# aress31/burpgpt

A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities and enables running traffic-based analysis of any type.

Repository: https://github.com/aress31/burpgpt
Canonical: https://ross.abutalabs.com/products/burpgpt
Language: Java
License: Apache-2.0
License Family: permissive
Topics: ai, burp-extensions, burpsuite, cybersecurity, gpt, openai, pentesting, security, security-automation, webapp, burp-plugin, burpsuite-extender, gpt-3, openai-api
Last push: 2024-06-09T20:40:29+00:00

## Health v2 (maintenance only)
Score: 30/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 35, longevity 88
- inputs: {"age_days": 1243, "days_push": 815, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2351, forks 286 (observed 2026-08-28T04:06:40.367230+00:00)

## What it is
burpgpt is a Burp Suite extension that sends HTTP traffic to OpenAI GPT models for AI-driven passive vulnerability scanning and traffic analysis. The free Community edition is no longer maintained or functional, with development moved to a paid Pro edition.

## Use cases
- detect bespoke web vulnerabilities that traditional scanners miss
- run AI-based analysis of HTTP traffic in Burp Suite
- generate automated security reports from passive scans
- analyze web app requests with custom GPT prompts
- augment pentesting workflows with LLM insights

## When to choose
- you want LLM-assisted passive scanning inside Burp Suite
- you need customizable prompts to analyze captured web traffic
- you're exploring AI-augmented vulnerability discovery approaches

## When to avoid
- you need a working free tool - the Community edition is unmaintained and non-functional
- you cannot send sensitive traffic data to OpenAI's API
- you expect fully automated results without manual triage of false positives

## Facets
- artifact type: plugin
- maturity: abandoned
- function: security, nlp, llm-inference, plugin-system
- domain: security, penetration-testing, artificial-intelligence, web-development
- platform: jvm
- tags: burp-suite-extension, openai, gpt, passive-scanning, vulnerability-detection, traffic-analysis, pentesting, desktop

## Member repositories
- aress31/burpgpt (main) score 30

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:40.367230+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:36:53.777449+00:00, confidence not recorded.
  - readme: https://github.com/aress31/burpgpt (fetched 2026-08-28T04:06:40.367230+00:00, sha dafcabce4a10)
- Data as of 2026-08-30T08:39:29.467469+00:00.
