zhuifengshaonianhanlu/pikachu
32.0
Weak · 19 September 2026
7.6k
lines of production code
PHP
primary language
1
measurement over time
What this system is
Pikachu is a vulnerable web application designed for web security training and penetration testing practice. It provides a PHP-based environment with Docker support that simulates various attack vectors, including XSS, SQL injection, CSRF, and brute-force attacks. The system includes dedicated modules for managing XSS testing scenarios and interactive labs for practicing authentication bypasses and request forgery exploits.
Features
Added brute-force and CSRF vulnerability labs
New interactive security training modules have been added to the vul directory, covering brute-force attack vectors (including form-based, client-side CAPTCHA bypass, server-side CAPTCHA bypass, and token-based protections) and Cross-Site Request Forgery (CSRF) scenarios (GET-based, POST-based, and token-protected forms). These files provide the frontend interfaces and backend logic for users to practice identifying and exploiting these specific authentication and request-forgery weaknesses.
vul · high confidence
Initial implementation of core application infrastructure and utilities
This change introduces the foundational \inc\ directory structure, establishing the application's core configuration, database connectivity, and utility functions. It adds \config.inc.php\ to define global settings such as the session start, timezone, character encoding, and MySQL connection parameters (host, user, password, database, port). The \mysql.inc.php\ file provides functions to establish database connections, execute queries, and escape data to prevent SQL injection. Additionally, \function.php\ implements essential helpers including CAPTCHA generation (\vcode\, \vcodex\), CSRF token management, page redirection, and multiple session/cookie-based login verification methods for different application modules. The \showvcode.php\ script handles CAPTCHA display and storage, while \uploadfunction.php\ introduces a suite of file upload handlers with varying levels of validation, from basic MIME checks to strict verification using file extensions, MIME types, \getimagesize\, and size limits.
inc · high confidence
Initial release of Pikachu web security training platform with Docker support
This change introduces the initial version of Pikachu, a vulnerable web application designed for web security training and penetration testing practice. The release includes the core PHP application files (index, install, header, footer) covering vulnerabilities such as brute force, XSS, CSRF, SQL injection, and SSRF. It also adds a Dockerfile based on Ubuntu 20.04 with PHP 7.4, which pre-configures the environment by enabling remote file inclusion and error display, installing the 'expect' PHP extension, and allowing phpMyAdmin to log in with an empty password to facilitate specific attack scenarios. An Apache 2.0 license and updated README documentation are also included.
(repo-wide) · high confidence
Initial release of the pkxss XSS management backend
This change introduces the complete pkxss module, a PHP-based management interface for XSS (Cross-Site Scripting) testing. It includes a login system (pkxss\_login.php), a database initialization script (pkxss\_install.php) that sets up MySQL tables for storing results, and a main dashboard (xssmanager.php) to access three specific testing modules: cookie collection (xcookie), phishing/credential harvesting (xfish), and keylogging (rkeypress). The module relies on new configuration (config.inc.php) and database connection helpers (mysql.inc.php) to store and display captured data such as cookies, HTTP authentication credentials, and keystrokes.
pkxss · high confidence
Behavioural changes
1 commit (0 fixes) modifying wiki
A change to existing behaviour in wiki — 1 commit, 2 files.
wiki · medium confidence · unverified
Added IE-specific and extended Ace Admin CSS styles
The assets directory now includes \ace-ie.min.css\ and \ace-part2.min.css\. The new IE stylesheet provides compatibility fixes for Internet Explorer, such as disabling gradients and adjusting layout properties. The second stylesheet adds comprehensive styling for profile pages, email inbox components, data tables, calendar views, and form controls (Chosen/Select2).
assets · high confidence
Test coverage
Added test files for PHP environment and code execution
Added two new test files: \phpinfo.txt\ to display PHP environment information and \yijuhua.txt\ to write a PHP web shell (\yijuhua.php\) that executes system commands via a GET parameter.
test · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 32.
Lenses
- Code Health 98
- Architecture 100
- Maturity 40
- Readiness 17
- Security 64
- Accessibility 28
Changes since last survey
- 70 commits — 67 feature/other, 3 fixes
By area
- (root) — 47 commits
- (repo) — 5 commits
- vul/csrf — 4 commits
- assets/js — 2 commits
- inc/config.inc.php — 2 commits
- inc/function.php — 1 commit
- inc/showvcode.php — 1 commit
- pkxss/inc — 1 commit
- pkxss/pkxss_login.php — 1 commit
- test/ser.php — 1 commit
- test/test.php — 1 commit
- vul/dir — 1 commit
- vul/overpermission — 1 commit
- vul/sqli — 1 commit
- vul/xss — 1 commit
Notable commits
- fix: Fix mysql connection
- fix: Fix the try-catch block
- fix: fix php label
- change: 1.修复ssrf路径拼接,支持将pikachu直接放在根目录。 2.优化dockerfile,环境使用ubuntu20.04+php7,额外安装expect扩展解锁更多玩法。 3.配置php.ini,使其默认开启远程文件包含和报错提示。 4.使用dockerfile修改config.inc.php,不修改默认配置文件的情况下可以直接在docker容器中启动安装 5.允许phpmyadmin空密码登录,解锁更多攻击方式(如使用general_log写马)
- change: 19/09/16 add dockerfile
- change: Add inactivity badge to README
- change: Create LICENSE
- change: Create LICENSE
- change: Delete ser.php
- change: Delete test.php
- change: FBI WARNING
- change: Initial commit
- change: Merge branch 'master' of https://github.com/zhuifengshaonianhanlu/pikachu
- change: Merge pull request #1 from Anemone95/master
- change: Merge pull request #25 from Zhniing/dev
- change: Merge pull request #3 from zhuifengshaonianhanlu/add-license-1
- change: Merge pull request #33 from 8023/master
- change: Update README.md
- change: Update README.md
- change: Update README.md
- …and 50 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
zhuifengshaonianhanlu/pikachu was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 5e1e8d9d14a3ba61d62f28cf35531c4df4dd24fc — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.