What is OWASP ZAP?
An open-source security scanner that performs dynamic analysis on web applications to detect potential vulnerabilities. It supports automation, extensibility through community add-ons, and integrates with CI/CD pipelines.
OWASP ZAP pricing
We don't have OWASP ZAP's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.
What OWASP ZAP does
The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.
- SAST (static analysis)
- -
- DAST (dynamic analysis)
- ✓
- SCA / dependency scanning
- -
- Secret scanning
- -
- Container / image scanning
- -
- IaC misconfiguration scanning
- -
- OSS licence compliance
- -
- SBOM generation (SPDX/CycloneDX)
- -
- Automated fix / upgrade PRs
- -
- Reachability / exploitability prioritisation
- -
- Hosting
- Self-hosted only
- First-class CI / pipeline integration
- ✓
- In-editor / IDE scanning
- -
- OSS engine available
- ✓
Platform & deployment
Independently observed- Self-hosted
Integrations (2)
Independently observed- GitHub
- GitHub Actions
Security & compliance
Known vulnerabilities: 1 (0 in the last 12 months), max severity MODERATE sourcea count reflects scale & disclosure, not quality
OWASP ZAP FAQ
Common questions about OWASP ZAP, answered from independent, dated evidence.
What is OWASP ZAP?
An open-source security scanner that performs dynamic analysis on web applications to detect potential vulnerabilities. It supports automation, extensibility through community add-ons, and integrates with CI/CD pipelines. It is indexed under DevSecOps Tools.
Source: https://www.zaproxy.org
Is OWASP ZAP free to use?
OWASP ZAP is open source, so it can be self-hosted and used at no licence cost. It is released under the Apache-2.0 licence. Pricing changes often, so verify at source before relying on it.
Source: https://www.zaproxy.org
Can OWASP ZAP be self-hosted?
Yes. OWASP ZAP can be deployed self-hosted, so it does not have to run on the vendor's infrastructure.
Source: https://www.zaproxy.org
Is OWASP ZAP open source?
Yes. OWASP ZAP is published under the Apache-2.0 licence, a permissive licence that generally allows commercial use and modification. Licence terms can change between releases, so verify against the repository for the version you intend to use.
OWASP ZAP alternatives
Other devsecops tools we track, ranked by the same independent score.
- SnykContinuous validation layer for AI-generated code and development agentshigh · 75%
- SonarQubeAutomated static analysis platform that identifies and helps fix code quality issues, security vulnerabilities, and bugs throughout the development lifecyclehigh · 76%
- GitGuardianDetect and prevent credential exposure across your code and infrastructuremedium · 72%
- Endor LabsAutomates vulnerability detection and remediation using AI agents integrated into developer workflowsmedium · 71%
- SemgrepVulnerability scanner for modern developmentmedium · 71%
- MendUnified platform for securing custom code, open source dependencies, and AI with automated governance and remediationmedium · 74%
Compare OWASP ZAP
Side by side against other devsecops tools, attribute by attribute, with a source on every value.
The vioscaleAI score: one lens on the evidence
Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for OWASP ZAP, not the verdict.
| Signal | Score | Weight | Contribution | Evidence |
|---|---|---|---|---|
| Release cadence | 97 | 0.05 | 5.0 | ✓ |
| Development activity | 49 | 0.09 | 4.6 | ✓ |
| Capabilities | 58 | 0.06 | 3.6 | ✓ |
| Security score | 68 | 0.04 | 2.9 | ✓ |
| Stars | 79 | 0.03 | 2.1 | ✓ |
| Dependent projects | 25 | 0.06 | 1.6 | ✓ |
| Integrations | 14 | 0.06 | 0.9 | ✓ |
| Security posture | 5 | 0.21 | 0.0 | - |
| Package downloads | 0 | 0.14 | 0.0 | - |
| Developer Q&A activity | 0 | 0.06 | 0.0 | - |
Computed . Re-weight it by intent, or see the full method.
All data & sourcesshow ↓
Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.
Activity
| Attribute | Value | Evidence |
|---|---|---|
| Commits last 30d | 36 | mediumsource · 2026-09-11 · 65% |
Adoption
Content
| Attribute | Value | Evidence |
|---|---|---|
| Faq | 4 items | mediumsource · 2026-09-10 · 69% |
Features
| Attribute | Value | Evidence |
|---|---|---|
| Capabilities | Dast: Yes · Hosting: self · Ci native: Yes · Open source: Yes | mediumsource · 2026-08-14 · 60% |
Integrations
| Attribute | Value | Evidence |
|---|---|---|
| Count | 2 | mediumsource · 2026-08-14 · 60% |
Language
| Attribute | Value | Evidence |
|---|---|---|
| Primary | Java | highsource · 2026-09-11 · 90% |
License
| Attribute | Value | Evidence |
|---|---|---|
| Spdx | Apache-2.0 | highsource · 2026-09-11 · 95% |
Pricing
Release
Security
| Attribute | Value | Evidence |
|---|---|---|
| Disclosure policy | Yes | mediumsource · 2026-08-01 · 60% |
| Scorecard | 6.8 | highsource · 2026-09-11 · 90% |
| Vulnerabilities | Count: 1 · Source: https://advisories.ecosyste.ms/api/v1/advisories?ecosystem=maven&package_name=org.zaproxy%3Azap&per_page=100 · Last 12m: 0 · Max severity: MODERATE | highsource · 2026-09-11 · 90% |
Is OWASP ZAP the right choice for you?
Tell us the job, the constraints and what you weigh most, and we will rank OWASP ZAP against the rest of the devsecops tools we index, using the same dated evidence weighted your way.
Free to run, no account needed to start. How the evaluation works
Is this your product?
This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves OWASP ZAP up or down: nobody can buy rank here, including you.
Take the badge
Live, always current, and free to use on your own site. It shows OWASP ZAP's independent score and links back to this profile.
<a href="https://www.vioscale.ai/software/owasp-zap" target="_blank" rel="noopener">
<img src="https://www.vioscale.ai/badge/software/owasp-zap.svg" alt="OWASP ZAP, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>Markdown, for a README →
[](https://www.vioscale.ai/software/owasp-zap)Claim the profile
Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing OWASP ZAP. Free, and it does not change the score.
- Correct anything wrong, with evidence
- Point our crawler at the pages that matter
- See which AI systems are reading this profile
Not the owner? How vendor profiles work