ZAP (zaproxy)

LSE top 100LSE top 100ZAP (16)ZAP (16)

Tool and Usage

The OWASP Zed Attack Proxy (ZAP) helps to find security vulnerabilities in web applications during development and testing.

Screenshot for ZAP tool review

Introduction

ZAP is an intercepting proxy of web traffic. You will need to configure your browser to connect to the web application you wish to test through ZAP.

Note: Zed Attack Proxy, or ZAP, is also known as zaproxy.

Usage and audience

ZAP is commonly used for penetration test, security assessment, or software testing. Target users for this tool are pentesters and security professionals.

Tool review

The review and analysis of this project resulted in the following remarks for this security tool:

Strengths

  • + More than 50 contributors
  • + More than 2000 GitHub stars
  • + Many maintainers
  • + The source code of this software is available

Weaknesses

  • - Many reported issues are still open

History and highlights

  • Demoed at Black Hat Europe 2016

Author and Maintainers

ZAP is under development by Simon Bennetts. This project is currently maintained by Goran Sarenkapa, Ricardo Pereira, Rick Mitchell, Sherif Mansour, Simon Bennetts.

Installation

Support operating systems

ZAP is known to work on Linux, macOS, and Microsoft Windows.

This tool page was recently updated. Found an improvement? Become an influencer and submit an update.
Project details
Latest release2.6.0 [2017-03-29]
License(s)Apache License 2.0
Last updatedSept. 19, 2017

Project health

100
This score is calculated by different factors, like project age, last release date, etc.

Links

GitHub iconzaproxy GitHub project
Twitter icon@zaproxy
 zaproxy project website

Related terms