ZAP

Open-source web application security scanner and intercepting proxy.

These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.

3 more ways to get ZAP

Package managers

About ZAP

ZAP, the Zed Attack Proxy, sits between a browser and a web application so requests can be inspected, modified and replayed, and adds passive and active scanning, spidering, fuzzing, an API and scripting for automated testing in CI.

Strengths

  • Intercepting proxy plus automated scanning in one free tool
  • API and automation framework make it usable inside CI pipelines

Limitations

  • Active scanning can damage a live application and must only be run with permission
  • Java application with a heavy interface

Details

Pricing
FreeFree and open source under the Apache licence.
License
Apache-2.0
Developer
The ZAP Project
Platforms
Windows, macOS, Linux
How it runs
Downloadable app
Best suited for
Open-source web application security scanner and intercepting proxy
Categories
Security tools
Last verified
Added
Provenance
Selected from the TechWalrus Resource Hub (Cybersecurity & Pentesting); facts checked against the developer's own pages, 2 sources on file.

Report a wrong fact or a dead link on this listing