OWASP ZAP

OWASP ZAP

OWASP
+
+

Related Products

  • Aikido Security
    123 Ratings
    Visit Website
  • Astra Pentest
    219 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • Carbide
    88 Ratings
    Visit Website
  • KrakenD
    71 Ratings
    Visit Website
  • NetNut
    575 Ratings
    Visit Website
  • Jscrambler
    33 Ratings
    Visit Website
  • DataDome
    221 Ratings
    Visit Website
  • Parasoft
    136 Ratings
    Visit Website
  • UTunnel VPN and ZTNA
    119 Ratings
    Visit Website

About

OWASP ZAP (Zed Attack Proxy) is a free, open-source penetration testing tool being maintained under the umbrella of the Open Web Application Security Project (OWASP). ZAP is designed specifically for testing web applications and is both flexible and extensible. At its core, ZAP is what is known as a “man-in-the-middle proxy.” It stands between the tester’s browser and the web application so that it can intercept and inspect messages sent between browser and web application, modify the contents if needed, and then forward those packets on to the destination. It can be used as a stand-alone application, and as a daemon process. ZAP provides functionality for a range of skill levels – from developers, to testers new to security testing, to security testing specialists. ZAP has versions for each major OS and Docker, so you are not tied to a single OS. Additional functionality is freely available from a variety of add-ons in the ZAP Marketplace, accessible from within the ZAP client.

About

OpenText Static Application Security Testing (SAST) identifies and remediates security vulnerabilities in source code early in the software development lifecycle. It supports extensive language coverage and integrates seamlessly with popular CI/CD tools such as Jenkins, Azure DevOps, Jira, and Visual Studio. The platform uses advanced static code analysis and AI-driven insights to prioritize risks and reduce false positives, enabling developers to focus on fixing critical vulnerabilities efficiently. With its customizable code analysis and rule sets, it helps reduce development time by catching issues early. OpenText SAST complies with industry standards like OWASP and offers flexible deployment options including SaaS, private cloud, and on-premises. This comprehensive approach enhances application security without sacrificing development speed or accuracy.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

A Security Testing application for DevOps teams or companies

Audience

Development and security teams seeking a comprehensive, AI-enhanced static application security testing solution integrated into CI/CD pipelines to identify and remediate vulnerabilities early

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

No information available.
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

OWASP
Founded: 2001
United States
www.zaproxy.org

Company Information

OpenText
Founded: 1991
Canada
www.opentext.com/products/static-application-security-testing

Alternatives

Caido

Caido

Caido Labs Inc.

Alternatives

Burp Suite

Burp Suite

PortSwigger
SonarQube Cloud

SonarQube Cloud

SonarSource
PT Application Inspector

PT Application Inspector

Positive Technologies

Categories

Categories

Application Security Features

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

Integrations

Nucleus
Phoenix Security
ThreadFix
Azure DevOps Server
Bitbucket
Bugzilla
CyCognito
Dradis
FuzzDB
HivePro Uni5
IriusRisk
Jenkins
Maverix
Microsoft 365
Parasoft
Prancer
Seeker
Selenium
Snyk
Tromzo

Integrations

Nucleus
Phoenix Security
ThreadFix
Azure DevOps Server
Bitbucket
Bugzilla
CyCognito
Dradis
FuzzDB
HivePro Uni5
IriusRisk
Jenkins
Maverix
Microsoft 365
Parasoft
Prancer
Seeker
Selenium
Snyk
Tromzo
Claim OWASP ZAP and update features and information
Claim OWASP ZAP and update features and information
Claim OpenText Static Application Security Testing and update features and information
Claim OpenText Static Application Security Testing and update features and information