Security hardening, improved scan reliability, Request Builder updates, and safer extension automation
OWASP PTK 9.9.8 improves the security of the extension UI, strengthens DAST and IAST reliability, modernizes Request Builder internals, and improves coordination with ZAP-managed browser scans.
- Added attack-surface recommendations based on evidence collected by DAST, SAST, and IAST.
- Added dedicated DAST request-capture storage for more reliable request and response evidence.
- Added a structured Request Builder model, transport layer, multipart encoder, and raw HTTP codec.
- Added stronger build and distribution validation to distinguish full-extension artifacts and verify their packaged contents.
- Improved DAST baseline handling for mutable or changing requests. PTK can safely reuse captured browser evidence when replaying a request does not produce a stable baseline.
- Improved Request Builder parsing, request reconstruction, multipart handling, and exact-origin request execution.
- Improved DAST, IAST, SAST, and SCA result finalization so completed scans and generated reports use consistent engine results.
- Improved JWT handling and restored reliable token loading from the active page's cookies and browser storage.
- Improved SAST payload validation so source collected for one document cannot be attributed to a different document URL.
- Improved SAST offscreen initialization failure handling.
- Improved ZAP-managed session coordination and shutdown so pending PTK engine work and findings can drain before the browser closes.
- Improved regression coverage across DAST, SAST, IAST, JWT, Request Builder, reporting, extension distribution, and ZAP automation.
- Fixed a malicious-cookie HTML injection and cross-site scripting issue tracked as GHSA-8xq3-9xpx-v2cc.
- Cookie, header, technology, CVE, session, report, and decoded-JWT values are now safely encoded before being inserted into HTML-backed extension views.
- IAST buffered findings are now stored in bounded, tab/frame-scoped extension storage rather than the scanned website's
localStorage. - Added acknowledgements, duplicate suppression, ownership validation, and scan-stop cleanup for buffered IAST findings.
- Updated security-sensitive dependencies and applied additional static-analysis hardening.
- Removed an unused remotely hosted PDF-viewer code path so Manifest V3 extension functionality remains self-contained.
- Added a fail-closed artifact check that rejects remotely hosted executable code.
This release focuses on safer handling of website-controlled data, more dependable scan evidence, and better consistency between interactive PTK scans, reports, and ZAP-managed browser sessions.
PTK 9.9.7 focuses on making ZAP-managed automation reliable enough for release, while reducing browser permissions and tightening callback-data handling.
- Reworked ZAP automation startup around an explicit controller-driven lifecycle for active scan rule and legacy spiderClient workflows.
- Removed the browser
historypermission from Chromium and Firefox builds. - Redacted ZAP callback URLs, callback secrets,
zapid, and session keys from runtime/logging paths. - Improved ZAP browser close/readiness handling so PTK findings are drained before managed browsers close.
- Improved multi-browser DAST, IAST, and SAST participation evidence for ZAP automation.
- Fixed SPA route tracking reliability, restoring Juice Shop hash-route and DOM XSS coverage after longer journeys.
- Hardened PTK Agent/npm activation, drain/export finalization, and installed-package validation.
- Reduced noisy ZAP add-on INFO logging while preserving release-gate lifecycle evidence.
- Added a structured pentester guide under
docs/guide, covering installation, workflows, scanning engines, manual tools, reporting, automation, ZAP integration, and troubleshooting. - Updated security-related npm dependencies.
- Juice Shop smoke test passed with required DAST, IAST, and SAST findings.
- ZAP active-scan-rule Firing Range matrix passed with no regressions.
- ZAP legacy spiderClient Firing Range matrix passed with no regressions.
- npm release matrix passed across packaged/installed flows.
-
ZAP automation reliability
- Hardened PTK/ZAP browser automation close handling so PTK-created child tabs can close without stopping the whole scan session.
- Improved target scoping so automation only attaches to the intended scan target and PTK-created child tabs, not unrelated tabs opened manually during a scan.
