Paid tier existsAll levelsRarely updated

Specifications

Specifications
FormatLearning
LevelBeginner, Intermediate, Advanced
PricePaid tier exists
AccessNo registration
ActivityRarely updated
LanguageEN
CategorySecure code

Training on writing secure code, organised around the OWASP Top 10 for web and API plus LLM topics. The OWASP exercises stay open without an account; audit and reporting moved behind an enterprise plan after the Security Compass acquisition. No exercise counter is published.

Pros & cons

Pros

  • Short exercises, each closable in one sitting
  • LLM security blocks that most course material still skips
  • The OWASP track is open, no account and no request

Cons

  • The audit and reporting side is enterprise after the Security Compass move
  • Exercises check the rule, not your code: nothing runs against a real app
  • Topic cadence has slowed to the point where the catalogue looks maintained, not grown

Who it fits

Suits a developer who knows what XSS is but has never worked through the OWASP list end to end. The exercises point at the line where the flaw enters your code, not at the flaw name again.

Getting started

  1. Work the free OWASP Top 10 track from the first module to the last
  2. Take the LLM track next: those topics appear least in older material
  3. Keep the rule list next to your editor and run it against your own code

History

Kontra ran as an independent training site before joining Security Compass, and much of what was open moved to an enterprise plan with that change. The free OWASP exercises stayed available. New topics arrive slowly, so the catalogue reads as maintained, not growing. Checked.