Free & Open Source

Download
ScopeProof

Real-time coverage tracking for Burp Suite. Know what you tested, prove it to your clients.

v1.2.0 · Montoya API · Java

Pending BApp Store approval — manual install via .jar for now

Setup

Install in under a minute

Three steps. No account required. No configuration needed.

1

Download the JAR

Download ScopeProof.jar from the button above or from the GitHub releases page.

2

Add to Burp Suite

In Burp Suite, go to Extensions > Installed > Add. Set the type to Java and select the JAR file.

3

Start Testing

A ScopeProof tab appears automatically. Test normally and coverage data populates in real time.

In Action

See your coverage at a glance

ScopeProof running in Burp Suite

Features

Everything in the free extension

Real-Time Coverage

Captures traffic from Proxy, Repeater, Intruder, Scanner, and all other Burp tools automatically.

Custom Payload Tagging

Define your own payloads by category. Paste lists, load from files, or tag directly from requests. Zero false positives.

Intruder Integration

Tagged payloads appear as Intruder payload generators. Select by category or use all at once.

Annotations

Add notes and tags to any endpoint. Document findings as you go. Persists across Burp sessions.

JSON & CSV Export

Export full endpoint data with testing depth, tool usage, and metadata for reports and analysis.

Persistent Storage

Coverage data, payloads, and annotations survive Burp restarts. Pick up right where you left off.

Requirements

Burp Suite Professional or Community Java 17+ Montoya API

Want dashboards, client portals, and team analytics?

ScopeProof Pro turns your coverage data into branded deliverables your clients can see and trust. Sign up free to get started.

Free to try. No credit card required.