PortSwigger Web Security Academy

Visit platform ↗

Paid tier existsAcademyAll levelsActive

Specifications

Specifications
FormatLearning
LevelBeginner, Intermediate, Advanced
PricePaid tier exists
AccessNo registration
ActivityActive
LanguageEN
CategoryWeb

The web pentesting academy run by the makers of Burp Suite, working through the OWASP list topic by topic, from recon to business logic flaws. Practice happens in labs on deliberately vulnerable applications. Learning is free; the exam at the end is not.

Pros & cons

Pros

  • Walks the full OWASP web list in an order that makes sense
  • Labs annotate the request and response that actually matter
  • Free and open: no account needed to reach any topic

Cons

  • The certificate needs an active Burp Suite Professional subscription
  • Web applications only, nothing on networks, Active Directory or binaries
  • Community solutions are uneven: some labs have a dozen writeups, some have none

Who it fits

Suits anyone moving into web security: it closes the gap between knowing a vulnerability name and testing for it. Finish the whole path even without the exam.

Getting started

  1. Do Access Control and SQL injection first, they set up everything after them
  2. Solve each lab in Burp Suite Community, the paid licence is not needed
  3. Keep a table: vulnerability, where you met it, how you confirmed it

History

Grew out of PortSwigger Research writing and became the reference most web testers cite. New topics arrive as new bug classes surface in breach reports, so the syllabus tracks what is actually being exploited rather than a fixed curriculum.