beefproject/beef

The Browser Exploitation Framework Project

View on GitHub ↗Jump to charts ↓Open shareable report

Summary Information

Updated 34 minutes ago
Added to GitGenius on September 5th, 2026
Created on November 23rd, 2011
Open Issues & Pull Requests: 37 (+0)
GitHub issues: Enabled
Number of forks: 2,374
Total Stargazers: 11,008 (+0)
Total Subscribers: 440 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 2.2 hours
Mean response time: 143.2 days
90th percentile: 205.0 days
Tracked items: 172

How this project is maintained

Around half of the issues opened in the past year never receive a reply. Work labelled "Enhancement" is answered fastest, typically in under an hour, while "Maintainability" waits about 7 days. Only 13% of issues opened in the past year have been closed. Three people close 77% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 9
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 1,587 days
Stale 30+ days: 9
Stale 90+ days: 8

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

  • Stale (26)
  • Enhancement (18)
  • Low (18)
  • Question (15)
  • Maintainability (10)
  • Core (9)
  • Defect (9)
  • Autorun Rules Engine (7)

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

BeEF is a penetration testing tool that focuses on assessing web browser security through client-side attack vectors.

BeEF addresses the challenge of evaluating security posture beyond hardened network perimeters by targeting the web browser as an attack surface. The tool hooks one or more web browsers and uses them as beachheads for launching directed command modules and further attacks from within the browser context. This approach examines exploitability in the one consistently open door: the browser itself, rather than relying solely on network or system-level assessments.

BeEF suits professional penetration testers conducting client-side security assessments in environments where web-borne attacks against clients represent a genuine concern. It is particularly valuable for evaluating actual security posture in scenarios where traditional network-focused testing misses browser-based vulnerabilities. The tool runs on Mac OSX or modern Linux systems and requires Ruby, Node.js, and SQLite as dependencies. Prospective users should review the Configuration wiki page for important security setup details before deployment.

The project maintains active community engagement through multiple channels including pull request contributions, issue tracking, and dedicated security reporting. Development activity shows ongoing maintenance with established processes for bug reports and security vulnerability disclosure.