- Improved multi-browser Edge and Firefox automation behavior for ZAP client-spider and browser-driven scan workflows.
- Split diagnostic browser-coverage tooling out of the production ZAP add-on build while keeping production automation leaner.
-
AngularJS and browser XSS coverage
- Improved AngularJS client-side template injection coverage, including
$parse, form, postMessage, storage, cookie, and raw-body style sources. - Added safer AngularJS template-marker checks for contexts where execution-style probes caused noisy framework errors.
- Improved browser-nav XSS confirmation and payload handling across reflected HTML, attribute, JavaScript, SVG, and Angular contexts.
- Reduced duplicate and low-signal XSS noise so confirmed findings are easier to review.
- Improved AngularJS client-side template injection coverage, including
-
DAST accuracy fixes
- Fixed JWT
alg=nonefalse positives where header-based JWT behavior could be reported as a cookie finding. - Tightened JWT carrier validation so cookie and header findings require evidence from the expected location.
- Improved source probing so scan checks are more transactional and avoid mutating shared authentication/session state.
- Fixed JWT
-
SAST and IAST improvements
- Expanded DOM source, propagation, and sink coverage for browser APIs such as location, hash, storage, postMessage, DOM writes, navigation, and form actions.
- Improved SAST reporting for web-message flows into HTML sinks, including clearer taint-flow findings where
messageevent data reaches dangerous DOM APIs. - Improved IAST/SAST collection for PTK-created browser-nav child tabs while keeping unrelated manual tabs out of active scan scope.
- Refined rulepack coverage across free and Pro DAST/SAST/IAST modules to keep shared fixes aligned.
-
Agent SDK and npm workflows
- Added and hardened
ptk-scan/ PTK Agent SDK workflows for running browser-extension scans from local automation. - Added scenario and no-scenario scan paths, matrix-style validation, and provider-oriented workflows for Codex, OpenCode, and non-agent runs.
- Improved report export handling for larger agent/npm scan outputs.
- Added and hardened
-
Packaging and release validation
- Updated the browser extension to version 9.9.5.
- Added release helper scripts and documented release-test workflows for extension rebuilds, ZAP add-on rebuilds, ZAP automation checks, smoke tests, agent matrices, and npm matrices.
- Refreshed extension and ZAP add-on rulepack resources for the 9.9.5 release line.
This release focuses on stabilizing PTK under real browser automation, improving AngularJS and DOM taint coverage, and fixing accuracy regressions found during release testing. PTK 9.9.5 makes ZAP-managed Edge/Firefox scans more predictable, keeps manual browser tabs out of scan scope, improves JWT and web-message reporting accuracy, and adds stronger local Agent SDK/npm workflows for repeatable release validation.
-
Automation reliability
- Improved PTK/ZAP browser automation startup and runtime selection with a background-owned automation profile and a smaller content bootstrap.
- Improved Chrome, Edge, and Firefox automation session coordination, progress handling, and shutdown behavior for more reliable one-browser and multi-browser runs.
- Added safer Codex/Playwright Agent SDK automation paths for direct scan, crawl, and export workflows, including scenario-guided crawling and planner-only crawl assistance.
-
Expanded DAST attack coverage
- Expanded reflected XSS attack coverage from 5 to 18 attack variants across script, SVG/onload, JavaScript string/template/regex/comment, and quoted/unquoted attribute contexts.
- Added OS command injection coverage for Unix command output detection.
- Improved attack planning around browser workflows and authentication-sensitive targets while preserving hard-deny protections for high-risk parameters.
-
Performance and cleaner results
- Reduced repeated SPA/DOM XSS noise with rulepack-driven presentation aggregation that keeps occurrence samples without flooding the main findings list.
- Added IAST presentation aggregation for repeated runtime source/sink/callsite findings.
- Improved export payload normalization and redaction handling across DAST, IAST, SAST, and SCA results.
- Refreshed bundled libraries and scan automation telemetry for smoother automated runs and easier debugging.
