Releases: SergeyMalych/plonix
Releases · SergeyMalych/plonix
Release list
Plonix 0.1.0
The first public release of Plonix for Mac.
Capture
- An intercepting HTTP and HTTPS proxy with its own certificate authority, created on first run.
- One step from nothing to captured traffic: open a target and Plonix starts the proxy, sets the scope and opens a browser with its own profile that trusts Plonix.
- HTTP/2 on both sides, WebSocket messages, and bodies that stream through as the server sends them.
- Intercept: hold requests and responses in flight to edit, forward or drop them. Match and replace rules change traffic as it passes.
- Works on every Mac: with no supported browser installed, Plonix offers to download its own, and trusting the certificate for Firefox is one click.
- Client certificates per host for servers that ask for one, and HAR files in and out of a project.
Investigate
- Traffic with a search language (
host:api.example.com method:POST status:5xx), include and exclude filters, filter packs and suggestions drawn from your traffic. - The Lens decodes what it finds in a request or response: tokens, URL-encoded and Base64 values, personal data, leaked secrets and internal addresses.
- Adaptive scope suggests related domains as you browse, with the evidence for each, to accept or reject one by one or in bulk.
- The Map shows hosts, the technologies behind them, and their endpoints and parameters.
Experiment
- The Bench: edit a request, send it, branch it and compare responses side by side. Edit decoded values in place.
- Bench runs send a request many times with values from payload lists, including lists from the Market.
- Crawl a host to find endpoints, parameters and forms, and run scope-gated active scans from the Scans screen.
- Crawl JavaScript apps in a headless browser that stays within accepted scope.
Validate
- Findings with the requests that prove them, which you can edit, confirm, close and export as Markdown, HTML or JSON.
AI and automation
- A read-only MCP server so Claude Code can see traffic, the map, scope and findings, and Ask Claude from any request, finding or host.
- Skills: playbooks agents follow for a job in Plonix.
- Claude can suggest an edited request on the Bench, shown as a diff you apply or discard. Nothing is sent until you click Send.
- The
plonixcommand and a token-protected local API for everything the window does. - Install Command Line Tool… in the app puts the
plonixcommand on your PATH.
Projects and Market
- Several projects open at once, each in a folder you choose, with a Start screen and Settings.
- The Market: a signed catalog of skills, rule packs, filter packs, payload lists and bundles.
- Sandboxed WebAssembly extensions that analyze traffic and propose findings, without network, file or process access.
- Updates you approve: Plonix asks before it downloads or installs anything.
- A demo project to try every tool without a target.
Trust and privacy
- You accept the license and terms once, on first launch.
- Anonymous usage statistics (counts of features used, never traffic, hosts or anything you type), which you can turn off on first launch, in Settings, or with
PLONIX_NO_ANALYTICS=1. See docs/privacy.md. - Crash reports stay on your Mac; Plonix offers to open a prefilled GitHub issue and never sends anything on its own.
- Documentation at plonix.io/docs.
Opening Plonix the first time
This build is not notarized by Apple yet, so macOS asks before opening it the first time:
- Open
Plonix-macOS.dmgand drag Plonix to Applications. - Open Plonix. When macOS says it can't check the app, click Done.
- Open System Settings › Privacy & Security, scroll down and click Open Anyway next to Plonix, then confirm.
Or, in Terminal: xattr -dr com.apple.quarantine /Applications/Plonix.app