owtf/owtf
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp observed · 2026-08-28
Health v2 · maintenance only
67/100
- Activity 99
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 5340
- days_rel: n/a
- days_push: 11
- n_releases_24m: 0
Adoption not part of the score
1949 stars · 492 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing workflows with standards like the OWASP Testing Guide, OWASP Top 10, PTES, and NIST. It is highly configurable, allowing testers to add plugins and tests without prior development experience.
Use cases
- run automated web application penetration tests aligned with OWASP standards
- orchestrate multiple security tools from a single framework during pentests
- find and verify web vulnerabilities efficiently within tight assessment windows
- perform targeted fuzzing on risky areas of a web application
- generate pentest reports mapped to OWASP Testing Guide and PTES
- create custom security test plugins without deep development experience
When to choose
- you are a penetration tester working on web application assessments
- you want testing workflows aligned with OWASP, PTES, or NIST standards
- you need to combine multiple security tools into one efficient pipeline
- you work on Kali Linux or a Debian derivative and want a ready-made pentest framework
When to avoid
- you need a fully automated scanner with no human expertise involved
- you are not comfortable interpreting raw tool output and security findings
- you need a lightweight one-off vulnerability scan rather than a full framework
- your environment cannot run Docker or PostgreSQL dependencies
Facets
framework · maturity active
security penetration-testing web-framework developer-tools security penetration-testing web-development python owasp pentest kali-linux web-application-security vulnerability-scanning security-testing linux macos docker
1 source
- readme: https://github.com/owtf/owtf · fetched 2026-08-28 · 0ae01c0c0465
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| owtf/owtf | main | 67 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem