 | Hackbar Simple security audit / Penetration test tool. | |
 | RESTClient Visit and test RESTful/WebDav services. |
 | Tamper Data Use tamperdata to view and modify HTTP/HTTPS headers and post parameters. | |
 | Live HTTP Headers View HTTP headers of a page and while browsing. |
 | RefControl Control what gets sent as the HTTP Referer on a per-site basis. | |
 | User Agent Switcher Easily switch the user agent of a browser. |
 | Web Developer Various web developer tools on browser. | |
 | DOM Inspector Inspect and edit the live DOM of any web document or XUL application. |
 | Inspect This Inspect the current element with the DOM Inspector. | |
 | Form Fox Displays the form action, the site to which the information you’ve entered is being sent. |
 | SQL Inject Me Test for SQL injection vulnerabilities which can cause a lot of damage to a web application. | |
 | XSS Me Test for XSS vulnerabilities which can cause a lot of damage to a web application. |
 | Cookies Manager+ View, edit and create cookies. | |
 | Firecookie View and manage cookies |
 | Autofill Forms Autofill Forms enables you to fill out web forms with one click or a keyboard shortcut. | |
 | Cookie Monster Cookie Monster provides proactive cookie management on a site or domain level basis, including 3rd party cookies. |
 | Fireforce Brute-force attacks on GET or POST forms | |
 | Groundspeed Groundspeed is an add-on that allows security testers to manipulate the application user interface to eliminate annoying limitations and client-side controls that interfere with the web application penetration tests. |
 | Http Requester A tool for easily making HTTP requests (GET/PUT/POST/DELETE), viewing the responses, and keeping a history of transactions. | |
 | Modify Headers Add, modify and filter the HTTP request headers sent to web servers. This addon is particularly useful for Mobile web development, HTTP testing and privacy. |
 | Poster A developer tool for interacting with web services and other web resources that lets you make HTTP requests, set the entity body, and content type. | |
 | Ref Spoof Easy spoofing of the URL referer (referrer) featuring a toolbar |
 | SeleniumExpertSeleniumIDE This plugin is my attempt to bring the wonderful world of inspections, tips, hints, fixes and refactoring to Selenese! | |
 | SeleniumIDE This plugin is my attempt to bring the wonderful world of inspections, tips, hints, fixes and refactoring to Selenese! |
 | NoRedirect Take control of web page redirects for fun and profit. | |
 | Websecurify Websecurify is a powerful, cross-platform web security testing technology designed from the ground up with simplicity in mind. |
 | Ra.2 Blackbox DOM-based XSS Scanner |