The OWASP ZAP homepage
Score7.0
Rank#7 of 34
PriceFree
Free planYes
Runs onAPI, Linux, macOS, Self-hosted, Windows

Summary

OWASP ZAP, now identified as ZAP or ZAP by Checkmarx, is a free, open-source web application scanner and proxy for security testing. Its scanner includes active and passive scanning, a spider, alerts, and scan policies. Users can add extensions through an online Marketplace; add-ons are typically installed or removed without restarting the application. The Automation Framework runs from YAML plans and supports work such as scans, spidering, API imports, and report generation. GitHub Actions are available for baseline, full, and API scans through Docker-packaged scans. API definitions in OpenAPI, GraphQL, SOAP, and Postman formats can be imported through framework jobs or add-ons. ZAP publishes Docker images, including a minimal image described as suitable for CI. It supports Linux, macOS, Windows, API use, and self-hosted deployment. Windows and Linux installers need Java 17 or later; the macOS installer includes Java 17. The project says it can support only its latest full release, and current releases are unsigned, with checksums provided for downloads.

Who it is for

ZAP is intended for developers, testers new to security testing, and security testing specialists. Its automation and Docker options also suit teams incorporating scans into CI workflows.

What is good

  • Free and open source.
  • Active and passive scanning are included.
  • YAML automation plans support scans and reports.
  • GitHub Actions support baseline, full, and API scans.
  • API definitions can be imported in four formats.

What to know first

  • Windows and Linux installers require Java 17 or higher.
  • Only the latest full release is supported by the team.
  • Current releases are unsigned.
  • macOS installer bundles Java 17; other installers do not.

Everything Xiaomi review

OWASP ZAP: the full review

ZAP offers scanning, extensibility, and automation in a free, open-source package. Check the Java requirements for Windows or Linux and verify downloads with the provided checksums.

Overview

OWASP ZAP is a self-hosted web application scanner and proxy for security testing, aimed at developers, testers new to security work, and security specialists. Its strongest case is broad, configurable scanning and automation at no software cost; its self-hosted setup and Java requirement on Windows and Linux make it less suitable for teams seeking a managed service.

Key features

Scanning and traffic inspection

Active and passive scanning, a spider, alerts, and scan policies cover discovery and assessment in one tool. The spider helps find application paths, passive scanning checks observed traffic, and active scanning sends tests to the application.

Add-ons and automation

ZAP’s online Marketplace lets users install add-ons dynamically, typically without restarting. This makes it practical to tailor the tool as needs change, though a team must still manage its own setup.

The Automation Framework runs from a YAML plan and supports active and passive scans, spidering, API imports, and report generation. It can import OpenAPI, GraphQL, SOAP, and Postman definitions through jobs or add-ons. GitHub Actions support baseline, full, and API scans through Docker-packaged scans, and a minimal Docker image is available for CI. These options make ZAP a credible fit for repeatable pipeline checks, not just interactive use.

Deployment and project status

ZAP is self-hosted and publishes Docker images. Windows and Linux installers require Java 17 or higher; the macOS installer includes Java 17. The download page says the team can support only the latest full release, and warns that current releases are unsigned while providing checksums. Users should verify downloads against those checksums.

ZAP says it has not been an OWASP project since August 2023 and identifies its current name as ZAP or ZAP by Checkmarx. This is worth knowing when seeking current project information or support. Products and services including DefectDojo, Dradis, and Faraday can import ZAP results.

Pricing

ZAP is free and open source, and anyone can contribute. Its ZAP plan costs 0.00 USD per free and includes access to the Marketplace add-ons. There is no paid tier or trial described; the trade-off is that ZAP is self-hosted rather than a hosted service, so it suits users prepared to handle deployment and upkeep.

Platforms

ZAP supports Linux, macOS, Windows, API workflows, and self-hosted deployment. The platform range accommodates desktop and pipeline use, but the Java requirement on Windows and Linux adds a setup consideration that macOS users avoid because its installer includes Java 17.

Who it's for

ZAP is a strong choice for developers and testers learning application security, as well as specialists who want configurable scans and automation without software fees. API testing, authenticated scanning, browser-based scanning, and CI/CD integration broaden its use across application testing workflows. It is a weaker fit for organizations that want a vendor-managed scanner or support across older full releases.