This release focuses on making PTK more reliable under automation while increasing DAST coverage. PTK 9.9.0 improves ZAP-managed Chrome, Edge, and Firefox automation startup and session handling, adds safer direct Playwright/Codex scan workflows, expands reflected XSS coverage across more browser contexts, and reduces noisy duplicate findings so scan results are easier to review.
-
DAST autodiscovery controls
- Added opt-in same-origin link autodiscovery for DAST scans.
- Added autodiscovery budgets: Strict, Safe, and Wide.
- Added clear Auto-discovered badges so discovered requests are easy to distinguish from user-driven traffic.
-
Better DAST review flow
- Added an Explorer tab to make passive and cross-engine review easier.
- Improved the Analysis view and grouped low-signal posture checks more cleanly.
- User-driven URLs now stay above autodiscovered URLs in the request list.
- Autodiscovery markers now persist after scan completion and reload.
-
Full HTTP details in DAST drill-down
- DAST finding details now lazy-load the full request/response snapshot instead of relying on truncated projected bodies.
- This keeps completed-scan evidence more accurate during manual review.
-
Secure headers and passive rulepack cleanup
- Cleaned up duplicate passive/header checks to reduce overlap and confusion.
- Improved secure-header coverage and aligned shared free/pro rulepack definitions where applicable.
- Refreshed free rulepack copies used by the extension and ZAP add-on resources.
-
Performance and UX
- The extension popup now opens faster with a lighter shell and direct history-based page restore.
- Improved popup navigation, dropdown behavior, and menu rendering.
- Fixed multiple DAST/dashboard UI issues, including scan management dialog sizing, explorer card layout, sticky table header behavior, and completed-scan request presentation.
This release focuses on making DAST easier to control and easier to review. PTK now supports opt-in autodiscovery with explicit budgets, clearer separation between user-driven and discovered requests, a better Explorer/Analysis workflow, and full HTTP evidence in DAST details. It also cleans up duplicate passive header checks, improves secure-header coverage, and makes the popup and dashboard noticeably faster and smoother to use.
-
DAST: new Analysis and Coverage tabs
- Added an Analysis tab to highlight the most interesting DAST candidates for manual follow-up, with clearer evidence and faster handoff to R-Builder.
- Added a Coverage tab to show which engines (DAST, IAST, SAST, SCA) contributed evidence for the same host/session and where coverage is still missing.
-
IAST: new buckets
- Added IAST buckets to group runtime findings and signals into practical client-side attack surfaces such as Execution, Authz/State, Data/Storage, Messaging, Navigation, and Runtime.
- This makes IAST results easier to review even when raw findings are sparse.
-
SAST: new buckets
- Added SAST buckets to group code-level artifacts into practical review areas such as Routes, Endpoints, GraphQL, Params, Surfaces, and Gadgets.
- This helps focus code review on the areas most useful for security testing.
-
Export / import
- Improved scan export/import handling for easier sharing and reloading of scan results.
- Added clearer progress feedback for long-running scan management actions.
-
UI improvements
- Reworked DAST, IAST, and SAST result UIs to surface actionable information first and move raw engine metadata into secondary details.
- Improved evidence display, confidence visibility, and R-Builder handoff flows.
-
Performance / Stability
- Improved cross-engine coverage analysis so DAST can reflect related IAST, SAST, and SCA results from the same host/session.
- Reduced IAST overhead and fixed multiple workflow and UI regressions to make scans more stable and responsive.
This release improves how PTK presents and connects DAST, IAST, and SAST results. DAST now includes dedicated Analysis and Coverage views, IAST and SAST now use bucketed summaries to make large result sets easier to review, and the UI focuses more on actionable testing guidance and less on raw engine metadata.
-
Report export (PDF + Markdown)
- Added report export in PDF format.
- Added report export in Markdown format for easy sharing in tickets, docs, and GitHub/GitLab.
-
Executive and Technical report presets
- Introduced Executive reports for shareable, prioritised summaries.
