OWASP Zed Attack Proxy (ZAP) is an easy-to-use integrated penetration testing tool for finding vulnerabilities in Web applications. It is designed to be used by people with a wide range of security experience and as such is ideal for developers and functional testers who are new to penetration testing as well as being a useful addition to an experienced pen tester's toolbox. ZAP provides automated scanners as well as a set of tools that allow you to find security vulnerabilities manually.
| Tags | Proxy Testing hacking penetration developers owasp |
|---|---|
| Licenses | Apache 2.0 |
| Operating Systems | Linux Java Runtime Environment 6 Windows Mac OS |
| Implementation | Java 1.6+ |
| Translations | Brazilian Portuguese German Polish Spanish French Japanese Chinese Greek Indonesian Danish Persian Filipino Italian Russian |
Last announcement
Download the latest language pack from https://code.google.com/p/zaproxy/downloads/list
Thanks to Mohsen Mostafa Jokar
Recent releases


Release Notes: Minor enhancements and lots of bugfixes.


Release Notes: An online marketplace, new traditional and AJAX spiders, Web sockets support, and many other changes.


Release Notes: This is a bugfix release.


Release Notes: This release adds the following main features: syntax highlighting; fuzzdb integration; parameter analysis; an enhanced XSS scanner; a port of some of the Watcher checks; and pluggable extensions. There are many bugfixes.


Release Notes: This is a bugfix and usability release.
C++ template classes implementing a B+ tree key/data container in main memory.