# owtf/owtf

Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp

Repository: https://github.com/owtf/owtf
Canonical: https://ross.abutalabs.com/products/owtf
Homepage: https://medium.com/@owtf 
Language: TypeScript
License: BSD-3-Clause
License Family: permissive
Topics: security, owasp, owtf, python, pentest, kali-linux, framework, web-application-security
Last push: 2026-08-22T05:35:06+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 8, longevity 100
- inputs: {"age_days": 5340, "days_push": 11, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1949, forks 492 (observed 2026-08-28T04:05:58.040035+00:00)

## What it is
OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing workflows with standards like the OWASP Testing Guide, OWASP Top 10, PTES, and NIST. It is highly configurable, allowing testers to add plugins and tests without prior development experience.

## Use cases
- run automated web application penetration tests aligned with OWASP standards
- orchestrate multiple security tools from a single framework during pentests
- find and verify web vulnerabilities efficiently within tight assessment windows
- perform targeted fuzzing on risky areas of a web application
- generate pentest reports mapped to OWASP Testing Guide and PTES
- create custom security test plugins without deep development experience

## When to choose
- you are a penetration tester working on web application assessments
- you want testing workflows aligned with OWASP, PTES, or NIST standards
- you need to combine multiple security tools into one efficient pipeline
- you work on Kali Linux or a Debian derivative and want a ready-made pentest framework

## When to avoid
- you need a fully automated scanner with no human expertise involved
- you are not comfortable interpreting raw tool output and security findings
- you need a lightweight one-off vulnerability scan rather than a full framework
- your environment cannot run Docker or PostgreSQL dependencies

## Facets
- artifact type: framework
- maturity: active
- function: security, penetration-testing, web-framework, developer-tools
- domain: security, penetration-testing, web-development
- platform: python
- tags: owasp, pentest, kali-linux, web-application-security, vulnerability-scanning, security-testing, linux, macos, docker

## Member repositories
- owtf/owtf (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:58.040035+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:06:54.606962+00:00, confidence not recorded.
  - readme: https://github.com/owtf/owtf (fetched 2026-08-28T04:05:58.040035+00:00, sha 0ae01c0c0465)
- Data as of 2026-08-30T08:39:29.467469+00:00.
