Skip to content

OWASP ZAP

Automated security scanner for finding vulnerabilities in web applications. Proxy, fuzzer, and scanner in one.

Self-hostedNot yet verified
Report issueDemo online
Apache-2.0★ 13500

Open the official app on www.zaproxy.org

This tool is hosted by its maintainers. Click below to open www.zaproxy.org in a new tab — it's their official demo.

Browse security tools →

What's next with OWASP ZAP?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is OWASP ZAP?

OWASP ZAP is a free web app vulnerability scanner tool used by security professionals and researchers.

How it works

How OWASP ZAP works — see the article below for details on this security tools tool.

How to use it

  1. 1Open the OWASP ZAP tool, enter your input, and get your result instantly.

What it can do

  • web app vulnerability scanner

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/zaproxy/zaproxy
  • license: Apache-2.0 — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Self-hosted — requires setup, maintenance, and your own infrastructure.
  • Relies on an external source (github.com); availability depends on that service.
  • Focused on the security tools category: Automated security scanner for finding vulnerabilities in web applications. Proxy, fuzzer, and scanner in one..

Understanding the result

Automated security scanner for finding vulnerabilities in web applications. Proxy, fuzzer, and scanner in one.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (Apache-2.0).
Built with
(zaproxy/zaproxy)
License
Apache-2.0
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with zaproxy/zaproxy. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
Apache-2.0
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Spotted something wrong with OWASP ZAP, or want to maintain it? See how to help.