OWASP Penetration Testing Kit

OWASP Penetration Testing Kit (PTK) is an open-source browser extension for testing web applications from the live browser session where they actually run.

PTK combines DAST, client-side SAST, in-browser IAST, SCA, traffic inspection, request replay, and JWT testing. It can test authenticated applications and single-page applications using the application state, traffic, and client-side code visible to the browser.

PTK provides its own extension interface. It does not use browser DevTools and does not require traffic to be routed through a separate desktop proxy for its normal testing workflows.

About OWASP Penetration Testing Kit

Why browser context matters

Many security tools begin outside the application and must reconstruct authentication, navigation, and application state. PTK starts from the browser session already being used by the tester. It can work with the authenticated user context, cookies, tokens, SPA routes, loaded JavaScript, DOM state, and browser-generated API traffic. This makes PTK particularly useful for testing authenticated workflows, single-page applications, and client-side behaviour.

Project Leaders

Denis Podgurskii

Project Leader

Email

Project Information

Production Project
Classification
Tool
Language
JavaScript
License
GNU Affero General Public License v3.0
Contributors
8
GitHub Stars
247
Downloads
59
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.