- Introduced Technical reports with deeper per-engine detail and evidence.
-
Summary section
- Added a dedicated Summary section for quick high-level visibility (totals and key risk highlights).
-
Findings management and triage
- Added severity filters to manage and triage findings faster.
- Improved prioritisation by focusing on Critical/High/Medium findings first.
-
Confidence scoring and correlated findings
- Added confidence scoring to help separate high-signal findings from potential noise.
- Added correlated findings across DAST, IAST, SAST and SCA to highlight issues backed by multiple engines.
-
Safer, cleaner exports
- Implemented safe-by-default redaction for exports (tokens,
Authorizationheaders, cookies, storage values). - Improved evidence readability with truncation and consistent formatting (including monospace blocks where applicable).
- Executive reports now deduplicate/group repeated findings to reduce noise (especially for repeated SCA/SAST-style entries).
- Implemented safe-by-default redaction for exports (tokens,
This release modernizes PTK reporting with PDF and Markdown exports, introduces Executive and Technical report presets, and adds correlation and confidence scoring across DAST/IAST/SAST/SCA to make prioritisation easier. Exports are safe-by-default with redaction enabled, evidence is more readable, and Executive reports are cleaner thanks to deduplication and grouping.
-
JWT attacks improvements
- Improved JWT attack validation to reduce noise and increase reliability.
- Fixed false positives for
alg=nonedetection by tightening success/verification criteria. - Improved handling of public/unauthenticated endpoints so “expected” responses aren’t reported as vulnerabilities.
-
SPA attacks support
- Added improved support for attacking Single-Page Applications (SPAs) with client-side routing.
- More reliable navigation and in-app flow handling during DAST execution.
-
UI performance improvements
- Faster, more responsive dashboard experience, especially while scans are running.
- Reduced UI jank caused by heavy analysis/binding work under load.
This release improves the accuracy of JWT attacks (especially around alg=none and public endpoints), expands DAST support for modern SPA flows, and delivers UI performance optimizations for smoother day-to-day scanning.
-
CVE Lookup module (passive + active)
- Added a new CVE Lookup module for passive CVE checks (non-invasive fingerprinting).
- Added 10 new CVEs supported across both passive lookup and DAST attack coverage.
-
IAST improvements with chrome.debugger
- Enhanced IAST visibility and correlation by leveraging chrome.debugger.
- Improved reliability for complex browser-driven flows and modern SPAs.
-
UI improvements & bug fixes
- Multiple UI refinements and stability fixes across the extension to improve usability, performance, and overall reliability.
This release introduces CVE-focused passive checks with expanded CVE coverage, strengthens IAST instrumentation via chrome.debugger, and delivers a set of UI and stability improvements.
-
Unified scan model
- Standardised the DAST, SAST and IAST scan envelope and finding structure (including
effectiveSeverity). - Updated the extension UI to use a common
normalizeScanResultview model.
- Standardised the DAST, SAST and IAST scan envelope and finding structure (including
-
Modules & rules refresh
- Cleaned up
modules.json/catalog.jsonand IAST modules with consistent metadata (description, recommendation, links, OWASP/CWE, severity in metadata). - All recommendations are now HTML-sanitised for safe rich-text display.
- Cleaned up
-
DAST attack strategy options
- Added configurable scan profiles: Fast / Smart / Comprehensive.
- Control atomic vs per-parameter attacks and stop re-attacking the same URL/parameter once a module has a confirmed finding.
-
CVE-focused DAST modules
- Added CVE modules using the React2Shell attack flow, including coverage for CVE-2025-55182 labs.
- Targets modern React-based injection chains.
-
IAST stability & noise reduction
- Fixed IAST module loading (background push + content pull on reload).
- Externalised sink rules into JSON.
- Reduced false positives where sources were previously reported as generic hashes.
-
SCA integration groundwork
- Defined how SCA scan results fit into the unified scan/finding model.
- Adjusted the portal schema to support SCA alongside DAST/SAST/IAST.
