Open source, native on macOS

Test web app security from your Mac.

Plonix captures every request, maps the target as you browse, and helps you prove what you find. From a window, a terminal or Claude Code.

LENS GET api.brightcart.example/v2/me 200 · in scope
GET /v2/me?next=%252Faccount%252Fsettings HTTP/1.1
host: api.brightcart.example
authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMDQyIiwiZW1haWwiOiJtYXlhLmxvcGV6QG1haWwuZXhhbXBsZSJ9
x-trace: 6f726465722d73657276696365
cookie: prefs=eyJyb2xlIjoidXNlciIsInRlYW0iOiJiaWxsaW5nIn0=
x-forwarded-for: 10.20.4.17
origin: https://www.brightcart.example
referer: https://www.brightcart.example/account
accept: application/json
sec-fetch-site: same-site

Move the lens over the request. Plonix decodes what it spots, right where it sits.

Plonix
The Plonix window: live traffic with filter chips, a scope suggestion for a newly seen domain, and the Lens showing a request and its response.The Plonix window: live traffic with filter chips, a scope suggestion for a newly seen domain, and the Lens showing a request and its response.

The Plonix window, capturing. A new domain is suggested for scope with the evidence behind it.

Everything a web assessment needs. Nothing it doesn't.

$ plonix connect claude
✓ Claude Code connected · read-only
Ask Claude Code

AI-first, built for Claude Code

Built-in MCP gives Claude Code your live traffic, scope and findings in one command. Ask about any request with one click.

AI and agents →
SShop API● :8081
ABrightcart staging● :8080
BBank portalclosed

Several projects at the same time

Every project is its own folder, window, proxy and database. Open as many as you need; nothing collides.

Projects →
api-kitBundle✓ Verified
leaksFilter pack✓ Verified
check-scopeSkill✓ Built in
✓ Signed · checked before install

A community Market for everything modular

Skills, rule packs, filter packs and bundles, maintained by the community and signed before they install.

Market →
status:5xx method:POST -is:trackers
+ Auth flows+ host:api.brightcart.example− Analytics & trackers− static files

Advanced filtering

Type a query or click chips to show only or hide. Save named filters, and use the same query in the CLI and API.

Filtering →
<60sdownload to captured traffic
CertificateProxyScopeBrowser

Friendly from the first minute

One click or one command sets up the certificate, proxy, scope and a capture browser. A real Mac app with shortcuts you already know.

Get started →
cdn.bcstatic.example looks like part of your target
↗ called from www.brightcart.example · shares a certificate
Accept+ subdomainsReject

Scope that works, and stays easy

Scope grows as you browse, with evidence for every suggestion. One click to accept or reject, and noise like trackers is excluded for you.

Adaptive scope →
Native Mac appRust engineYour data stays on your MacOpen source, Apache-2.0CLI + local API

Mind Reader suggests the next step.

One-click actions that surface the single most useful next step for whatever is on screen: the right chip, in the right pane, at the moment you notice something. Nothing fires on its own: you click to run, and anything that sends stays in scope.

LENS

        
Suggested

Pick a moment, then click the chip to see what one click does. This is a preview. The real actions live in the app.

AI-native

Claude Code can see your project. You decide how much.

Plonix has a built-in MCP server. One command connects Claude Code to the live project: it can search traffic, read requests and responses, see hosts, endpoints and technologies, and review scope and findings. Any other MCP client can run plonix mcp.

Terminal
$ plonix open brightcart.example        # capture while you browse
✓ Proxy   127.0.0.1:8080
✓ Scope   brightcart.example (+ subdomains)
$ plonix connect claude        # once
✓ Plonix added to Claude Code (read-only)
$ claude
> Use Plonix to find in-scope API endpoints that
  returned errors, then read the most interesting
  request and tell me what stands out.
The Ask Claude Code dialog: a question and the request, response, spotted values and technologies it will share, each with a token count.The Ask Claude Code dialog: a question and the request, response, spotted values and technologies it will share, each with a token count.
Read-only by defaultAgents sign in with their own token. Anything but reading is refused by the engine.
You see what is sharedAsk Claude Code on a request, host or finding shows exactly what goes, with a size limit you set.
Same scope rules as youEvery agent request passes the same scope check as yours, and shows up on the Agents screen.

It points at what matters before you go looking.

The Lens shows the selected request and its response, decoded and pretty-printed. Above them, Plonix lists what it spotted. Click one to highlight it in place, copy the decoded value, or find it across everything you captured.

