PortSwigger Web Security Academy
Free web security training with hundreds of interactive labs from the makers of Burp Suite.
Technical Architecture & Overview
The Web Security Academy offers free structured materials and hands-on labs covering SQL injection, XSS, CSRF, access control, race conditions, GraphQL, and modern API attacks, with content maintained by the Burp Suite team. Labs run in the browser against hosted instances, and solutions are available when stuck. Content updates track current web attack techniques.
Targeted Technical Use Cases
Learning web exploitation systematically, whether or not you use Burp Suite professionally.
Evaluation & Trade-offs
Core Strengths
- +Lab quality and topic currency from a specialist vendor.
- +Completely free, no trial limits.
- +Progress tracking across a large curriculum.
Trade-Offs & Limitations
- -Web security only.
- -Some labs assume Burp Suite familiarity.
Defensive Security Application
Building the web attack literacy that application defenders and code reviewers need.
Frequently Asked Questions
What is PortSwigger Web Security Academy?→
The Web Security Academy offers free structured materials and hands-on labs covering SQL injection, XSS, CSRF, access control, race conditions, GraphQL, and modern API attacks, with content maintained by the Burp Suite team. Labs run in the browser against hosted instances, and solutions are available when stuck. Content updates track current web attack techniques.
What is PortSwigger Web Security Academy used for?→
Learning web exploitation systematically, whether or not you use Burp Suite professionally.
What are the strengths of PortSwigger Web Security Academy?→
- +Lab quality and topic currency from a specialist vendor.
- +Completely free, no trial limits.
- +Progress tracking across a large curriculum.
What are the limitations of PortSwigger Web Security Academy?→
- +Web security only.
- +Some labs assume Burp Suite familiarity.
How is PortSwigger Web Security Academy used defensively?→
Building the web attack literacy that application defenders and code reviewers need.