This release focuses on making all engines speak the same scan/finding language, tightening module metadata, and laying the foundations for SCA and CVE-driven DAST, while improving IAST stability and reducing noise in real-world scans.
- SAST runs off the main thread
- Chrome: MV3 offscreen document + worker
- Firefox: background worker
- Richer SAST telemetry with per-file and per-module progress events
- Improved taint traces and trace visualisation in the findings UI
- Taint model cleanup, new rule filters, and refined
document.cookiehandling
SAST now executes in a dedicated worker context (offscreen document on Chrome MV3, background worker on Firefox), so heavy JavaScript scans no longer freeze the UI and remain responsive even on large SPAs. New structured telemetry emits per-file and per-module progress, while upgraded taint traces and visualisation make it easier to follow data flows end-to-end. The taint model has been refined with cleaner document.cookie handling and new rule filters to cut noise and keep reports focused on the most relevant issues.
-
Queued, rate-limited attack execution
Rebuilt the runtime scanner around a queued worker pool with token-bucket rate limiting, per-plan/per-module locking, and resilient worker error handling. Large scans now complete more reliably under throttling, with safe retries and no request storms. -
Request fingerprinting & consistent drill-downs
All outgoing requests are fingerprinted before being queued, so duplicate attacks are deduplicated at the planner level. Each attack plan now carries its own context end-to-end, keeping per-request drill-down views consistent with live stats and historical counters. -
DAST UI filters & live counters
The DAST panel now supports scoped filters (all/vulns/5xx/4xx) plus per-request filtering. Filters feed back into the aggregated counters so operators can slice and dice results without losing a trustworthy high-level view.
-
New rules & expanded coverage
Added new SAST rules to broaden coverage across client-side injection, cookie handling, and DOM-driven flows, improving the depth and breadth of findings surfaced during scans. -
Taint trace visualisation
Taint traces are now surfaced directly in the UI and reports, showing the fullsource → propagation → sinkchain. This makes it easier for developers to understand why a value is tainted and how it flows through the application. -
Library-aware scanning (less noise)
Well-known third-party libraries such as jQuery are now excluded from SAST analysis to reduce false positives and noise, keeping the focus on your application-specific code. -
Richer, self-contained findings
Report cards now render sanitized source/sink metadata, taint traces, contextual code snippets, and rule guidance so each finding is self-contained and ready for developers to act on without cross-referencing raw logs. -
New SAST report UI
The SAST report UI has been refreshed to better group findings, highlight key context, and keep source/sink traces readable, aligning the in-app cards with exported report structure.
- Attacks on each parameter separately
- Vulnarable parameter is reported
- Attacks on JSON
- Bug fixes
- All scans can be managed from the dashboard panel
- Added SAST taint flow rules
- Added DAST settings to manage requests per second and concurrency
- Bug fixes
- Added SAST freature
- Improved DAST capabilities
- Bug fixes
- Added SAST freature
- Improved DAST capabilities
- Bug fixes
- Added IAST freature
- Bug fixes
- R-Attacker is now DAST
- Cheat sheets added for XSS and SQL
- Bug fixes
- R-Builder with cURL support
- R-Builder export/import functionality
- Bug fixes
- JWT attacks added
- Bug fixes
- Json Web Token Inspector
- Bug fixes
- Request builder with DAST scan feature.
- More passive attacks according OWASP Secure Headers project.
- Attacks improvements.
- UI improvements
- Bug fixes
- Request builder with declarativeNetRequest support for Chome/Edge browsers.
- Macro and traffic recording feature is back again.
- Reload extension functionality added. There are a lot of changes related to manifest V3 and due to worker may be inactive after 5 minutes, sometims you may need to reload the PTK
- UI improvements
- Bug fixes
- Cookie editor allows to manage cookies, eg add, edit or remove cookies. Rules to block or protect cookies. Import and export.
