
OWASP ZAP is a free open-source DAST proxy and web application security scanner for finding vulnerabilities in running apps.
OWASP ZAP is an open-source dynamic application security testing tool for scanning running web applications, intercepting traffic, automating security tests, and finding exploitable vulnerabilities.
ZAP is an independent open-source project with contributions from a global community, ensuring transparency and continuous improvement.
Provides automated scanning options to detect common web application vulnerabilities efficiently.
Users can extend ZAP's functionality by installing community-contributed add-ons from the ZAP Marketplace.
Offers various automation options to integrate security testing into CI/CD pipelines and automated workflows.
Includes detailed user guides, developer documentation, and quick start materials to assist users at all skill levels.
Features an authentication decision tree to configure ZAP to authenticate with target applications for accurate scanning.
Provides official Docker images for easy deployment and integration in containerized environments.
Generates detailed alerts and reports on identified security issues to assist in remediation efforts.
Obtain the latest version of ZAP from the official website and install it on your system.
Set up the web application URL and configure authentication if required using the authentication decision tree.
Initiate an automated scan to detect common vulnerabilities and security issues.
Analyze the detailed alerts generated by ZAP to identify potential security risks.
Browse and install add-ons from the ZAP Marketplace to enhance scanning capabilities.
Use ZAP's automation features or Docker images to incorporate security testing into CI/CD pipelines.
Pricing details are gathered from the official OWASP ZAP website and are provided for reference only. Always confirm the latest information directly with the vendor.
| Plan | Price | Highlights |
|---|---|---|
| Free | $0 | Full access to all features
|
Explore tools grouped by use case so you can keep researching without losing momentum.
Compare other vetted products our editors see buyers evaluate alongside OWASP ZAP.