Softwr
OWASP ZAP logo

OWASP ZAP

Free security testing tool for web applications

Overview

What OWASP ZAP does

OWASP ZAP (Zed Attack Proxy) is a free, open-source web application security scanner. It is one of the most active OWASP projects and is designed to be used by both security professionals and developers.

What people use it for

  • Penetration Testing
  • Web Security
  • Open Source

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about OWASP ZAP.

  • OWASP ZAP is free and open source with no official paid enterprise support contract available from OWASP; support is community-only (mailing lists, GitHub issues).

Pricing

What OWASP ZAP costs

Taken from the vendor's own pricing page. Prices move, so check before you buy.

Free & Open Source

Free

  • Full functionality
  • Active & passive scanning
  • Spider
  • Fuzzer
  • API support
  • Extensions marketplace

Capabilities

Features

  • Active scanner

    Active scanner capability

  • Passive scanner

    Passive scanner capability

  • Spider/crawler

    Spider/crawler capability

  • Fuzzer

    Fuzzer capability

  • Forced browse

    Forced browse capability

  • WebSocket testing

    WebSocket testing capability

  • AJAX spider

    AJAX spider capability

  • Authentication support

    Authentication support capability

  • API scanning

    API scanning capability

  • Jenkins

    Integration with Jenkins

  • GitHub Actions

    Integration with GitHub Actions

  • GitLab CI

    Integration with GitLab CI

Behind it

Who makes OWASP ZAP

Company
OWASP Foundation
Based in
Global (Non-profit)

Keep looking

Where to go from OWASP ZAP

Other Security Cybersecurity software

Softwr does not host reviews and shows no star rating for OWASP ZAP, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on OWASP ZAP