- Bug fixes
- Manifest 3 support for chromium based browsers
- R-Attacker, R-Builder and Encoder/Decoder data saved in local storage, so you won't miss your data even after restarting
- Macro and Traffic recording no longer supported
- Bug fixes
- Improved R-Attacker module to support attacks for every parameter separately
- Added R-Attacker external integration to support Selenium tests
- Bug fixes
- New stored XSS attack with window.postMessage payload!
- Wappalyzer module updated to the latest version
- Bug fixes
- New! Reporting feature has been added, so you can generate a report in one click.
- Wappalyzer and Retire NPM module updated to the latest version
- Privacy policy is now in place, please check it out
- Bug fixes
- Retire.js NPM module added to identify known vulnerbailities (CVE)
- Wappalyzer NPM module updated to the latest version
- Bug fixes
- Tabs monitoring functionality improvements
- Bug fixes
- Recording authentication is now starting with incognito mode when allowed (not supported in Firefox)
- Fixed an issue with recording events on iframes in a new popup window
- R-Builder can now store requests
- Added a blacklist for R-Attacker to exclude .css and .js files from attacking
- Added a new attack - JWT None algorithm
- Added a disclaimer
- Added encode and decode features
- Fixed an issue with \ and ` characters in macro recording
- Added double click support for macro recording
- Added an option to generate additional delays when export a macro for better SPA support
- Removed HAR viewer due to problem with PerfCascade NPM module
- Bug fixes
- Improved dashboard performance and detection
- Added ability to execute requests and export a HAR file with recorded output
- Bug fixes
- New R-Attacker functionality - scan in runtime and get a report once completed
- New Proxy tab to monitor requests for selected tab
- Dashborad - Web Application Firewall detection card
- Dashborad - Storage/Authentication card (with auto decoding JWT tokens)
- Incognito mode is now separated, no shared resources between normal and private windows (not supported in Firefox)
- NPM package release - 1.0.2
- Bug fixes
- ES6 standart support
- NPM modules support
- Cross-browser support including incognito mode on Firefox browsers
- Added R-Attacker to allow attacks execution on any request
- Cross-browser support
- Export a list of URLs discovered during browsing an application
- Export a list of FQDNs discovered during browsing an application
- Added SQL Injection attacks against POST requests
- New Dashboard view
- Request builder executes a request based on simple url
- New macro event type added to support Javascript. When selected the exported macro will contain javascript code to help simplify playback on most of the modern SPA apps like ReactJS/Angular
- Added recording import to support conversion from Selenium .side and .html recording to javascript macro
- Real time events tracking during recording/playback on the floating window. Tracker window is draggable and resizable iFrames support added for recording/playback
- Added HAR viewer for traffic recording
- Improved performance by limiting number of tracking tabs
- Export macro recording using Driver events by default
- Issue with validate functionality fixed
- Bug fixes
- UI changes to improve user experience
- Macro auto export and auto save features have been added
- Bug fixes
- Swagger YAML to JSON convertor has been added
- Issue where 'Host' header was missed in recorded traffic
- Incognito mode support for traffic/macro recording
- Macro replay notifications added
- Improved display HTML response in request builder
- Added traffic analysis for authentication
- Added onChange event support for macro recording and replay
- Fixed an issue with traffic recording
- Fixed an issue with delete event during macro recording
- Fixed an issue with backspace event during macro recording
- Added functionality to validate HTML using a regex after macro replay
- Fixed an issue when request builder used wrong header
- Added functionality to display a response as HTML
- Fixed an issue with Access-Control-Allow-Origin response header
- Added local file support for swagger utility
- AS Pro / AS Enterprise support disabled by default
- Minor fix for messages passing
- Added support for AS Pro / AS Enterprise validate functionality
- Fixed issues with export/download macro
- Fixed issue with validate functionality
- Request builder now supports 2xx, 3xx, 4xx, 5xx response statuses. Added support for Referer and User-Agent request headers
- Replay macro functionaly has been added
- Validate functionality for AppSpider Pro reports