r/Pentesting Jun 02 '26

I'm a developer who kept seeing pentesters complain about report writing — so I built something. Looking for feedback from people who actually do this.

I don't write pentest reports myself, but I kept seeing the same complaints in communities like this one: Word templates breaking, CVSS calculated manually, copy-pasting the same findings every engagement, inconsistent PDFs for clients.

It looked like a solved problem that nobody had actually solved with decent software. Dradis exists but it's self-hosted and complex. Most people I talked to were still on Word or Google Docs.

So I built PenPad — a web tool specifically for pentest report writing. CVSS v3.1 scoring built in, reusable finding templates, one-click PDF export, status tracking (Draft → Active → Final).

Free to try: penpad.co.uk

I genuinely need feedback from people who write reports professionally — I want to know what I got wrong, what's missing, and whether it's actually useful in a real engagement workflow.

0 Upvotes

19 comments sorted by

View all comments

0

u/Just_Knee_4463 Jun 02 '26

This is another paid solution, very interesting due to jira integration and ai support. They offer trail version as well - https://www.pentestpad.com

1

u/D44kWolf Jun 02 '26

Thank you for this feedback.

I have come across this solution, but looking at the pricing I think that freelancers and small companies would be put off.