Softwr
OWASP ZAP logo

OWASP ZAP

Free, open-source web application scanner and intercepting proxy, now governed by the Software Security Project.

As of 30 August 2026, OWASP ZAP is free to use. The only full-featured dynamic application security scanner that is free and scriptable, which is why it ends up in pipelines where a per-application commercial licence would never be approved. Softwr lists it under Cybersecurity. OWASP ZAP is made by OWASP Foundation, launched in 2001, available on Windows, macOS, API.

Overview

What OWASP ZAP does

ZAP, the Zed Attack Proxy, is an open-source dynamic application security testing tool released under the Apache 2.0 licence. It works as an intercepting HTTP and HTTPS proxy with a passive scanner that inspects traffic as it passes, an active scanner that sends attack payloads, a traditional spider and an AJAX spider driven by a headless browser, a fuzzer, and an add-on marketplace. It runs as a desktop application, as a headless daemon driven by a documented REST API, and as official Docker images intended for continuous integration. It is written in Java and runs on Windows, macOS and Linux. Started in 2010 by Simon Bennetts as an OWASP flagship project, ZAP moved in August 2024 to the Software Security Project, a separate organisation, with core development sponsored by Checkmarx. Much older documentation and many search results still call it OWASP ZAP. What makes it distinctive is not a detection capability that commercial scanners lack. It is the licensing. Commercial DAST is sold per application or per scan target, which means an organisation with two hundred internal applications tests the twelve it can afford to license, and the rest are never scanned at all. ZAP has no per-target cost, so the constraint moves from procurement to staffing, and the baseline scan can run against everything. For most organisations that shift is worth more than any difference in detection quality, because the applications that get breached are usually the ones nobody was scanning. It is used by application security teams, penetration testers who want an intercepting proxy they can script, and development teams adding a baseline scan to a pipeline. The trade-off is that there is no vendor. Nobody is contractually obliged to fix your broken authentication script before the release, nobody signs off the report for your auditor, and the tuning work that makes the output credible is yours. Teams that adopt ZAP successfully treat it as a tool that needs an owner; teams that treat it as a free replacement for a commercial product usually end up with a pipeline step that always passes and nobody who can say why.

What people use it for

  • Adding a baseline security scan to every application's pipeline where per-target commercial licensing would limit coverage to a handful
  • Manual penetration testing that needs an intercepting proxy, request replay and fuzzing without a paid licence per tester
  • Teaching developers what an attack against their own endpoint looks like, using a tool they can install themselves
  • Pre-release regression scanning of an internal application that would never justify a commercial DAST subscription

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about OWASP ZAP.

  • Authenticated scanning of modern single-page applications is the hard part and ZAP makes you build it by hand: session handling, token refresh and login scripts are configured per application, and a misconfigured session means the scanner logs itself out and reports a clean result for pages it never reached.
  • There is no support contract in the product, so when a scan breaks the day before a release the escalation path is a GitHub issue and a community chat, which is not an answer that satisfies a delivery manager or an auditor who wants a named responsible party.
  • Active scanning sends genuine attack traffic, so it can create records, trigger emails, exhaust rate limits or destabilise a fragile environment, and pointing it at production without prior agreement produces an incident rather than a test result.
  • Output needs triage: passive rules generate large volumes of low-severity informational findings about headers and cookie flags that bury the few results that matter, and a team without someone tuning the rule set stops reading the report within a few sprints.
  • As a dynamic scanner it can only test what it can reach, so authorisation flaws between accounts, business logic abuse and anything behind an undiscovered endpoint go unreported, and a passing ZAP scan is evidence of nothing more than the absence of the classes of bug it looks for.

Cross-shopped

What people choose instead of OWASP ZAP

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

Pricing

What OWASP ZAP costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Free & Open Source

Free

  • Full functionality
  • Active & passive scanning
  • Spider
  • Fuzzer
  • API support
  • Extensions marketplace

Capabilities

Features

  • Intercepting proxy

    Sits between browser and application so requests and responses can be inspected, modified and replayed by hand

  • Passive scanner

    Analyses traffic that already passed through the proxy without sending any additional requests to the target

  • Active scanner

    Sends crafted attack payloads against discovered endpoints and parameters to confirm exploitable behaviour

  • AJAX spider

    Drives a headless browser to discover routes in single-page applications that a traditional crawler cannot see

  • Automation Framework

    Declarative YAML job definitions so a scan is version-controlled configuration rather than console clicks

  • Headless daemon and REST API

    Full control of scanning from scripts and pipelines without the desktop interface

  • Docker images

    Official images including baseline and full-scan entry points designed for continuous integration

  • Add-on marketplace

    Community and core extensions for additional rules, reporting formats, protocols and integrations

  • Scripting engine

    Custom authentication, payload and rule scripts in JavaScript and other JSR-223 languages

  • Apache 2.0 licence

    Free for commercial use, modification and redistribution with no per-application or per-scan cost

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Is it still called OWASP ZAP?

The project left OWASP in August 2024 and is now governed by the Software Security Project, with core development sponsored by Checkmarx. The tool is now just ZAP, though most existing documentation, courses and search results still use the OWASP name.

Is it free for commercial use?

Yes. It is Apache 2.0 licensed, with no per-application, per-scan or per-user cost, and it can be used and modified commercially without a licence agreement.

Can it replace a penetration test?

No. It automates checks for known vulnerability classes against endpoints it can reach. It does not reason about business logic, chain findings into an attack, or test authorisation between accounts, which is most of what a tester actually does.

Does it run in CI?

Yes, through the official Docker images and the Automation Framework, which defines scan jobs in YAML so configuration lives in the repository. A baseline passive scan is the usual starting point because it is fast and non-intrusive.

How does it compare to Burp Suite?

Burp Suite Professional is the more polished manual testing tool and has a stronger scanner and extension ecosystem, but it is licensed per tester and Burp Suite Enterprise per target. ZAP is the better fit where cost per target is the binding constraint; many teams use both.

Behind it

Who makes OWASP ZAP

Company
OWASP Foundation
Based in
Global (Non-profit)
Share

Keep looking

Where to go from OWASP ZAP

Best Cybersecurity software for

Compare OWASP ZAP with

Other Cybersecurity software

  • The world's most-loved password manager

    From $2.99/mo10 researched notes
  • Powerful protection against evolving threats

    From $36/yr14 researched notes
  • Simplify online life with LastPass password manager

    Free plan12 researched notes
  • Open source password management for everyone

    Free, then $1.65/mo12 researched notes
  • The leading toolkit for web security testing

    Free, then $449/yr11 researched notes
  • The world's most used penetration testing framework

    Free plan11 researched notes
  • The world's foremost network protocol analyzer

    Free plan8 researched notes
  • Open-source identity provider with flexible authentication flows

    Free plan9 researched notes
  • Open-source authentication and two-factor portal for reverse proxies

    Open source9 researched notes
  • Security infrastructure for developers and AI agents

    Free, then $20/mo10 researched notes
  • Open-source vulnerability and misconfiguration scanner

    Open source7 researched notes
  • Real-time transaction fraud and financial crime detection for banks and payment processors

    Pricing on request10 researched notes
  • Customer identity and access management platform for SaaS applications

    Free plan9 researched notes
  • Identity-aware session broker for infrastructure access without distributing credentials

    Open source12 researched notes
  • Unified identity and device management for hybrid workforce.

    From $9/user/month12 researched notes
  • Security infrastructure for developers and AI agents

    Free, then $20/mo10 researched notes

Softwr does not host reviews and shows no star rating for OWASP ZAP, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on OWASP ZAP

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare OWASP ZAP with alternatives