When I saw the first description of the project I though that the benchmark was checking how many WebGoat issues where discovered But this looks like it has a difference code base, is that correct?