Burp Suite User Forum

Create new post

Requesting more details on security reviews executed by PortSwigger on BappStore extensions

Lucas | Last updated: May 31, 2023 11:44AM UTC

Hello! Based on the following quoted text extracted from: https://portswigger.net/burp/documentation/desktop/extensions "We review community-created extensions for security and quality before we make them available from the BApp Store. However, PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose." I'm psyched that PortSwigger takes security seriously and would kindly ask for additional details on what "security and quality review" means. The reason I ask is because we make good use of several extensions and review their code ourselves; but knowing that there's an additional layer of review taking place by your team would be calming. Could you please be more specific on what sort of review your team executes? Thank you in advance!

Michelle, PortSwigger Agent | Last updated: Jun 01, 2023 07:31AM UTC

Hi When an extension is submitted to us for inclusion in the BApp Store, we follow this process (step 3 details the review process): https://portswigger.net/burp/documentation/desktop/extensions/creating/bapp-store-submitting-extensions You can also find details of our acceptance criteria here: https://portswigger.net/burp/documentation/desktop/extensions/creating/bapp-store-acceptance-criteria I hope this helps.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.