# OWASP ZAP vs SonarQube

**Leader by Vioscale score:** SonarQube

| Attribute | OWASP ZAP | SonarQube |
|---|---|---|
| **Vioscale score** | 51.1 (41% (low)) | 70.9 (75% (high)) |
| activity.commits_last_30d | 34 | 100 |
| adoption.dependent_repos | 30 | 497 |
| adoption.github_stars | 15,685 | 10,928 |
| deployment.options | `{"self_hosted":true}` | `{"cloud":true,"on_prem":true,"air_gapped":true,"self_hosted":true}` |
| description.long | An open-source security scanner that performs dynamic analysis on web applications to detect potential vulnerabilities. It supports automation, extensibility through community add-ons, and integrates with CI/CD pipelines. | A code verification system that scans source code repositories for bugs, security flaws, and quality problems, supporting both human-written and AI-generated code. It integrates directly into development workflows and CI/CD pipelines to provide real-time feedback and automated fix suggestions. |
| features.capabilities | `{"dast":true,"hosting":"self","ci_native":true,"open_source":true}` | `{"sca":true,"dast":false,"sast":true,"sbom":true,"hosting":"both","ci_native":true,"ide_plugin":true,"auto_fix_pr":true,"open_source":true,"iac_scanning":true,"reachability":true,"secret_scanning":true,"container_scanning":true,"license_compliance":true}` |
| integrations.count | 2 | 20 |
| integrations.list | `[{"name":"GitHub"},{"name":"GitHub Actions"}]` | `[{"name":"GitHub"},{"name":"GitLab"},{"name":"Bitbucket"},{"name":"Azure DevOps"},{"name":"CodeCatalyst"},{"name":"CircleCI"},{"name":"TravisCI"},{"name":"GitHub Actions"},{"name":"Jenkins"},{"name":"Codemagic"},{"name":"Slack"},{"name":"Jira"},{"name":"Linear"},{"name":"GitHub Advanced Security"},{"name":"Backstage"},{"name":"Compass"},{"name":"Cortex"},{"name":"Harness"},{"name":"Port"}]` |
| language.primary | Java | Java |
| license.spdx | Apache-2.0 | LGPL-3.0 |
| market.availability | - | `{"hqCountry":"CH","primaryMarkets":["US","EU"],"availabilityScope":"global","availableCountries":[],"notAvailableCountries":[]}` |
| platform.support | - | `{"cli":true,"web":true}` |
| pricing | `{"type":"open_source","freeTier":true,"sourceUrl":"https://www.zaproxy.org","retrievedAt":"2026-08-14T15:30:17.577Z"}` | `{"type":"subscription","plans":[{"free":false,"name":"Team","summary":"$34/month","features":["30+ languages","code quality standards","bug and vulnerability detection","secret scanning","AI-powered code fixes","PR analysis","commercial support available"],"commitment":"monthly","components":[{"kind":"fixed","amount":34,"period":"month","currency":"USD"}],"description":"For small teams analyzing up to 100k lines of code","contactSales":false,"includedLimits":{"private_loc":"up to 100k"}},{"free":false,"name":"Enterprise","summary":"Custom pricing","features":["40+ languages including ABAP, COBOL, Apex","all Team features plus","advanced security reports and audit logs","OWASP, CWE, PCI DSS, MISRA C++:2023 compliance","unlimited users and projects","SSO, SCIM, CMK/BYOK, IP allowlist","enterprise hierarchy and portfolios","GitHub Advanced Security integration","enterprise SLA","premium support"],"description":"For large organizations with advanced security and compliance needs","contactSales":true}],"addOns":[{"name":"Advanced Security"},{"name":"Sonar Agent Essentials"}],"summary":"From $34/month. Free tier for open source projects. 14-day free trial.","currency":"USD","freeTier":true,"sourceUrl":"https://www.sonarsource.com/jp/plans-and-pricing/","retrievedAt":"2026-08-14T15:24:06.893Z","freeTrialDays":14,"startingPrice":{"amount":34,"period":"month","currency":"USD"},"billingPeriods":["month","year"]}` |
| pricing.free_tier | yes | yes |
| pricing.model | open_source | freemium |
| pricing.price_level | free | mid |
| pricing.transparent | - | yes |
| release.cadence_days | 6 | 28 |
| release.history | `[{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-26","date":"2026-08-26T08:35:57Z","type":"prerelease","version":"w2026-08-26"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-19","date":"2026-08-19T10:51:56Z","type":"prerelease","version":"w2026-08-19"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-11","date":"2026-08-11T14:53:54Z","type":"prerelease","version":"w2026-08-11"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-08-06","date":"2026-08-06T14:19:52Z","type":"prerelease","version":"w2026-08-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-28","date":"2026-07-28T11:12:43Z","type":"prerelease","version":"w2026-07-28"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-21","date":"2026-07-21T16:10:37Z","type":"prerelease","version":"w2026-07-21"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-14","date":"2026-07-14T13:46:09Z","type":"prerelease","version":"w2026-07-14"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-13","date":"2026-07-13T15:29:09Z","type":"prerelease","version":"w2026-07-13"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-07-06","date":"2026-07-06T14:25:44Z","type":"prerelease","version":"w2026-07-06"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-30","date":"2026-06-30T14:30:23Z","type":"prerelease","version":"w2026-06-30"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-29","date":"2026-06-29T14:01:46Z","type":"prerelease","version":"w2026-06-29"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-24","date":"2026-06