AI-Powered Security Analysis for Burp Suite
Version 1.0 β€’ Production Ready

BurpAI brings the power of multi-model AI to your security testing workflow. Analyze HTTP requests in real-time and identify vulnerabilities with enterprise-grade AI models.

Get Started View on GitHub

✨ Features

🧠

Multi-Model AI

11 AI models with automatic failover. Switch between Kimi, DeepSeek, GLM, Qwen, LLaMA, and more.

⚑

Real-Time Analysis

Background threadingβ€”zero UI lag. Analyze requests instantly without blocking your workflow.

πŸ”

Smart Detection

Priority detection for P1/P2 vulnerabilities: RCE, IDOR, SQLi, Auth bypass, and more.

πŸ“‹

Native Repeater

Built-in request/response editing with Burp's native editors. Full control in one place.

πŸ“Š

Request History

Automatic tracking of 1000+ requests. Never lose context on your security tests.

πŸ’¬

Interactive Chat

Custom prompts for targeted analysis. Ask the AI security expert any question.

πŸš€ Quick Start

1. Get API Key

Sign up for DigitalOcean AI and create an API key.

2. Load Extension

Burp Suite β†’ Extensions β†’ Add β†’ Select burpaai.py

3. Configure

Enter your DigitalOcean API key in the BurpAI tab β†’ Click Save

4. Analyze

Load any request in Repeater β†’ Click Analyze with AI β†’ Review results

Download v1.0

🧠 Supported Models

Automatic failover across 11 enterprise-grade AI models:

Alibaba Qwen 3
DeepSeek R1
GLM-5
Kimi K2.5
LLaMA 3/3.3
Mistral Nemo
NVIDIA Nemotron
OpenAI GPT OSS

πŸ“‹ Requirements

Requirement Details
Burp Suite Pro or Community Edition (latest)
API Key DigitalOcean AI (free tier available)
Java 8+ (included with Burp)
Network HTTPS outbound to AI API

πŸ›‘οΈ Security First

BurpAI is built with security as a core principle:

βœ… HTTPS-only API communication

βœ… No telemetry or tracking

βœ… Local-only data storage

βœ… User-managed API keys

βœ… Open-source for transparency

πŸ› Report Security Vulnerabilities

Found an issue? Use GitHub Security Advisory to report privately.

Security Policy

πŸ“₯ Download

Get the latest version from GitHub:

All Releases Download v1.0

License: Apache 2.0 | Status: Production Ready

πŸ“š Documentation

README Security Policy Changelog Contributing