Cross-browser extension Penetration Testing Kit

Joined May 2021
14 Photos and videos
Great for anyone interested in browser-side security testing, SAST, and modern web application security. youtu.be/uUUAm4U9tA8
1
1
176
If you use @browserling for cross-browser testing, you can also add a lightweight security testing layer with OWASP PTK. Watch the demo.
2
2
210
๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐—ฎ๐˜ƒ๐—ฎ๐—ถ๐—น๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฎ๐˜€ ๐—ฎ๐—ป ๐—ป๐—ฝ๐—บ ๐—ฝ๐—ฎ๐—ฐ๐—ธ๐—ฎ๐—ด๐—ฒ Instead of treating browser security testing as a separate manual activity, teams can now run PTK-backed scans as part of automation. npmjs.com/package/pentestkit

21
I wrote a scenario like a prompt, hit runโ€ฆ and Codex just did the job. Playwright is driving the browser. OWASP PTK is turning it into real DAST/IAST findings. It even solved a math captcha on its own. This is what crawling should look like. youtu.be/UjjrxENjyEg
85
pentestkit retweeted
Like half a million of those runs were me ๐Ÿ˜‚
1
2
139
OWASP PTK ZAP
1
1
256
PTK 9.8.0 with auto-discovery is out and I tested it on burpbountylab.com/ 10 XSS first. Same workflow auto-discovery. 32 high-severity findings across XSS SQLi. Video: youtu.be/bdC-hZ79kDk #AppSec #BugBounty #XSS #SQLi #DAST

2
101
๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž ๐Ÿต.๐Ÿณ.๐Ÿฌ is out for Chromium and Firefox This release is all about improving the ๐—ฏ๐˜‚๐—ด ๐—ฏ๐—ผ๐˜‚๐—ป๐˜๐˜† ๐˜‚๐˜€๐—ฒ๐—ฟ ๐—ฒ๐˜…๐—ฝ๐—ฒ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฐ๐—ฒ. See how SAST can find hidden routes!
2
29
๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž ๐Ÿต.๐Ÿฒ.๐Ÿฌ ๐—ถ๐˜€ ๐—ผ๐˜‚๐˜ - a reporting correlation focused release. This version is all about turning scan output into something you can actually share, triage, and act on. pentestkit.co.uk/release_notโ€ฆ

12
๐—ญ๐—”๐—ฃ ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž as a browser-based AppSec tool is a pretty powerful combo. Iโ€™m really excited to share a major milestone for OWASP PTK: the ๐—ข๐—ช๐—”๐—ฆ๐—ฃ ๐—ฃ๐—ง๐—ž ๐—ฎ๐—ฑ๐—ฑ-๐—ผ๐—ป ๐—ณ๐—ผ๐—ฟ ๐—ญ๐—”๐—ฃ is now released. zaproxy.org/blog/2026-01-19-โ€ฆ
3
5
496
PWASP PTK 9.5.0 has been released: JWT attacks improved: fixed false positives for alg=none checks and better handling of public/unauthenticated endpoints. SPA attacks support: improved attack flow for modern single-page applications. UI performance and bug fixes.
34
26 May 2025
OWASP PTK v.9.1.0/1 has just been released with a full house appsec tools: - DAST (Dynamic Application Security Testing) - IAST (Interactive Application Security Testing) - SAST (Static Application Security Testing) - SCA (Software Composition Analysis)
38
14 May 2025
Meet first in class in-browser IAST agent for JavaScript! In OWASP PTK v9, weโ€™ve introduced an integrated IAST capability to help surface client-side issues immediately: *Taint-Flow Visibility *Contextual Findings *Zero-Configuration Deployment
28