ZAP
Free, open-source web application scanner and intercepting proxy for finding vulnerabilities in web apps, manually or in automated pipelines.
- Category
- Application Security
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 24 September 2026
What it is
ZAP (Zed Attack Proxy) is an open-source web application security scanner and proxy, maintained with backing from Checkmarx. It runs on desktop systems and is also available as Docker images.
What it helps with
Intercepting and inspecting web traffic, spidering applications, and running passive and active scans for common vulnerabilities. Its automation framework and Docker images make it a common choice for scanning inside CI/CD pipelines.
Who it's for
Developers, QA and AppSec teams adding security testing to their workflow, and testers who want a free alternative for proxy-based testing.
Worth knowing
An add-on marketplace extends its features. Active scans send attack traffic, so run them only against applications you are authorised to test.