OWASP Zap is a free and open-source web application security scanner.
Product | Market Share (%) |
---|---|
OWASP Zap | 4.7% |
SonarQube Server (formerly SonarQube) | 22.1% |
Checkmarx One | 10.0% |
Other | 63.2% |
Type | Title | Date | |
---|---|---|---|
Category | Static Application Security Testing (SAST) | Aug 28, 2025 | Download |
Product | Reviews, tips, and advice from real users | Aug 28, 2025 | Download |
Comparison | OWASP Zap vs SonarQube Server (formerly SonarQube) | Aug 28, 2025 | Download |
Comparison | OWASP Zap vs Veracode | Aug 28, 2025 | Download |
Comparison | OWASP Zap vs Checkmarx One | Aug 28, 2025 | Download |
Title | Rating | Mindshare | Recommending | |
---|---|---|---|---|
SonarQube Server (formerly SonarQube) | 4.0 | 22.1% | 81% | 116 interviewsAdd to research |
GitLab | 4.2 | 2.4% | 97% | 85 interviewsAdd to research |
Users reported significant improvements in security measures, enhanced vulnerability detection, and increased overall protection.
The tool was praised for its user-friendly interface, extensive features, and effectiveness in identifying potential threats.
Users also highlighted the cost-effectiveness of OWASP Zap, as it provided robust security solutions without requiring substantial financial investments.
Company Size | Count |
---|---|
Small Business | 10 |
Midsize Enterprise | 10 |
Large Enterprise | 18 |
Company Size | Count |
---|---|
Small Business | 344 |
Midsize Enterprise | 271 |
Large Enterprise | 939 |
The solution helps developers identify vulnerabilities in their web applications by actively scanning for common security issues.
With its user-friendly interface and powerful features, Zap is a popular choice among developers for ensuring the security of their web applications.
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Author info | Rating | Review Summary |
---|---|---|
Project Manager at Al Hassan LLC | 4.0 | We primarily use OWASP Zap for web application security testing due to its simplicity and effective scanning features. However, it needs better alignment with CVSS scores. We also use Burp Suite and Nessus for comprehensive vulnerability analysis. |
Delivery Head - DevOps at Datamato Technologies | 3.5 | I find OWASP Zap effective for scanning code vulnerabilities, whether manually or via CI/CD. However, it should improve false positive reduction and expand coverage. GitLab Ultimate and other tools are viable alternatives, offering comprehensive scanning features. |
Technical Analyst at Hexaware Technologies Limited | 4.0 | I've worked with OWASP Zap for years, finding it effective overall, though it has limitations compared to Burp Suite, particularly in scan engines, authentication, and reporting. Its open-source nature allows for integrations but needs improvements, especially for APIs. |
Data Protection Officer at Aura | 4.5 | I use OWASP Zap for DevSecOps in pipelines, employing its add-ons for tasks like brute forcing. The reporting feature is beneficial, although improvements like noise cancellation and a cloud version could enhance its utility, especially for larger tests. |
Researcher in Cyber Security at Sekolah Tinggi Ilmu Statistik BPS | 4.0 | I use OWASP Zap for vulnerability scanning because it offers valuable features for free, like the Zap HUD for manual exploration. However, it needs improved algorithms to reduce false positives and better integration options with tools like Burp Suite. |
Elite Global CISO at Scybers | 4.0 | We use OWASP Zap for scanning pipelines and find it beneficial, as it helps in identifying and fixing vulnerabilities. Our clients provide positive feedback, though the technical support team could improve by offering proactive guidance on feature usage. |
Cloud Solutions Architect at TANGENT SOLUTIONS | 4.5 | I use OWASP Zap within our DevOps process to securely develop apps by integrating security testing into our pipeline. Its automated scans and code crawler are valuable, despite occasional false positives. The active community and constant improvements make it indispensable. |
Security Officer at UnDisclosed | 3.5 | I use OWASP Zap for dynamic security testing of web applications, particularly for automation in crawling and response manipulation. Improvements are needed in updating vulnerabilities and differentiating false positives. While I consider Burp Suite, I hope OWASP Zap advances similar capabilities. |