← Home
Zed Attack Proxy
zap · v2.17.0
6
8.0
Free and open source web app scanner
brew install --cask zap 839
30-day installs
2.5K
90-day installs
9.5K
365-day installs
Install trend
Trust Score 6/10
✓ Open source (Apache-2.0) +3
✗ Active development +0
✓ Licensed +1
✗ No auto-updates +0
✓ Not deprecated +1
✓ Established (>1yr) +1
✗ Low installs +0
Review
Mar 10, 2026Zed Attack Proxy (ZAP) is a free and open-source web application security scanner that automates vulnerability detection, integrates with CI/CD pipelines, and offers active scanning features. It benefits developers and security teams by identifying security flaws early in the development process.
ZAP automatically detects security vulnerabilities in web applications.
Maturity: The project is mature with active development and a large community, though it has a high number of open issues.
Community: No significant community discussion found, with limited engagement on HN.
Pros
- + Open-source and free to use.
- + Integrates well with CI/CD pipelines.
- + Active development with recent updates.
Cons
- - No automatic updates feature.
- - High number of open issues.
Community Mentions
hackernews
hackernews
Positive sentiment Negative sentiment Neutral / unknown
Similar apps
View all alternatives →mitmproxy
mitmproxy
8.5
Intercept, modify, replay, save HTTP/S traffic
Security & Privacy 9.2K installs/mo
vs.
ngrok
ngrok
8.0
Reverse proxy, secure introspectable tunnels to localhost
Developer Tools 21.2K installs/mo
vs.