JWT Base64, hex, URL-encoded Leaked secrets Emails and card numbers Basic auth Internal IPs

Detection runs locally, on traffic you already captured. A token's signature is never claimed valid.

The Lens with a JWT spotted in the authorization header, its header decoded, and the token highlighted in the request.The Lens with a JWT spotted in the authorization header, its header decoded, and the token highlighted in the request.

Scope that learns the target while you browse.

Static allow-lists assume you already know every domain an app uses. You find out by using it. Plonix records everything, then suggests domains to bring into scope, each one backed by evidence you can click.

  • Called from an in-scope page Referer or Origin
  • Redirected or linked Location, page links, CSP
  • Shares a session or a certificate tokens and TLS SANs
  • Enforced in one place replays, sends and agents can only reach accepted hosts
The Scope screen: suggested domains, each with the evidence that links it to the target, and buttons to accept or reject.The Scope screen: suggested domains, each with the evidence that links it to the target, and buttons to accept or reject.

Experiments, kept and comparable.

Press b on any request to take it to the Bench. Edit it, send it, and every send stays in that tab's history. Restore or branch any earlier send into a new tab, and put two sends side by side to see what changed.

  • Side-by-side response and request diff
  • Sends only reach in-scope hosts accept a host right there
  • Turn a send into a finding in one click
The Bench: a request on the left, its JSON response on the right, and the send history below with Restore, Branch and Finding buttons.The Bench: a request on the left, its JSON response on the right, and the send history below with Restore, Branch and Finding buttons.

See exactly what changed.

Tick two sends on the Bench and Plonix lines them up side by side. Changed lines are highlighted and unchanged runs fold away. Change an order id, and someone else's name, card and total stand out at once.

  • Switch between the responses and the requests
  • Unchanged lines fold away
  • Any two sends from the tab's history
Compare view on the Bench: two order lookups side by side, with the changed lines highlighted. The second order shows another customer's name, email, card number and total.Compare view on the Bench: two order lookups side by side, with the changed lines highlighted. The second order shows another customer's name, email, card number and total.

Several targets open, nothing colliding.

A project is a folder you choose. It holds its own traffic, scope, findings and settings. Open several at once: each gets its own window, proxy port, API and database. Trust the certificate once and it covers them all.

Turn on Keep only in-scope traffic and out-of-scope requests are deleted from disk when the project closes.

The Projects screen with two open projects, Shop API on proxy port 8081 and the Brightcart demo on port 8080.The Projects screen with two open projects, Shop API on proxy port 8081 and the Brightcart demo on port 8080.

Add what you need, and know where it came from.

One catalog for everything modular: skills that tell an agent how to do a job, rule packs that recognise technologies, filter packs like is:auth, and bundles that install a set together. Open it with ⌘7 or run plonix market.

  • Signed by the Plonix maintainers every file is checked before anything installs
  • Clear labels Verified, Built in, Not verified, Changed
  • Nothing runs code skills are text and packs are data
  • Host your own a team Market with its own signing key
The Market: skills, extensions and rule packs, each marked Built in or Verified, with Install buttons.The Market: skills, extensions and rule packs, each marked Built in or Verified, with Install buttons.

Anything you can click, you can script.

The window, the plonix command and agents are equal clients of one local API, and plonix mcp serves it to any MCP client. Every command takes --json, and exit codes tell a script what happened, down to a request refused by scope.

The API listens on loopback only and needs a token from ~/.plonix/api-token.

$ plonix search host:brightcart.example status:5xx
$ plonix show 42
$ plonix watch scope:in
$ plonix scope review
$ plonix scope accept '*.bcstatic.example'
$ plonix replay 42 -H 'Authorization: Bearer other-user' -t /api/users/2
$ plonix -p shop search status:5xx --json
Get started

Captured traffic in under a minute.

For Apple silicon and Intel, macOS 11 or later. Plonix is in early development and not notarized by Apple yet: the first time, open it from System Settings › Privacy & Security › Open Anyway. All releases

Build from source
$ git clone https://github.com/SergeyMalych/plonix.git
$ cd plonix
$ cargo install --path crates/plonix-cli
$ plonix open example.com
✓ Certificate  ~/.plonix/ca.pem  (created)
✓ Proxy        127.0.0.1:8080
✓ Scope        example.com (+ subdomains)
✓ Browser      isolated profile, trusts Plonix
Capturing. Browse the site.