Zed Attack Proxy
Free and open source web app scanner
Zed Attack Proxy (ZAP) is a free, open‑source scanner designed to assess the security of web applications. It offers a graphical interface and a set of tools that enable users to discover vulnerabilities, intercept and modify traffic, and generate reports on findings. The project is maintained by a community of contributors and is listed among GitHub’s Top 1000 repositories, reflecting broad participation and ongoing development.
The tool targets security professionals, developers, and anyone interested in testing web applications for flaws. Newcomers can follow a Quick Start Guide that walks through basic usage, while more experienced users can integrate ZAP into automated testing pipelines using the provided automation options. A marketplace of community‑contributed add‑ons allows further extension of its capabilities.
ZAP runs on macOS and other platforms, and its stable maturity level indicates that it is production‑ready. Its open‑source nature enables users to inspect the code, contribute improvements, and tailor the scanner to specific security testing workflows.
Reviews
Loading reviews…
Similar apps

Network & Connectivity
Burp Suite Community Edition
Web security testing toolkit

Security & Identity
mitmproxy
Interactive intercepting HTTP proxy for penetration testers and software developers.

Network & Connectivity
Zenmap
Multi-platform graphical interface for official Nmap Security Scanner

Network & Connectivity
Caido
Web security auditing toolkit

Security & Identity
SCAP Workbench
SCAP Scanner And Tailoring Graphical User Interface

Network & Connectivity
Angry IP Scanner
Network scanner