Application Security
Application Security covers tools that find, prevent, and fix weaknesses in software before and after it ships. That includes static and dynamic testing, software composition analysis, API and container checks, runtime protection, and related workflows for web, mobile, and cloud apps. Use this category when you need to harden code, dependencies, and running services rather than probe networks or operate systems.
2 listings
ZAP
Free, open-source web application scanner and intercepting proxy for finding vulnerabilities in web apps, manually or in automated pipelines.

Burp Suite
Web application security testing toolkit built around an intercepting proxy, with a free Community Edition and paid professional and enterprise editions.