A deliberately vulnerable Representational State Transfer (REST) API built with PHP and MySQL.
All who are interested in REST API. Developers, security professionals, students, instructors etcetera.
Version 1.0 is already out with basic features. You can get it from download page.
In security testing labs. Using it in a public facing server or production environment is more or less like installing a back-door to your system.
The server part of the code can be run on any system that supports PHP and MySQL. The web client can be used from any web browser and there is also an Android application available. However, you are free to write your own client for other platforms.