The Template Injection Playground allows to test a large number of the most relevant template engines for template injection possibilities.
69
stars
32
commits
PHP
primary language
Apr 29, 2026
updated
With the Template Injection Playground a large number of the most relevant template engines (as of September 2023) can be tested for template injection possibilities. For this purpose, simple web pages are provided, each of which uses one of the template engines. Furthermore, various optional security measures such as sandboxes, encodings, and denylists can be activated.
The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand.
docker compose builddocker compose upError starting userland proxy: listen tcp4 127.0.0.1:13370: bind: address already in use
13370 to any free port for the service nginx.Secure Connection Failed, This site can’t provide a secure connection or something similar.
http:// and not https:// when accessing the playground.nginx: [emerg] host not found in upstream "FOO" in /etc/nginx/nginx.conf:BAR
docker compose up again.A blog post providing more information about template injection and TInjA – the Template INJection Analyzer can be found here:
Template Injection Vulnerabilities – Understand, Detect, Identify
The Template Injection Playground was developed as a part of a master's thesis by Maximilian Hildebrand. You can find results of the master's thesis publicly available here:
The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand as a part of his master's thesis. The Template Injection Playground is licensed under the Apache License, Version 2.0.
PHP
24.8%
JavaScript
23.2%
Elixir
17.4%
HTML
16.4%
Blade
8.0%
C#
2.2%
Java
2.0%
Python
1.5%
Ruby
1.4%
CSS
1.4%
The Template Injection Playground allows to test a large number of the most relevant template engines for template injection possibilities.
69
stars
32
commits
PHP
primary language
Apr 29, 2026
updated
With the Template Injection Playground a large number of the most relevant template engines (as of September 2023) can be tested for template injection possibilities. For this purpose, simple web pages are provided, each of which uses one of the template engines. Furthermore, various optional security measures such as sandboxes, encodings, and denylists can be activated.
The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand.
docker compose builddocker compose upError starting userland proxy: listen tcp4 127.0.0.1:13370: bind: address already in use
13370 to any free port for the service nginx.Secure Connection Failed, This site can’t provide a secure connection or something similar.
http:// and not https:// when accessing the playground.nginx: [emerg] host not found in upstream "FOO" in /etc/nginx/nginx.conf:BAR
docker compose up again.A blog post providing more information about template injection and TInjA – the Template INJection Analyzer can be found here:
Template Injection Vulnerabilities – Understand, Detect, Identify
The Template Injection Playground was developed as a part of a master's thesis by Maximilian Hildebrand. You can find results of the master's thesis publicly available here:
The Template Injection Playground was developed by Hackmanit and Maximilian Hildebrand as a part of his master's thesis. The Template Injection Playground is licensed under the Apache License, Version 2.0.
PHP
24.8%
JavaScript
23.2%
Elixir
17.4%
HTML
16.4%
Blade
8.0%
C#
2.2%
Java
2.0%
Python
1.5%
Ruby
1.4%
CSS
1.4%