DirectoryCybersecurityApplication SecurityOWASP ZAP

OWASP ZAP

Open Source

Open source web application security testing and vulnerability scanning tool

Visit Website

About OWASP ZAP

OWASP ZAP (Zed Attack Proxy) is a widely adopted open source security tool designed for automated and manual testing of web applications. It serves security professionals, developers, and QA teams aiming to identify vulnerabilities early in the software development lifecycle. ZAP provides comprehensive dynamic application security testing (DAST) capabilities with an intuitive interface suitable for both novices and experienced testers.

The tool supports automation and integration into CI/CD pipelines, enabling continuous security assessment. Its extensible architecture includes a marketplace of community-contributed add-ons, enhancing functionality to meet diverse security testing needs. As a community-driven project, ZAP emphasizes transparency and collaboration, making it a cost-effective solution for enterprises seeking robust application security without vendor lock-in.

Key Capabilities

  • βœ“Dynamic application security testing (DAST)
  • βœ“Automated vulnerability scanning
  • βœ“Extensible add-on marketplace
  • βœ“CI/CD pipeline integration
  • βœ“User-friendly interface for all skill levels

Integrations

CI/CD toolsSecurity automation platformsDeveloper IDEs

Related Buyer Guides

Independent evaluation frameworks for this category.

API Security Platforms
The API is now the primary attack surface, and a WAF pointed at it isn't API security. Evaluate Salt, Akamai (Noname), Imperva, F5, Traceable, Wallarm, Cequence, and Data Theorem on whether they actually discover your shadow APIs and catch BOLA and business-logic abuse at runtime β€” not just sign endpoints off as β€œprotected.”
Attack Surface Management (ASM / CTEM)
Evaluate Wiz, CrowdStrike Falcon Surface, Microsoft Defender EASM, Cortex Xpanse, Censys, CyCognito, Tenable, and runZero across EASM, CAASM, and platform-embedded camps β€” judged on discovery accuracy and how cleanly the surface feeds prioritization, not how many assets it claims to find.
Cloud Access Security Broker (CASB)
Evaluate Netskope, Microsoft Defender for Cloud Apps, Zscaler, and Palo Alto for SaaS security, shadow IT discovery, and data protection.

This profile was compiled by CIOPages from public sources with AI assistance, and may be incomplete or out of date. It is informational only and not an endorsement. Represent this vendor? or .

Quick Facts

www.zaproxy.org
CategoryCybersecurity
SubcategoryApplication Security
PricingOpen Source
DeploymentOpen Source
Target SizeEnterprise