Skip to main content

Tool Information

FieldDetails
ToolOWASP ZAP
CategoryWeb Application Security Scanner
LicenseApache License 2.0
Source Codehttps://github.com/zaproxy/zaproxy
Documentationhttps://www.zaproxy.org/docs/
Community Scriptshttps://github.com/zaproxy/community-scripts

OWASP ZAP is a widely used dynamic application security testing (DAST) tool for detecting vulnerabilities in web applications and APIs.


Dashboards Using This Tool

Dashboard
Web Application

Scanners Available

Unauthenticated Scan

Scans public-facing web applications and APIs for OWASP Top 10 vulnerabilities such as:

  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Security misconfigurations

This scan does not require login credentials.


Authenticated (Credentialed) Scan

Performs deeper security testing using login credentials.

This scan helps identify vulnerabilities across:

  • Authenticated user areas
  • Role-based access control
  • Protected APIs
  • Business logic flaws

OWASP ZAP Web & API Scanner

Actively scans web applications and APIs for security vulnerabilities including:

  • Injection flaws
  • XSS
  • Broken authentication
  • Security misconfigurations

Scanner Options

OptionDescription
Run Aggressive Web ScanningEnables extended crawling and active attack testing
Scan Infrastructure LayerDetect vulnerable services, weak SSL, and infrastructure misconfigurations
Scan for Known Vulnerabilities (CVEs)Identify vulnerable services and dependencies with known exploits
Enable Advanced Security ChecksEnables advanced testing modules during Authenticated scans