# Endor Labs vs OWASP ZAP

**Leader by Vioscale score:** Endor Labs

| Attribute | Endor Labs | OWASP ZAP |
|---|---|---|
| **Vioscale score** | 65.2 (71% (medium)) | 51.1 (41% (low)) |
| activity.commits_last_30d | - | 34 |
| adoption.dependent_repos | - | 30 |
| adoption.github_stars | - | 15,685 |
| deployment.options | `{"cloud":true,"hybrid":true,"self_hosted":true}` | `{"self_hosted":true}` |
| description.long | An AI-powered application security platform combining static analysis, dependency scanning, and container image scanning with reachability-based prioritization to reduce false positives and enable automated vulnerability remediation across the development lifecycle. | An open-source security scanner that performs dynamic analysis on web applications to detect potential vulnerabilities. It supports automation, extensibility through community add-ons, and integrates with CI/CD pipelines. |
| features.capabilities | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":false,"iac_scanning":false,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":false}` | `{"dast":true,"hosting":"self","ci_native":true,"open_source":true}` |
| integrations.count | 10 | 2 |
| integrations.list | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"BitBucket"},{"name":"Azure DevOps"},{"name":"AWS Marketplace"},{"name":"Microsoft Azure"},{"name":"Google Cloud Marketplace"},{"name":"Wiz"},{"name":"Cursor AI"},{"name":"Microsoft Defender for Cloud"}]` | `[{"name":"GitHub"},{"name":"GitHub Actions"}]` |
| language.primary | - | Java |
| license.spdx | - | Apache-2.0 |
| market.availability | `{"hqCountry":"US","primaryMarkets":["US"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` | - |
| platform.support | `{"cli":true,"web":true}` | - |
| pricing | `{"type":"subscription","plans":[{"free":true,"name":"Developer","summary":"Free for individual developers","features":["Local scanning","Read-only vulnerability data"],"description":"Free tier for individual developers with local scanning and read-only access to vulnerability data","contactSales":false},{"free":false,"name":"Core","description":"Team-oriented tier with reachability analysis, prioritization, and policies","contactSales":false},{"free":false,"name":"Pro","description":"Enterprise-scale tier with advanced detection, triage, and fix capabilities across application layers","contactSales":false}],"summary":"Seat-based subscription pricing with free Developer tier; specific pricing available on request","currency":"USD","freeTier":true,"sourceUrl":"https://www.endorlabs.com/pricing","retrievedAt":"2026-08-14T09:22:26.641Z","billingPeriods":["month","year"]}` | `{"type":"open_source","freeTier":true,"sourceUrl":"https://www.zaproxy.org","retrievedAt":"2026-08-14T15:30:17.577Z"}` |
| pricing.free_tier | yes | yes |
| pricing.model | freemium | open_source |
| pricing.price_level | low | free |
| pricing.transparent | no | - |
| release.cadence_days | - | 6 |
| release.history | - | `[{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-26","date":"2026-08-26T08:35:57Z","type":"prerelease","version":"w2026-08-26"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-19","date":"2026-08-19T10:51:56Z","type":"prerelease","version":"w2026-08-19"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-11","date":"2026-08-11T14:53:54Z","type":"prerelease","version":"w2026-08-11"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-06","date":"2026-08-06T14:19:52Z","type":"prerelease","version":"w2026-08-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-28","date":"2026-07-28T11:12:43Z","type":"prerelease","version":"w2026-07-28"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-21","date":"2026-07-21T16:10:37Z","type":"prerelease","version":"w2026-07-21"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-14","date":"2026-07-14T13:46:09Z","type":"prerelease","version":"w2026-07-14"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-13","date":"2026-07-13T15:29:09Z","type":"prerelease","version":"w2026-07-13"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-06","date":"2026-07-06T14:25:44Z","type":"prerelease","version":"w2026-07-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-30","date":"2026-06-30T14:30:23Z","type":"prerelease","version":"w2026-06-30"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-29","date":"2026-06-29T14:01:46Z","type":"prerelease","version":"w2026-06-29"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-24","date":"2026-06-24T16:56:19Z","type":"prerelease","version":"w2026-06-24"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-23","date":"2026-06-23T16:18:04Z","type":"prerelease","version":"w2026-06-23"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-16","date":"2026-06-16T16:08:49Z","type":"prerelease","version":"w2026-06-16"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-09","date":"2026-06-09T13:57:54Z","type":"prerelease","version":"w2026-06-09"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-01","date":"2026-06-01T18:13:38Z","type":"prerelease","version":"w2026-06-01"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-27","date":"2026-05-27T16:59:12Z","type":"prerelease","version":"w2026-05-27"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-18","date":"2026-05-18T16:47:20Z","type":"prerelease","version":"w2026-05-18"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-12","date":"2026-05-12T13:45:04Z","type":"prerelease","version":"w2026-05-12"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-05","date":"2026-05-05T16:56:04Z","type":"prerelease","version":"w2026-05-05"}]` |
| reliability.sla_pct | 99.9 | - |
| reliability.status_page | yes | - |
| security.disclosure_policy | yes | yes |
| security.fedramp | yes | - |
| security.pci | yes | - |
| security.scorecard | - | 6.8 |
| security.soc2 | yes | - |
| security.vulnerabilities | - | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.zaproxy%3Azap&per_page=100","last_12m":0,"max_severity":"MODERATE"}` |

## Capabilities (DevSecOps Tools)

| Capability | Endor Labs | OWASP ZAP |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | ✓ | - |
| DAST (dynamic analysis) | ✗ | ✓ |
| SCA / dependency scanning | ✓ | - |
| Secret scanning | ✓ | - |
| Container / image scanning | ✓ | - |
| IaC misconfiguration scanning | ✗ | - |
| **Governance** |  |  |
| OSS licence compliance | ✗ | - |
| SBOM generation (SPDX/CycloneDX) | ✓ | - |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | ✓ | - |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | ✓ | - |
| **Deployment** |  |  |
| Hosting | Cloud + self-hosted | Self-hosted only |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | ✓ | - |
| **Licensing** |  |  |
| OSS engine available | ✗ | ✓ |

*Source: Vioscale. Generated 2026-09-01T15:14:56.600Z. "-" = undocumented, not absent.*
