Secure-code-review platform

Find the vulnerability.
Write the fix.

A white-box training ground: read real vulnerable code in eleven languages, mark the lines that bite, and explain the flaw in your own words — graded on meaning, in any language.

5 labs free·80+ challenges·AI-graded

The Arena

Real CVEs and planted bugs in readable code. Flag the lines, then defend your reasoning in prose.

The Academy

Long-form write-ups that turn each class of flaw into something you recognise on sight — OWASP Top 10 through COBOL and Fortran.

Semantic Assessment

Explain the vulnerability your way. Claude grades meaning, not keywords — a hundred phrasings, one correct answer.

How an audit works

Read · Flag · Explain
  1. 01

    Read the source

    Open a real, vulnerable file in the read-only editor. No setup, no VM — just code.

  2. 02

    Flag the lines

    Click the line numbers where the flaw lives. Contiguous sinks count as one region.

  3. 03

    Explain & unlock

    Describe the bug and its fix. Pass, and the exploit payload is revealed as your reward.

Simple pricing

Start free · upgrade when hooked

Free

$0

The first 5 labs, forever.

Eleven languages, one discipline
GoRustNode.jsC#CC++AssemblyPerlCOBOLFortranFlutter

The vulnerable line is easy to find.
Explaining why — that's the craft.

VulnArena — a journal of secure code review Set in Source Serif 4 · Inter · JetBrains Mono