Try our new research platform with insights from 80,000+ expert users

What is OWASP Zap?

Featured OWASP Zap reviews

OWASP Zap mindshare

As of August 2025, the mindshare of OWASP Zap in the Static Application Security Testing (SAST) category stands at 4.7%, up from 4.7% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
OWASP Zap4.7%
SonarQube Server (formerly SonarQube)22.1%
Checkmarx One10.0%
Other63.2%
Static Application Security Testing (SAST)

PeerResearch reports based on OWASP Zap reviews

TypeTitleDate
CategoryStatic Application Security Testing (SAST)Aug 28, 2025Download
ProductReviews, tips, and advice from real usersAug 28, 2025Download
ComparisonOWASP Zap vs SonarQube Server (formerly SonarQube)Aug 28, 2025Download
ComparisonOWASP Zap vs VeracodeAug 28, 2025Download
ComparisonOWASP Zap vs Checkmarx OneAug 28, 2025Download
Suggested products
TitleRatingMindshareRecommending
SonarQube Server (formerly SonarQube)4.022.1%81%116 interviewsAdd to research
GitLab4.22.4%97%85 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business10
Midsize Enterprise10
Large Enterprise18
By reviewers
By visitors reading reviews
Company SizeCount
Small Business344
Midsize Enterprise271
Large Enterprise939
By visitors reading reviews

Top industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
11%
Manufacturing Company
8%
University
7%
Government
7%
Educational Organization
5%
Retailer
5%
Comms Service Provider
5%
Healthcare Company
4%
Construction Company
4%
Media Company
3%
Insurance Company
3%
Real Estate/Law Firm
2%
Non Profit
2%
Outsourcing Company
2%
Performing Arts
2%
Transportation Company
2%
Consumer Goods Company
1%
Logistics Company
1%
Hospitality Company
1%
Wholesaler/Distributor
1%
Energy/Utilities Company
1%
Legal Firm
1%
Recreational Facilities/Services Company
1%
Pharma/Biotech Company
1%
Marketing Services Firm
1%

Compare OWASP Zap with alternative products

Learn more about OWASP Zap

OWASP Zap customers

Related questions

 
OWASP Zap Reviews Summary
Author infoRatingReview Summary
Project Manager at Al Hassan LLC4.0We primarily use OWASP Zap for web application security testing due to its simplicity and effective scanning features. However, it needs better alignment with CVSS scores. We also use Burp Suite and Nessus for comprehensive vulnerability analysis.
Delivery Head - DevOps at Datamato Technologies3.5I find OWASP Zap effective for scanning code vulnerabilities, whether manually or via CI/CD. However, it should improve false positive reduction and expand coverage. GitLab Ultimate and other tools are viable alternatives, offering comprehensive scanning features.
Technical Analyst at Hexaware Technologies Limited4.0I've worked with OWASP Zap for years, finding it effective overall, though it has limitations compared to Burp Suite, particularly in scan engines, authentication, and reporting. Its open-source nature allows for integrations but needs improvements, especially for APIs.
Data Protection Officer at Aura4.5I use OWASP Zap for DevSecOps in pipelines, employing its add-ons for tasks like brute forcing. The reporting feature is beneficial, although improvements like noise cancellation and a cloud version could enhance its utility, especially for larger tests.
Researcher in Cyber Security at Sekolah Tinggi Ilmu Statistik BPS4.0I use OWASP Zap for vulnerability scanning because it offers valuable features for free, like the Zap HUD for manual exploration. However, it needs improved algorithms to reduce false positives and better integration options with tools like Burp Suite.
Elite Global CISO at Scybers4.0We use OWASP Zap for scanning pipelines and find it beneficial, as it helps in identifying and fixing vulnerabilities. Our clients provide positive feedback, though the technical support team could improve by offering proactive guidance on feature usage.
Cloud Solutions Architect at TANGENT SOLUTIONS4.5I use OWASP Zap within our DevOps process to securely develop apps by integrating security testing into our pipeline. Its automated scans and code crawler are valuable, despite occasional false positives. The active community and constant improvements make it indispensable.
Security Officer at UnDisclosed3.5I use OWASP Zap for dynamic security testing of web applications, particularly for automation in crawling and response manipulation. Improvements are needed in updating vulnerabilities and differentiating false positives. While I consider Burp Suite, I hope OWASP Zap advances similar capabilities.