Pros and cons

  • Pros: Free and open source, with Marketplace add-ons that can usually be installed or removed without a restart.
  • Pros: YAML-driven automation, Docker scans, and GitHub Actions support make repeatable CI checks practical.
  • Pros: Imports OpenAPI, GraphQL, SOAP, and Postman definitions, supporting varied API workflows.
  • Cons: Self-hosted deployment means users must manage the runtime and environment themselves.
  • Cons: Windows and Linux installers require Java 17 or higher, and only the latest full release is supported by the team.
  • Cons: Current releases are unsigned, so users need to verify downloads with checksums.

Alternatives

For a different option, compare Dynamic Application Security Testing Software, Web Application Security Scanners, and Penetration Testing Software.

  • Beagle Security may suit readers who want a freemium option with a defined free allowance: one lite test per month, monthly surface scan reports, and SSL and domain-expiry monitoring. Its Essential plan is 99.00 USD per month, billed Billed $1188 annual.
  • Veracode DAST is a paid alternative with a free trial and a live-demo option for web applications and APIs.
  • Bright Security DAST is a paid alternative that offers a demo request.
  • Tenable One Attack Surface Management is a paid alternative with demo or quote requests.
  • Detectify Surface Monitoring is a paid web platform that also has a free plan.
  • Rapid7 Surface Command is a paid option with a free trial, focused on asset discovery, unified inventory, and internal and external attack-surface visibility.
  • Safeguard DAST is a freemium web option with a free plan.
  • Wapiti is another free option for Windows, macOS, and Linux.

Verdict

Choose ZAP if you want a free, adaptable web application scanner with API coverage and automation that can fit into CI. Its main advantage is the combination of scanning depth and extensibility without a software charge; look elsewhere if you need hosted deployment or do not want to maintain a Java-based setup on Windows or Linux.

OWASP ZAP plans and pricing

All plans
ZAP Free Free and open source · add-ons available in the Marketplace zaproxy.org · 29 Sept 2026

Compared on penetration testing software

Free plan
Yeszaproxy.org
Authenticated scanning
Yeszaproxy.org
API testing
Yeszaproxy.org
Browser-based scanning
Yeszaproxy.org
CI/CD integration
Yeszaproxy.org
Deployment model
self_hostedzaproxy.org

Facts

Purpose
ZAP is a web application scanner and proxy for security testing.zaproxy.org · 29 Sept 2026
Open source
ZAP describes itself as free and open source, and says anyone can contribute to the project.zaproxy.org · 29 Sept 2026
Scanner
ZAP provides active scanning, passive scanning, a spider, alerts, and scan policies.zaproxy.org · 29 Sept 2026
Add-ons
Add-ons can be installed dynamically from the online Marketplace, and are typically added or removed without restarting ZAP.zaproxy.org · 29 Sept 2026
Automation
The Automation Framework controls ZAP with a YAML plan and supports jobs including active scanning, passive scanning, spidering, API imports, and report generation.zaproxy.org · 29 Sept 2026
CI integration
ZAP provides GitHub Actions for baseline, full, and API scans through its Docker packaged scans.zaproxy.org · 29 Sept 2026
API formats
The Automation Framework supports importing OpenAPI, GraphQL, SOAP, and Postman definitions through jobs or add-ons.zaproxy.org · 29 Sept 2026
Deployment
ZAP publishes Docker images, including a bare image described as minimal and ideal for CI.zaproxy.org · 29 Sept 2026
Audience
ZAP says it is designed for developers, testers new to security testing, and security testing specialists.zaproxy.org · 29 Sept 2026
Runtime requirement
The Windows and Linux installers require Java 17 or higher, while the macOS installer includes Java 17.zaproxy.org · 29 Sept 2026
Release support
The download page says the ZAP team can support only the latest full release.zaproxy.org · 29 Sept 2026
Download security
The download page warns that current ZAP releases are unsigned and provides checksums for downloads.zaproxy.org · 29 Sept 2026
Project status
ZAP says it has not been an OWASP project since August 2023 and identifies its current name as ZAP or ZAP by Checkmarx.zaproxy.org · 29 Sept 2026
Third-party integrations
ZAP lists DefectDojo, Dradis, and Faraday among products and services that can import ZAP results.zaproxy.org · 29 Sept 2026

Company

Founded
2010zaproxy.org · 23 Sept 2026

Best OWASP ZAP alternatives

See all 12

Where it ranks on Everything Xiaomi

Is OWASP ZAP yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources