OWASP Penetration Testing Kit icon

OWASP Penetration Testing Kit

Extension Actions

CRX ID
ojkchikaholjmcnefhjlbohackpeeknd
Description from extension meta

OWASP Penetration Testing Kit

Image from store
OWASP Penetration Testing Kit
Description from store

The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application.

Key Features:

Runtime Scanning (DAST & IAST & SAST & SCA):
Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats.

Static Analysis (SAST):
PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like `eval()`, `innerHTML`/`outerHTML` injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns.

In-Browser IAST (Interactive Application Security Testing):
PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe `eval`/`innerHTML` usage, open-redirects, and more without leaving your dev tools.

JWT Inspector:
Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious `jwk`, `jku`, or `kid` parameters.

Insightful Application Info:
One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows.

Built-in Proxy & Traffic Log:
Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection.

R-Builder for Request Tampering & Smuggling:
Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export.

Cookie Management:
Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor.

Decoder/Encoder Utility:
Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats.

Swagger.IO Integration:
Browse and interact with API endpoints directly from your Swagger documentation.

Selenium Integration:
Shift left security by running automated Selenium tests with built-in vulnerability checks.

Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!

Latest reviews

Dan Cristino
Works on Chrome and other Chrome-based browsers. Sadly, won't work on Arc browser :(
Przemysław Samsel
Helpful stuff thanks!
gideon adavize
Wonderful extension
Andasin
Wonderful and amazing extension
Danmiest4k
JWT Inspector in this extension is fantastic for securing token-based authentication. Easy to use, highly recommended!
Hallam Stoned
Request Builder is a dream for executing modified requests. OWASP PTK nailed it with this one!
iyanu
Request Attacker impresses with its ability to find XSS and SQL Injection. OWASP PTK, you've got a winner!
Jehujese
Request Builder is a straightforward solution for modified requests. OWASP PTK made it user-friendly.
Kathy Phil moser
Request Builder is a dream for executing modified requests. OWASP PTK nailed it with this one!
linbest
Request Builder is a game-changer for crafting and testing modified requests. Kudos!
mercyline
Request Attacker deserves praise for its efficiency in finding XSS and SQL Injection.
Mercytonia
SCA scan with reporting in OWASP PTK is a solid tool. Comprehensive insights for enhanced security.
Obanyi obi
JWT Inspector is a reliable choice for checking token security. Easy to use and effective.
Raymond Joel
Request Builder is a user-friendly solution for executing modified requests. Thumbs up!
Raymond akubo
Request Attacker makes identifying XSS and SQL Injection vulnerabilities effectively.
Samuel Gabriel
SCA scan with reporting is a valuable asset for comprehensive security checks.
Sophie Lucky
JWT Inspector is a standout for JWT security. A crucial tool for secure authentication.
William Sinwill
Request Builder simplifies the process of executing modified requests. Well-designed and efficient.
Gideonozi
What a powerful extension i really love using it.
Gideon Obanyi
SCA scan with reporting is stellar. A must for anyone serious about application security.
Gery Smith
Request Attacker nails it for finding XSS and SQL Injection. Solid tool for boosting app security.
George akuboh
Wow this extension is the best that i have ever used so far.
Creative Finix
Request Builder is a gem in the OWASP PTK, simplifying modified requests. Perfect for testing app resilience.
Tatiana
OWASP Pen Testing Kit's JWT Inspector is a lifesaver for checking token security. User-friendly and effective.
Jeyboy
This extension is truely outstanding
Rominado
I found two SQL injection was found just while crawing my app
emmasome
Nice tools it really amazing
Roseline
This is a great and amazing extension
Chico GPT
like a mini Burp Suite,
Chico GPT
like a mini Burp Suite,
Bug Bounty
Great tool! Like in-browser Burp.
Bug Bounty
Great tool! Like in-browser Burp.
Benewendel Freitas
Infelizmente a ferramenta não funciona como se propõe. Varias funcionalidades não entregam o que deveriam ou apresentam Bugs.
Anthony Mcqueen
I have used many tools some were good while others were just all hype. This tool was okay there are still some issues for me personally i am having. I hope i can fix these issues so i can continue to hunt for those bugs that are critical.
Anthony Mcqueen
I have used many tools some were good while others were just all hype. This tool was okay there are still some issues for me personally i am having. I hope i can fix these issues so i can continue to hunt for those bugs that are critical.
Dan Ramirez
no funciona al hacer clic en la extensión
Geraldine Tatuada
Nice
Geraldine Tatuada
Nice
Blas Jose Manuel Lara Alt Cortés
great
Jose Manuel Lara Cortes
great
Julian Molloy
Wow! awesome yet simple effective tool.
Julian Molloy
Wow! awesome yet simple effective tool.
初七
great job
初七
great job
Petro Krasnomovets
Great extension!
Petro Krasnomovets
Great extension!
John Wick
Великолепное дополнение от создателей metasploit
Bob Lerner
We use this internally to enable customers to authenticate to their applications with complex mechanisms. This extension has been a game changer.
Bob Lerner
We use this internally to enable customers to authenticate to their applications with complex mechanisms. This extension has been a game changer.
Carl Castin
great