based on Ubuntu 20.04 with PHP 7.4, which pre-configures the environment by enabling remote file inclusion and error display, installing the 'expect' PHP extension, and allowing phpMyAdmin to log in with an empty password to facilitate specific attack scenarios. An Apache 2.0 license and updated README documentation are also included.

(repo-wide) · high confidence

Initial release of the pkxss XSS management backend

This change introduces the complete pkxss module, a PHP-based management interface for XSS (Cross-Site Scripting) testing. It includes a login system (pkxss\_login.php), a database initialization script (pkxss\_install.php) that sets up MySQL tables for storing results, and a main dashboard (xssmanager.php) to access three specific testing modules: cookie collection (xcookie), phishing/credential harvesting (xfish), and keylogging (rkeypress). The module relies on new configuration (config.inc.php) and database connection helpers (mysql.inc.php) to store and display captured data such as cookies, HTTP authentication credentials, and keystrokes.

pkxss · high confidence

Behavioural changes

1 commit (0 fixes) modifying wiki

A change to existing behaviour in wiki — 1 commit, 2 files.

wiki · medium confidence · unverified

Added IE-specific and extended Ace Admin CSS styles

The assets directory now includes \ace-ie.min.css\ and \ace-part2.min.css\. The new IE stylesheet provides compatibility fixes for Internet Explorer, such as disabling gradients and adjusting layout properties. The second stylesheet adds comprehensive styling for profile pages, email inbox components, data tables, calendar views, and form controls (Chosen/Select2).

assets · high confidence

Test coverage

Added test files for PHP environment and code execution

Added two new test files: \phpinfo.txt\ to display PHP environment information and \yijuhua.txt\ to write a PHP web shell (\yijuhua.php\) that executes system commands via a GET parameter.

test · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 32.

Lenses

  • Code Health 98
  • Architecture 100
  • Maturity 40
  • Readiness 17
  • Security 64
  • Accessibility 28

Changes since last survey

  • 70 commits — 67 feature/other, 3 fixes

By area

  • (root) — 47 commits
  • (repo) — 5 commits
  • vul/csrf — 4 commits
  • assets/js — 2 commits
  • inc/config.inc.php — 2 commits
  • inc/function.php — 1 commit
  • inc/showvcode.php — 1 commit
  • pkxss/inc — 1 commit
  • pkxss/pkxss_login.php — 1 commit
  • test/ser.php — 1 commit
  • test/test.php — 1 commit
  • vul/dir — 1 commit
  • vul/overpermission — 1 commit
  • vul/sqli — 1 commit
  • vul/xss — 1 commit

Notable commits

  • fix: Fix mysql connection
  • fix: Fix the try-catch block
  • fix: fix php label
  • change: 1.修复ssrf路径拼接,支持将pikachu直接放在根目录。 2.优化dockerfile,环境使用ubuntu20.04+php7,额外安装expect扩展解锁更多玩法。 3.配置php.ini,使其默认开启远程文件包含和报错提示。 4.使用dockerfile修改config.inc.php,不修改默认配置文件的情况下可以直接在docker容器中启动安装 5.允许phpmyadmin空密码登录,解锁更多攻击方式(如使用general_log写马)
  • change: 19/09/16 add dockerfile
  • change: Add inactivity badge to README
  • change: Create LICENSE
  • change: Create LICENSE
  • change: Delete ser.php
  • change: Delete test.php
  • change: FBI WARNING
  • change: Initial commit
  • change: Merge branch 'master' of https://github.com/zhuifengshaonianhanlu/pikachu
  • change: Merge pull request #1 from Anemone95/master
  • change: Merge pull request #25 from Zhniing/dev
  • change: Merge pull request #3 from zhuifengshaonianhanlu/add-license-1
  • change: Merge pull request #33 from 8023/master
  • change: Update README.md
  • change: Update README.md
  • change: Update README.md
  • …and 50 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

zhuifengshaonianhanlu/pikachu was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5e1e8d9d14a3ba61d62f28cf35531c4df4dd24fc — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.