So what are the chances of someone who's never really dealt with web security capturing the flag? Last year's results don't make it seem too promising, 12k unique IP's -> 250 captures.
We hope that people new to web security can solve the first few levels with some work and inspection, and the later levels with hints from others or a significant amount of research into the topics.
At the end of the day, the point of the exercise is to expose realistic vulnerabilities for fun and education. We try to make them similar to how they'd be in the wild.
In the first Stripe CTF, I played for the first 3 levels, learned some things, then stopped. But I considered it a success for myself. I'm sure others did similar things.
Capturing the flag wasn't something most people could do in a short time, so having 250/12k even accomplish it I'd think was a rather high conversion rate.