Discover / Security

OWASP ZAP

by zaproxyJava

The OWASP web application security scanner for authorized dynamic testing.

Toolstable

Maturity: stable because 11y old, v2.17.0 released 231d ago. Derived from release and commit history, not a rating.

Stars
16k
Forks
2.6k
Downloads / mo
Last commit
2026-08-01
License
Apache-2.0
Open issues
856

Market and trust evidence

Edition not yet matched

No exact skills.sh identity match is available for this repository. Repository adoption and freshness remain visible above; install momentum is not inferred.

Trust analysis is a screening signal, not a security warranty. Read the ranking and trust methodology.

In practice

Written by AI from this repository’s README · low confidence

Web apps ship with runtime vulnerabilities that unit tests and static analysis never exercise.

Use it when

When you want dynamic scanning of a running web application during development or a manual pentest.

Not the right pick when

Thin guidance in the repo itself, since the README mostly links out to zaproxy.org for downloads and details.

Capabilities

  • automatically finds security vulnerabilities in web applications
  • supports manual security testing by experienced pentesters
  • usable while developing and testing applications
  • free and open source with an active contributor community

Cost: Free and open source

Video walkthroughs

Third-party YouTube uploads matched to this tool by title, channel and repository name on 2026-08-03. Not made, reviewed or endorsed by SkillPilot. View counts and publish months are as of the match date and the month is approximate. Nothing loads from YouTube until you press play.

What the repository ships

Has docsHas examplesSecurity policyCI configured

Detected from the actual files in the repository root.

Latest release v2.17.0

Published 2025-12-15

Release notes: https://www.zaproxy.org/docs/desktop/releases/2.17.0/


| File | Checksum (SHA-256) |

|---|---|

| ZAP_2.17.0.dmg | a3d246125dd6e576036af8fb29f90377fc72a0a5df8c89c54711972b449582c7 |

| ZAP_2.17.0_aarch64.dmg | 3b3c6c8b105a33cb2a7d718e7f9aa41418a6d8aae3887d94a42523b5eeac723b |

| ZAP_2.17.0_Core.zip | 0cb73b7f72d12c263fb61de304edb82a455d7aa4e1813c216c061765c306f5b7 |

| ZAP_2.17.0_Crossplatform.zip | 94c8f767b1c2e94f0db66b3ae56514d5e3f5a728ee1b6c798e0c8fe2d61fbff0 |

| ZAP_2.17.0_Linux.tar.gz | efe799aaa3627db683b43f00c9c210aea0b75c00cc8f0a0f0434d12bb3ddde5a |

| ZAP_2_17_0_unix.sh | c172d81756458414249ad8170514ac8bf1a6903f3b5c45fa4011f79596608adb |

| ZAP_2_17_0_windows-x32.exe | 125fc89c73d440141ce859109e23258700b863b94475d5461926ec757d99e94a |

| ZAP_2_17_0_windows.exe | ebdaf6f00ffd9c21891d29360196e13a14091f84dde2bfa1e0b61213a93bc5ca |

| bom.json | c91137d66c34a7e2803cbd4fbaf41f2e16201f754b9fc7c954293939a32371bf |

Tags

README

image

License

GitHub release

Java CI

CII Best Practices

Github Releases

javadoc

CodeQL

Quality Gate Status

Open Source Helpers

Twitter Follow

Integration Tests

Docker Live Release

The Zed Attack Proxy (ZAP) by Checkmarx is the world’s most widely used web app scanner.

Free and open source. A community based GitHub Top 1000 project that anyone can contribute to.

It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications.

It's also a great tool for experienced pentesters to use for manual security testing.

image

For more details about ZAP see the website: zaproxy.org

image

Related tools