No more typing reviews! Try our Samantha, our new voice AI agent.

Harness vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Harness
Ranking in Static Application Security Testing (SAST)
7th
Average Rating
8.0
Reviews Sentiment
7.3
Number of Reviews
11
Ranking in other categories
Build Automation (5th), Cloud Cost Management (6th), Feature Management (2nd)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
16th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Static Application Security Testing (SAST) category, the mindshare of Harness is 0.7%, up from 0.3% compared to the previous year. The mindshare of OWASP Zap is 2.7%, down from 5.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Harness0.7%
OWASP Zap2.7%
Other96.6%
Static Application Security Testing (SAST)
 

Featured Reviews

MK
Technical Associate at ZS
Templatized pipelines have improved efficiency while limitations in code-based development remain
Harness UI can do a lot of good things. Harness's UI should not feel very complicated. At the current stage, it feels very commercialized and compared to other platforms such as Argo CD or Jenkins, which feel much more lively and much more simple. Infrastructure as code or pipeline as code is something that Harness severely lacks. There is not a lot of good support for pipeline as code, and I often find myself not using pipeline as code the way other platforms such as GitHub Actions or Jenkins integrate pipeline as code. Pipeline as code is definitely one of the disadvantages when it comes to Harness. Additionally, the entire platform feels very commercialized, which is something that a lot of developers, especially open-source enthusiasts, might not appreciate even within the organization. One of the very important key factors I observed was that there is no way to execute nested pipelines, which means that we cannot execute child pipelines within child pipelines and child pipelines even within those child pipelines. There is no way to execute nested pipeline execution, which may or may not be required based on the use case, but it is definitely one of those features that I wish the platform had.
Amit Beniwal - PeerSpot reviewer
Project Manager at Al Hassan LLC
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Harness positively impacts our organization by reducing deployment time, improving release confidence, and lowering operational overhead during deployment."
"It's a highly customizable DevOps tool."
"Harness integrates all functions like execution pipelines, environment checks, and log monitoring in one place, making it convenient."
"Harness has impacted my organization positively; we use Harness in most of all deployments, so it is uniform."
"Some of the best features of Harness include powerful CI/CD pipeline automation, intelligent deployment strategies, and building monitoring, and its automation capabilities significantly improve speed and reliability while saving time by reducing manual operational tasks and the number of employees needed for deployments."
"By adopting templates and various different pipelines across our own IDP platform, we have saved upwards of 30 to 40% of development time and also reduced risks of failures or error rates by upwards of 70%."
"Approximately seventy-five percent time was reduced in case of deployment and around sixty to sixty-five percent time was reduced while troubleshooting it."
"Harness has positively impacted my organization as several teams have already migrated to it, and some are in the process of moving, reducing the dependency on one specific platform and making it faster with shortened build times and much faster deployments."
"It can be used effectively for internal auditing."
"The API is exceptional."
"The pull request analysis is also very good."
"If you're a company and you've got your own websites, internally and externally, it's great."
"OWASP is definitely in the top three as a tool that we would probably recommend to our team, as a frequent users' tool, however, I don't believe we have any kind of a formal relationship with the company."
"Fuzzer and Java APIs help a lot with our custom needs."
"Automatic updates and pull request analysis."
"The reporting is quite intuitive, which gives you a clear indication of what kind of vulnerability you have that you can drill down on to gather more information."
 

Cons

"Harness setup and configurations could be made easier to configure, which would be helpful."
"I prefer the previous less compact UI version of Harness, which showed more details on the screen."
"Harness can be improved by providing more clarity on the credits it issues for Harness Cloud, as it has a tiered pricing structure involving license and credit costs, which can get confusing."
"Infrastructure as code or pipeline as code is something that Harness severely lacks."
"When integrating Harness with more than twenty applications in one place, it becomes less stable, causing improvements to be necessary."
"The initial setup can be complex and time-consuming, and the advanced features may require some learning time due to a steep learning curve."
"There are some UI components that can be improved."
"When deploying multiple components to multiple environments, like production and BCP, failures sometimes occur. Improvements are needed when deploying one component to one environment."
"I'd also like to see an improvement in test reports because we get too many false positives."
"It would be ideal if I could try some pre-built deployment scenarios so that I don't have to worry about whether the configuration sector team is doing it right or wrong. That would be very helpful."
"The port scanner is a little too slow.​"
"The documentation is lacking and out-of-date, it really needs more love."
"If there was an easier to understand exactly what has been checked and what has not been checked, it would make this solution better. We have to trust that it has checked all known vulnerabilities but it's a bit hard to see after the scanning."
"There isn't too much information about it online."
"The technical support team must be proactive."
"I would recommend this product to people although I think it is very difficult to deploy and we also have issues with maintenance."
 

Pricing and Cost Advice

Information not available
"The tool is open-source."
"It is open source, and we can scan freely."
"OWASP ZAP is a free tool provided by OWASP’s engineers and experts. There is an option to donate."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"It is highly recommended as it is an open source tool."
"We have used the freeware version. I believe Zap only has freeware."
"The solution’s pricing is high."
"The tool is open source."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
25%
Outsourcing Company
8%
Manufacturing Company
7%
Computer Software Company
6%
Computer Software Company
10%
University
9%
Financial Services Firm
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise1
Large Enterprise10
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise22
 

Questions from the Community

What needs improvement with Harness?
There are some UI components that can be improved. The needed UI improvements include more graphs, more history, the ability to create pipelines through the UI, and more interactions, with UI compo...
What is your primary use case for Harness?
My main use case for Harness is to create pipelines, deploy applications, and manage security pipelines. I use Harness to deploy applications to EC2 instances and Kubernetes instances, and I create...
What advice do you have for others considering Harness?
My advice for others looking into using Harness is to use AI capabilities, create pipelines, and then use it to deploy. Harness is a good tool. I would rate this review a nine out of ten.
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
What needs improvement with OWASP Zap?
The improvement that has to be done for APIs focuses on manual activities where the feature exists, but it is not at the same level as what Burp Suite does with intercepting and tools such as Postm...
 

Comparisons

 

Also Known As

Armory
No data available
 

Overview

 

Sample Customers

Linedata, Openbank, Home Depot, Advanced
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Harness vs. OWASP Zap and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.