OWASP PenTestKit Automation Firefox

OWASP PenTestKit Automation

PTK Auto is the browser security runtime used by PTK Agent in automated tests, CLI workflows, CI/CD pipelines and supported browser-testing platforms.
xHeader
Modify request and response headers. No ads, no malware.

Features & Capabilities

PTK Auto is the browser automation companion for OWASP Penetration Testing Kit.

It provides the browser-side security runtime used by PTK Agent, automated tests, CI/CD pipelines and supported browser-testing platforms.

PTK Auto is controlled programmatically. It allows security checks to run inside the same browser session and user workflow created by Playwright, Puppeteer, Selenium, Cypress or another supported automation client.

Use PTK Auto to:

Add OWASP PTK security checks to existing browser automation. Test authenticated workflows using the browser state created by the automated scenario. Capture browser-generated requests and responses during a test. Run configured DAST checks against selected requests and parameters. Analyse loaded client-side code with PTK SAST. Observe security-relevant runtime behaviour with PTK IAST. Identify vulnerable client-side dependencies with PTK SCA. Return structured findings and evidence to the controlling automation client. Run security tests locally, in CI/CD or through supported hosted-browser platforms.

PTK Auto works with PTK Agent, published as pentestkit.

PTK Agent controls the browser and scan lifecycle, applies the selected security policy, collects results and produces reports. PTK Auto performs the browser-side inspection and testing inside the automated session.

PTK Auto is not the interactive version of OWASP PTK and does not provide the complete manual testing interface. Install the full OWASP PTK extension if you want to inspect traffic, launch scans, modify requests or test JWTs manually.

During an authorised scan, PTK Auto may inspect application traffic, page resources and browser behaviour required by the selected checks. Use a dedicated browser profile and test environment whenever possible.

Use PTK Auto only against applications where you have explicit authorisation. Active security testing can generate additional traffic, modify application data and trigger security monitoring.

User Growth & Download Statistics

Manifest V2 Add-on
By:
pentestkit.co.uk
Daily users:
1
Version:
9.9.8 Last updated: 2026-07-31
Version code:
6380630
Creation date:
2026-07-28
Risk:
Very high risk impact High risk likelihood
Permissions:
Content scripts matches:
  • <all_urls>
Size:
3.03MB
Email:
de*****@gmail.com
URLs:
Website
Full description:
See detailed description
Source:
Firefox Add-ons Store
Data ingested on:
2026-08-04
Compare stats and ranking:

Contact the developer

Chrome-Stats does not own this Firefox add-on. Please use these information below to contact the Firefox add-on developer.
Developed by:
pentestkit.co.uk
Firefox Add-ons Store
https://addons.mozilla.org/firefox/addon/owasp-pentestingkit-automation/
Email:
de*****@gmail.com
Website:
https://pentestkit.co.uk/

Is OWASP PenTestKit Automation Safe?

Risk impact
Risk impact measures the level of extra permissions an extension has access to. A low risk impact extension cannot do much harms, whereas a high risk impact extension can do a lot of damage like stealing your password, bypassing your security settings, and accessing your personal data. High risk impact extensions are not necessarily malicious. However, if they do turn malicious, they can be very harmful.

OWASP PenTestKit Automation requires a lot of sensitive permissions. Exercise caution before installing.

Risk impact analysis details
  • Critical Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
  • Critical ****** ****** ** ******* ***** ***** *** ** **** ** ***** **** ******** ****** *** ******** ********** * ******* ********
  • High ****** *** ********* ** ******* *** ******* ******* ** ****** *** *** ******** ******
  • High ****** ********* ** * ****** ******** ******** ********** * ******* ******* *****
  • High ******* ******* **** *** ****** ***** *** ***** ** ******* **** ********* ********* ** * *********** *****
Risk likelihood
Risk likelihood measures the probability that a Firefox add-on may turn malicious. This is determined by the publisher and the Firefox add-on reputation on Firefox Add-ons Store, the amount of time the Firefox add-on has been around, and other signals about the Firefox add-on. Our algorithms are not perfect, and are subject to change as we discover new ways to detect malicious extensions. We recommend that you always exercise caution when installing a Firefox add-on.

OWASP PenTestKit Automation is recently added, and hasn't been around long enough for us to gather enough data to accurately assess its risk level.

Risk likelihood analysis details
  • High This extension was recently updated in the past month. New updates may not be stable or safe.
  • High **** ********* *** ******** ****** *** ********** *** *** ** ****** ** *****
  • High **** ********* *** *** **** ****** ********* ********** *** *** ** ****** ** *****
Extension Guard
Extension Guard

Discover every extension in use, analyze risks, and enforce blocking policies with Extension Guard

Secure Your Browser
Upgrade to see full risk analysis details

Best OWASP PenTestKit Automation Alternatives

Here are some Firefox add-ons that are similar to OWASP PenTestKit Automation: