Ross ROSS = Recommend OSS · open-source software intelligence for agents

mitmproxy/mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. observed · 2026-08-28

github.com/mitmproxy/mitmproxy · homepage · Python · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

89/100

  • Activity 99
  • Release rhythm 71
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 33.5
  • age_days: 6042
  • days_rel: 113
  • days_push: 8
  • n_releases_24m: 15

Full methodology

Adoption not part of the score

44820 stars · 4696 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

mitmproxy is an interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, HTTP/3, and WebSockets, offered as a console tool (mitmproxy), a web UI (mitmweb), and a command-line dumper (mitmdump). It supports on-the-fly traffic inspection and modification, replay, transparent/reverse/local capture modes, and scripting via a Python addon API.

Use cases

  • intercept and inspect https traffic from any app or device
  • debug http requests and responses like chrome devtools for native apps
  • modify web traffic on the fly with python scripts
  • replay recorded http conversations for testing
  • man-in-the-middle proxy for penetration testing
  • capture local application traffic without proxy settings
  • convert captured traffic to openapi specs

When to choose

  • you need to inspect, modify, or replay TLS-protected HTTP/WebSocket traffic
  • you want scriptable traffic manipulation via a Python API
  • you need cross-platform interception including transparent, reverse, and local capture modes
  • you want a free open-source alternative to Charles Proxy or Fiddler

When to avoid

  • you only need simple non-TLS packet capture (tcpdump or Wireshark may suffice)
  • you need a pure load-testing tool rather than interactive interception
  • you require interception of non-HTTP protocols without TLS or custom binary protocols out of the box

Facets

application · maturity stable

proxy security http-client developer-tools penetration-testing websocket cli gui security developer-tools networking penetration-testing web-development privacy windows python cli cross-platform mitm traffic-interception http-debugging tls-interception traffic-replay http3 python-addons linux macos docker

6 sources

Member repositories

RepositoryRoleHealth v2
mitmproxy/mitmproxymain89

For agents

markdown · JSON · MCP: product_card(name="mitmproxy/mitmproxy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem