The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers*. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.
For more videos see the links on the wiki videos page.
Interested in a ZAP talk or training event? Not one near you? Contact a Zap Evangelist to arrange one!
Some of ZAP’s features:
- Open source
- Cross platform (it even runs on a Raspberry Pi!)
- Easy to install (using a multi-platform installer builder)
- Completely free (no paid for ‘Pro’ version)
- Ease of use a priority
- Comprehensive help pages
- Fully internationalized
- Translated into over 20 languages
- Community based, with involvement actively encouraged
- Under active development by an international team of volunteers ZAP is a fork of the well regarded Paros Proxy.
- 2019/06/07 Version 2.8.0 released
- 2018/07/26 The ZAP Heads Up Display (HUD) revealed at Bay Area OWASP meetup
- 2017/11/28 Version 2.7.0 released
- 2017/03/29 Version 2.6.0 released
- 2017/02/11 ZAP came second in the Top Security Tools of 2016 as voted by ToolsWatch.org readers
- 2016/06/03 Version 2.5.0 released
- 2016/05/26 ZAP bug bounty program launched
- 2016/02/23 ZAP declared the Top Security Tool of 2015 as voted by ToolsWatch.org readers
ZAP is developed by a worldwide team of volunteers.
But we have also been helped by many organizations, either financially or by encouraging their employees to work on ZAP: