Skip to content
cask.news
← Home

Zed Attack Proxy

zap · v2.17.0 • deprecated

7
8.0

Free and open source web app scanner

brew install --cask zap
791
30-day installs
2.3K
90-day installs
8.8K
365-day installs
Install trend
Trust Score 7/10
Open source (Apache-2.0) +3
Active development +2
Licensed +1
No auto-updates +0
Deprecated +0
Established (>1yr) +1
Low installs +0

Review

Mar 10, 2026

Zed Attack Proxy (ZAP) is a free and open-source web application security scanner that automates vulnerability detection, integrates with CI/CD pipelines, and offers active scanning features. It benefits developers and security teams by identifying security flaws early in the development process.

ZAP automatically detects security vulnerabilities in web applications.

Maturity: The project is mature with active development and a large community, though it has a high number of open issues.

Community: No significant community discussion found, with limited engagement on HN.

Pros

  • + Open-source and free to use.
  • + Integrates well with CI/CD pipelines.
  • + Active development with recent updates.

Cons

  • - No automatic updates feature.
  • - High number of open issues.
14.8k
Stars
2.5k
Forks
850
Issues
Apache-2.0
License
JavaLast commit: Mar 10, 2026

Community Mentions

Positive sentiment Negative sentiment Neutral / unknown