Penetration Testing Kit Firefox

Penetration Testing Kit

Attention! This version is no longer supported. Use /firefox/addon/owasp-penetration-testing-kit/ extension instead.

Features & Capabilities

The Penetration Testing Kit (PTK) is a comprehensive browser extension designed to streamline application security testing for penetration testers, Red Teams, and security practitioners.

Features include in-browser Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA), powerful JWT inspection and manipulation, a proxy with traffic logging, and the R-Builder tool for advanced HTTP request tampering including request smuggling. Additional utilities such as cookie management and encoder/decoder tools further enhance your workflow. Integrated with Swagger.IO and Selenium, PTK supports API security assessments and early-stage vulnerability detection. Note: This Chrome extension version is no longer supported; users are advised to switch to the Firefox alternative.

Upgrade your application security process with PTK’s all-in-one capabilities, helping uncover complex vulnerabilities and optimize testing efficiency.

User Growth & Download Statistics

Contact the developer

Chrome-Stats does not own this Firefox add-on. Please use these information below to contact the Firefox add-on developer.
Developed by:
pentestkit.co.uk
Firefox Add-ons Store
https://addons.mozilla.org/firefox/addon/penetration-testing-kit/
Email:
de*****@gmail.com
Website:
https://pentestkit.co.uk/

Permission Change History

2022-09-24: Version 8.1.2 → 8.2.2
Add Permissions: scripting
2022-08-01: Version 7.5.2 → 8.1.2
Add Permissions: unlimitedStorage

User Reviews

The OWASP Penetration Testing Kit is praised for its powerful features, unique functionality, and especially the user-friendly Request Builder ideal for penetration testers. Users report it greatly improves productivity and meets expectations. However, multiple reviews mention concerns about the extension requesting permissions to read all webpage inputs, including sensitive data. There are also recurring issues with the extension initially showing a blank window or failing to open, requiring reinstallations or time to load, indicating possible bugs that need addressing.
Pros
  • Powerful and greatly improves productivity of penetration testers
  • User-friendly Request Builder for testing modified requests
  • Unique and very useful functionality
  • Meets user expectations and works great
  • Considered a great and awesome extension by users
Cons
  • Asks for permission to read all information filled on webpages, including sensitive data
  • Initial loading issues causing the extension to show a blank window
  • Some users experienced bugs preventing opening the extension on Firefox, requiring reinstall or waiting for fixes
Recent reviews
by Ha*****, 2025-05-07

by 敬念*****, 2025-02-19

by Ma*****, 2024-09-16
View all user reviews ›

Is Penetration Testing Kit Safe?

Risk impact
Risk impact measures the level of extra permissions an extension has access to. A low risk impact extension cannot do much harms, whereas a high risk impact extension can do a lot of damage like stealing your password, bypassing your security settings, and accessing your personal data. High risk impact extensions are not necessarily malicious. However, if they do turn malicious, they can be very harmful.

Penetration Testing Kit requires some sensitive permissions that could impact your browser and data security. Exercise caution before installing.

Risk impact analysis details
  • Critical Allows access to all websites, posing a significant security risk as it can monitor and modify data from any visited site.
  • Critical ****** ****** ** ******* ***** ***** *** ** **** ** ***** **** ******** ****** *** ******** ********** * ******* ********
  • High ****** *** ********* ** ******* *** ******* ******* ** ****** *** *** ******** ******
  • High ******* ******* **** *** ****** ***** *** ***** ** ******* **** ********* ********* ** * *********** *****
  • Medium ******* ******* ************* ***** *** ** ******* *** **** ******* ****** ******** *******
Risk likelihood
Risk likelihood measures the probability that a Firefox add-on may turn malicious. This is determined by the publisher and the Firefox add-on reputation on Firefox Add-ons Store, the amount of time the Firefox add-on has been around, and other signals about the Firefox add-on. Our algorithms are not perfect, and are subject to change as we discover new ways to detect malicious extensions. We recommend that you always exercise caution when installing a Firefox add-on.

Penetration Testing Kit is probably trust-worthy. Prefer other publishers if available. Exercise caution when installing this add-on.

Risk likelihood analysis details
  • High This extension has low user count. Unpopular extensions may not be stable or safe.
  • Low **** ********* *** ******* **** **** * ****** **** ***** ******** *** **** ****** ** ** ****** *** *****
  • Low **** ********* *** ***** **** **** * ****** **** ***** ********** *** **** ****** ** ** ****** *** *****
  • Good **** ********* *** **** **** *******
Extension Guard
Extension Guard

Discover every extension in use, analyze risks, and enforce blocking policies with Extension Guard

Secure Your Browser
Upgrade to see full risk analysis details

Best Penetration Testing Kit Alternatives

Here are some Firefox add-ons that are similar to Penetration Testing Kit: