
OWASP ZAP
Summary
OWASP ZAP, now identified as ZAP or ZAP by Checkmarx, is a free, open-source web application scanner and proxy for security testing. Its scanner includes active and passive scanning, a spider, alerts, and scan policies. Users can add extensions through an online Marketplace; add-ons are typically installed or removed without restarting the application. The Automation Framework runs from YAML plans and supports work such as scans, spidering, API imports, and report generation. GitHub Actions are available for baseline, full, and API scans through Docker-packaged scans. API definitions in OpenAPI, GraphQL, SOAP, and Postman formats can be imported through framework jobs or add-ons. ZAP publishes Docker images, including a minimal image described as suitable for CI. It supports Linux, macOS, Windows, API use, and self-hosted deployment. Windows and Linux installers need Java 17 or later; the macOS installer includes Java 17. The project says it can support only its latest full release, and current releases are unsigned, with checksums provided for downloads.
Who it is for
ZAP is intended for developers, testers new to security testing, and security testing specialists. Its automation and Docker options also suit teams incorporating scans into CI workflows.
What is good
- Free and open source.
- Active and passive scanning are included.
- YAML automation plans support scans and reports.
- GitHub Actions support baseline, full, and API scans.
- API definitions can be imported in four formats.
What to know first
- Windows and Linux installers require Java 17 or higher.
- Only the latest full release is supported by the team.
- Current releases are unsigned.
- macOS installer bundles Java 17; other installers do not.
Everything Xiaomi review
OWASP ZAP: the full review
ZAP offers scanning, extensibility, and automation in a free, open-source package. Check the Java requirements for Windows or Linux and verify downloads with the provided checksums.
Overview
OWASP ZAP is a self-hosted web application scanner and proxy for security testing, aimed at developers, testers new to security work, and security specialists. Its strongest case is broad, configurable scanning and automation at no software cost; its self-hosted setup and Java requirement on Windows and Linux make it less suitable for teams seeking a managed service.
Key features
Scanning and traffic inspection
Active and passive scanning, a spider, alerts, and scan policies cover discovery and assessment in one tool. The spider helps find application paths, passive scanning checks observed traffic, and active scanning sends tests to the application.
Add-ons and automation
ZAP’s online Marketplace lets users install add-ons dynamically, typically without restarting. This makes it practical to tailor the tool as needs change, though a team must still manage its own setup.
The Automation Framework runs from a YAML plan and supports active and passive scans, spidering, API imports, and report generation. It can import OpenAPI, GraphQL, SOAP, and Postman definitions through jobs or add-ons. GitHub Actions support baseline, full, and API scans through Docker-packaged scans, and a minimal Docker image is available for CI. These options make ZAP a credible fit for repeatable pipeline checks, not just interactive use.
Deployment and project status
ZAP is self-hosted and publishes Docker images. Windows and Linux installers require Java 17 or higher; the macOS installer includes Java 17. The download page says the team can support only the latest full release, and warns that current releases are unsigned while providing checksums. Users should verify downloads against those checksums.
ZAP says it has not been an OWASP project since August 2023 and identifies its current name as ZAP or ZAP by Checkmarx. This is worth knowing when seeking current project information or support. Products and services including DefectDojo, Dradis, and Faraday can import ZAP results.
Pricing
ZAP is free and open source, and anyone can contribute. Its ZAP plan costs 0.00 USD per free and includes access to the Marketplace add-ons. There is no paid tier or trial described; the trade-off is that ZAP is self-hosted rather than a hosted service, so it suits users prepared to handle deployment and upkeep.
Platforms
ZAP supports Linux, macOS, Windows, API workflows, and self-hosted deployment. The platform range accommodates desktop and pipeline use, but the Java requirement on Windows and Linux adds a setup consideration that macOS users avoid because its installer includes Java 17.
Who it's for
ZAP is a strong choice for developers and testers learning application security, as well as specialists who want configurable scans and automation without software fees. API testing, authenticated scanning, browser-based scanning, and CI/CD integration broaden its use across application testing workflows. It is a weaker fit for organizations that want a vendor-managed scanner or support across older full releases.
Pros and cons
- Pros: Free and open source, with Marketplace add-ons that can usually be installed or removed without a restart.
- Pros: YAML-driven automation, Docker scans, and GitHub Actions support make repeatable CI checks practical.
- Pros: Imports OpenAPI, GraphQL, SOAP, and Postman definitions, supporting varied API workflows.
- Cons: Self-hosted deployment means users must manage the runtime and environment themselves.
- Cons: Windows and Linux installers require Java 17 or higher, and only the latest full release is supported by the team.
- Cons: Current releases are unsigned, so users need to verify downloads with checksums.
Alternatives
For a different option, compare Dynamic Application Security Testing Software, Web Application Security Scanners, and Penetration Testing Software.
- Beagle Security may suit readers who want a freemium option with a defined free allowance: one lite test per month, monthly surface scan reports, and SSL and domain-expiry monitoring. Its Essential plan is 99.00 USD per month, billed Billed $1188 annual.
- Veracode DAST is a paid alternative with a free trial and a live-demo option for web applications and APIs.
- Bright Security DAST is a paid alternative that offers a demo request.
- Tenable One Attack Surface Management is a paid alternative with demo or quote requests.
- Detectify Surface Monitoring is a paid web platform that also has a free plan.
- Rapid7 Surface Command is a paid option with a free trial, focused on asset discovery, unified inventory, and internal and external attack-surface visibility.
- Safeguard DAST is a freemium web option with a free plan.
- Wapiti is another free option for Windows, macOS, and Linux.
Verdict
Choose ZAP if you want a free, adaptable web application scanner with API coverage and automation that can fit into CI. Its main advantage is the combination of scanning depth and extensibility without a software charge; look elsewhere if you need hosted deployment or do not want to maintain a Java-based setup on Windows or Linux.
OWASP ZAP plans and pricing
All plansCompared on penetration testing software
- Free plan
- Yeszaproxy.org
- Authenticated scanning
- Yeszaproxy.org
- API testing
- Yeszaproxy.org
- Browser-based scanning
- Yeszaproxy.org
- CI/CD integration
- Yeszaproxy.org
- Deployment model
- self_hostedzaproxy.org
Facts
- Purpose
- ZAP is a web application scanner and proxy for security testing.zaproxy.org · 29 Sept 2026
- Open source
- ZAP describes itself as free and open source, and says anyone can contribute to the project.zaproxy.org · 29 Sept 2026
- Scanner
- ZAP provides active scanning, passive scanning, a spider, alerts, and scan policies.zaproxy.org · 29 Sept 2026
- Add-ons
- Add-ons can be installed dynamically from the online Marketplace, and are typically added or removed without restarting ZAP.zaproxy.org · 29 Sept 2026
- Automation
- The Automation Framework controls ZAP with a YAML plan and supports jobs including active scanning, passive scanning, spidering, API imports, and report generation.zaproxy.org · 29 Sept 2026
- CI integration
- ZAP provides GitHub Actions for baseline, full, and API scans through its Docker packaged scans.zaproxy.org · 29 Sept 2026
- API formats
- The Automation Framework supports importing OpenAPI, GraphQL, SOAP, and Postman definitions through jobs or add-ons.zaproxy.org · 29 Sept 2026
- Deployment
- ZAP publishes Docker images, including a bare image described as minimal and ideal for CI.zaproxy.org · 29 Sept 2026
- Audience
- ZAP says it is designed for developers, testers new to security testing, and security testing specialists.zaproxy.org · 29 Sept 2026
- Runtime requirement
- The Windows and Linux installers require Java 17 or higher, while the macOS installer includes Java 17.zaproxy.org · 29 Sept 2026
- Release support
- The download page says the ZAP team can support only the latest full release.zaproxy.org · 29 Sept 2026
- Download security
- The download page warns that current ZAP releases are unsigned and provides checksums for downloads.zaproxy.org · 29 Sept 2026
- Project status
- ZAP says it has not been an OWASP project since August 2023 and identifies its current name as ZAP or ZAP by Checkmarx.zaproxy.org · 29 Sept 2026
- Third-party integrations
- ZAP lists DefectDojo, Dradis, and Faraday among products and services that can import ZAP results.zaproxy.org · 29 Sept 2026
Company
- Founded
- 2010zaproxy.org · 23 Sept 2026
Best OWASP ZAP alternatives
See all 12Where it ranks on Everything Xiaomi
Is OWASP ZAP yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- zaproxy.org· checked 29 Sept 2026
- zaproxy.org/docs/desktop/start/features/· checked 29 Sept 2026
- zaproxy.org/docs/desktop/start/features/addons/· checked 29 Sept 2026
- zaproxy.org/docs/automate/automation-framework/· checked 29 Sept 2026
- zaproxy.org/docs/docker/about/· checked 29 Sept 2026
- zaproxy.org/download/· checked 29 Sept 2026
- zaproxy.org/getting-started/· checked 29 Sept 2026
- zaproxy.org/docs/nowaspzap/· checked 29 Sept 2026
- zaproxy.org/third-party-services/· checked 29 Sept 2026
