Skip to main content

PTP parses and ranks the discoveries listed in security tool reports.

Project description

What is PTP?

The primary goal of ptp (Pentester’s Tools Parser) is to enhance OWASP - OWTF project in order to provide an automated ranking for each plugin. This will allow the user to focus attention on the most likely weak areas of a web application or network first, which will be valuable to efficiently use the remaining time in a penetration assessment.

Instead of evaluating every plugins run by OWASP - OWTF and defining the rankings for each of them, thanks to ptp, the user will be able to focus on the ones that have been ranked with the highest risks. The user is then able to confirm or override the automated rankings since we estimate that she/he is the only one that can accurately detect the false positives.

When developing the automated ranking system, ptp’s main goal was joined with a secondary one.

Apart from its main feature which is ranking the results from security tools reports, it also provides an unified way to reuse these reports directly in your python code, without having to deal with complex parsing.


Using pip

The ptp library is available on PyPI at the following address:

The easiest way to install it is using pip.

$ pip install ptp

Note: If an error occurs during the installation process, check your permissions. It might be required to run pip as root.

From scratch

It is also possible to install the library from its repository. You will then be able to use the latest possible version or even try the develop branch.

The first step is to clone the repository of the project:

$ git clone

Then use the Makefile command:

$ make install


from __future__ import print_function
from ptp import PTP

if __name__ == '__main__':
    ptp = PTP()
    print('Highest severity:', ptp.highest_ranking)


The documentation is available online at the following address:

It explains how to use the library and even how to contribute. Plus it contains the technical documentation of the project.

Current support

  • arachni (0.4.x to 1.x) (XML and JSON report)
  • burpsuite (1.x.x) (XML report)
  • dirbuster (1.0-RC1)
  • hoppy (1.x.x)
  • metasploit
  • owasp
  • robots.txt
  • skipfish (2.10b)
  • w3af (1.x.x) (XML report)
  • wapiti (2.x.x) (XML report)

Warning: Since v0.4, PTP relies on the fact that the supported tools are following semantic version (except observed otherwise). In other words, as long as the tool doesn’t update its MAJOR version, PTP will assume that it can parse its report, reducing the maintenance cost on our side.

Project details

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Files for PTP, version 0.4.1
Filename, size File type Python version Upload date Hashes
Filename, size PTP-0.4.1.tar.gz (694.6 kB) File type Source Python version None Upload date Hashes View

Supported by

AWS AWS Cloud computing Datadog Datadog Monitoring DigiCert DigiCert EV certificate Facebook / Instagram Facebook / Instagram PSF Sponsor Fastly Fastly CDN Google Google Object Storage and Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Salesforce Salesforce PSF Sponsor Sentry Sentry Error logging StatusPage StatusPage Status page