-24T16:56:19Z","type":"prerelease","version":"w2026-06-24"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-23","date":"2026-06-23T16:18:04Z","type":"prerelease","version":"w2026-06-23"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-16","date":"2026-06-16T16:08:49Z","type":"prerelease","version":"w2026-06-16"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-09","date":"2026-06-09T13:57:54Z","type":"prerelease","version":"w2026-06-09"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-06-01","date":"2026-06-01T18:13:38Z","type":"prerelease","version":"w2026-06-01"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-27","date":"2026-05-27T16:59:12Z","type":"prerelease","version":"w2026-05-27"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-18","date":"2026-05-18T16:47:20Z","type":"prerelease","version":"w2026-05-18"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-12","date":"2026-05-12T13:45:04Z","type":"prerelease","version":"w2026-05-12"},{"url":"https://github.com/zaproxy/zaproxy/releases/tag/w2026-05-05","date":"2026-05-05T16:56:04Z","type":"prerelease","version":"w2026-05-05"}]` | `[{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.8.0.126808","date":"2026-08-05T07:17:56Z","type":"stable","version":"26.8.0.126808"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.7.0.124771","date":"2026-07-08T13:48:56Z","type":"stable","version":"26.7.0.124771"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.6.0.123539","date":"2026-06-03T09:56:25Z","type":"stable","version":"26.6.0.123539"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.5.0.122743b","date":"2026-05-19T12:59:25Z","type":"stable","version":"26.5.0.122743b"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.4.0.121862","date":"2026-04-10T13:17:33Z","type":"stable","version":"26.4.0.121862"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.3.0.120487","date":"2026-03-03T09:53:50Z","type":"stable","version":"26.3.0.120487"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.2.0.119303","date":"2026-02-04T10:07:42Z","type":"stable","version":"26.2.0.119303"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/26.1.0.118079","date":"2026-01-06T14:46:07Z","type":"stable","version":"26.1.0.118079"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.12.0.117093","date":"2025-12-23T15:00:10Z","type":"stable","version":"25.12.0.117093"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.11.0.114957","date":"2025-11-05T10:26:59Z","type":"stable","version":"25.11.0.114957"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.10.0.114319","date":"2025-10-03T13:33:44Z","type":"stable","version":"25.10.0.114319"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.9.0.112764","date":"2025-09-01T15:33:36Z","type":"stable","version":"25.9.0.112764"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.8.0.112029","date":"2025-08-06T13:33:07Z","type":"stable","version":"25.8.0.112029"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.7.0.110598","date":"2025-07-07T09:39:23Z","type":"stable","version":"25.7.0.110598"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.6.0.109173","date":"2025-06-02T14:19:56Z","type":"stable","version":"25.6.0.109173"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.5.0.107428","date":"2025-05-06T08:12:43Z","type":"stable","version":"25.5.0.107428"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.4.0.105899","date":"2025-04-07T13:22:08Z","type":"stable","version":"25.4.0.105899"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.3.0.104237","date":"2025-03-04T14:08:50Z","type":"stable","version":"25.3.0.104237"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.2.0.102705","date":"2025-02-03T16:06:10Z","type":"stable","version":"25.2.0.102705"},{"url":"https://github.com/SonarSource/sonarqube/releases/tag/25.1.0.102122","date":"2025-01-07T15:44:51Z","type":"stable","version":"25.1.0.102122"}]` |
| reliability.sla_pct | - | 99.9 |
| reliability.status_page | - | yes |
| security.disclosure_policy | yes | - |
| security.gdpr | - | yes |
| security.iso27001 | - | yes |
| security.scorecard | 6.8 | 4.9 |
| security.soc2 | - | yes |
| security.vulnerabilities | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.zaproxy%3Azap&per_page=100","last_12m":0,"max_severity":"MODERATE"}` | `{"count":1,"source":"https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.sonarsource.sonarqube%3Asonar-plugin-api&per_page=100","last_12m":0,"max_severity":"MODERATE"}` |

## Capabilities (DevSecOps Tools)

| Capability | OWASP ZAP | SonarQube |
|---|:--:|:--:|
| **Scan types** |  |  |
| SAST (static analysis) | - | ✓ |
| DAST (dynamic analysis) | ✓ | ✗ |
| SCA / dependency scanning | - | ✓ |
| Secret scanning | - | ✓ |
| Container / image scanning | - | ✓ |
| IaC misconfiguration scanning | - | ✓ |
| **Governance** |  |  |
| OSS licence compliance | - | ✓ |
| SBOM generation (SPDX/CycloneDX) | - | ✓ |
| **Remediation** |  |  |
| Automated fix / upgrade PRs | - | ✓ |
| **Prioritisation** |  |  |
| Reachability / exploitability prioritisation | - | ✓ |
| **Deployment** |  |  |
| Hosting | Self-hosted only | Cloud + self-hosted |
| **Integration** |  |  |
| First-class CI / pipeline integration | ✓ | ✓ |
| In-editor / IDE scanning | - | ✓ |
| **Licensing** |  |  |
| OSS engine available | ✓ | ✓ |

*Source: Vioscale. Generated 2026-09-01T16:46:33.126Z. "-" = undocumented, not absent.*
