OWASP Penetration Testing Kit icon

OWASP Penetration Testing Kit

Extension Actions

CRX ID
knjnghhnhcpcglfdjppffbpfndeebkdm
Status
  • Extension status: Featured
Description from extension meta

OWASP Penetration Testing Kit

Description from store

The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application.

Key Features:

Runtime Scanning (DAST & IAST & SAST & SCA):
Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats.

Static Analysis (SAST):
PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like `eval()`, `innerHTML`/`outerHTML` injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns.

In-Browser IAST (Interactive Application Security Testing):
PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe `eval`/`innerHTML` usage, open-redirects, and more without leaving your dev tools.

JWT Inspector:
Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious `jwk`, `jku`, or `kid` parameters.

Insightful Application Info:
One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows.

Built-in Proxy & Traffic Log:
Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection.

R-Builder for Request Tampering & Smuggling:
Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export.

Cookie Management:
Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor.

Decoder/Encoder Utility:
Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats.

Swagger.IO Integration:
Browse and interact with API endpoints directly from your Swagger documentation.

Selenium Integration:
Shift left security by running automated Selenium tests with built-in vulnerability checks.

Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!

Latest reviews

luix
I really recommended this extension because of its professionalism
ASDASXD
Indeed this extension is very professional
fddssxz
Wow this extension is an extraordinary
finix
Request Attacker in OWASP PTK deserves applause for its prowess in finding XSS and SQL Injection.
iyanu
I really like the professionalism of this extension.
jehu
Request Builder is a brilliant addition to the extension. Makes modified requests a piece of cake.
mercy
JWT Inspector is a go-to tool for token security. User-friendly and powerful.
anitap
JWT Inspector is a standout in the OWASP PTK. Simple, effective, and crucial for JWT security.
gideon
SCA scan with reporting is like having a security superhero. Thorough and impactful.
amond
SCA scan with reporting in OWASP PTK is a powerful tool for identifying and addressing security concerns.
abraham
JWT Inspector is a reliable companion for checking token security. Streamlined and effective.
peculiar
Request Builder is a must-have for crafting and testing modified requests. User-friendly and powerful.
faith
Request Builder is a dream for executing modified requests. OWASP PTK nailed it with this one!
sexxy
JWT Inspector is a standout in the OWASP PTK. Simple, effective, and crucial for JWT security.
william
This extension was such an amazing
sandy
Request Attacker is top-notch in identifying XSS and SQL Injection. A real game-changer for app security.
hitton
Request Builder makes crafting modified requests a breeze. Kudos to OWASP for the user-friendly design.
ejec
JWT Inspector in this extension is fantastic for securing token-based authentication. Easy to use, highly recommended!
enya
SCA scan with reporting is stellar. A must for anyone serious about application security.
emma
Good extension and i like how it works.
eric
Best extension i have used so far.
gideon
PTK's ability to swiftly detect SQL Injections is impressive, providing a robust defense against a common yet critical vulnerability.
Thailand
Half the functions do not work but after installing it somebody remotely tried to access my personal data on twitter and my accoun t was hacked. I assume it to be the developer of this extension through using it to send the personal data of users tohimself. A hack disguised as a hacking tool, which is common when noobies seek hacking tools without knowledge. hired a Singaporean Pentesting company to check out this extension to find out of ;legit or not. Most extensions are mere browser links to webapps anyway (dynamic obm based websites)m, so browser extensions have always been a load of rubbish ever since the days of Mozillla
Johnson,
so far its good but the micro is a bit broke for some webs but all in all i like it good job brother :} i would recommend this an try it out with others