# yeswehack/PwnFox

PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.

Repository: https://github.com/yeswehack/PwnFox
Canonical: https://ross.abutalabs.com/products/pwnfox
Language: JavaScript
License Family: other
Topics: bugbounty, firefox-extension, hacking, pentest
Last push: 2024-08-07T14:49:45+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2285, "days_push": 756, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1339, forks 124 (observed 2026-08-28T04:04:25.854298+00:00)

## What it is
PwnFox is a Firefox extension paired with a Burp Suite extension that provides tools for web security audits, such as one-click Burp proxy connection, container profiles with identifying headers, and postMessage logging. It also offers JavaScript injection on page load and one-click removal of security headers like CSP and X-Frame-Options.

## Use cases
- proxy firefox traffic through burp suite with one click
- manage multiple identities in one browser during pentests
- log and inspect postMessage traffic between frames
- strip security headers like CSP while testing payloads
- inject custom javascript into pages during security audits
- highlight requests by container color in burp

## When to choose
- you do web pentesting or bug bounty work with Burp Suite and Firefox
- you need multi-identity browsing with per-identity request tagging in Burp
- you want quick toggling of security headers or postMessage visibility in devtools

## When to avoid
- you use Chrome instead of Firefox (consider nccgroup/autochrome)
- you need a general-purpose proxy without Burp Suite
- you require a formally licensed or commercially supported tool

## Facets
- artifact type: plugin
- maturity: active
- function: security, developer-tools, logging, proxy
- domain: security, browser-extensions, developer-tools, penetration-testing
- platform: browser, browser-extension
- tags: burp-suite, pentesting, bug-bounty, firefox-addon, security-audit, postmessage-logging, container-profiles

## Member repositories
- yeswehack/PwnFox (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:25.854298+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:43:57.222127+00:00, confidence not recorded.
  - readme: https://github.com/yeswehack/PwnFox (fetched 2026-08-28T04:04:25.854298+00:00, sha d10c5c1e8534)
- Data as of 2026-08-30T08:39:29.467469+00:00.
