No more typing reviews! Try our Samantha, our new voice AI agent.

What is OWASP Zap?

Get the report
Helped 900,277 peers since 2012

Featured OWASP Zap reviews

OWASP Zap mindshare

As of June 2026, the mindshare of OWASP Zap in the Static Application Security Testing (SAST) category stands at 2.9%, down from 5.1% compared to the previous year, according to calculations based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
OWASP Zap2.9%
SonarQube14.5%
Checkmarx One9.2%
Other73.4%
Static Application Security Testing (SAST)

PeerResearch reports based on OWASP Zap reviews

TypeTitleDate
CategoryStatic Application Security Testing (SAST)Jun 22, 2026Download
ProductReviews, tips, and advice from real usersJun 22, 2026Download
ComparisonOWASP Zap vs SonarQubeJun 22, 2026Download
ComparisonOWASP Zap vs Checkmarx OneJun 22, 2026Download
ComparisonOWASP Zap vs VeracodeJun 22, 2026Download
Suggested products
TitleRatingMindshareRecommending
SonarQube4.014.5%84%135 interviewsAdd to research
Snyk4.15.8%100%51 interviewsAdd to research
 
 
Key learnings from peers

Valuable Features

Room for Improvement

ROI

Pricing

Popular Use Cases

Service and Support

Deployment

Scalability

Stability

Review data by company size

By reviewers
Company SizeCount
Small Business10
Midsize Enterprise10
Large Enterprise19
By reviewers
By visitors reading reviews
Company SizeCount
Small Business291
Midsize Enterprise169
Large Enterprise569
By visitors reading reviews

Top industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
9%
University
9%
Manufacturing Company
8%
Comms Service Provider
7%
Government
6%
Retailer
6%
Construction Company
5%
Outsourcing Company
5%
Educational Organization
4%
Healthcare Company
4%
Insurance Company
3%
Media Company
3%
Real Estate/Law Firm
2%
Performing Arts
2%
Wholesaler/Distributor
2%
Consumer Goods Company
2%
Non Profit
2%
Energy/Utilities Company
1%
Marketing Services Firm
1%
Hospitality Company
1%
Transportation Company
1%
Logistics Company
1%
Mining And Metals Company
1%
Legal Firm
1%
Aerospace/Defense Firm
1%
Pharma/Biotech Company
1%
Recreational Facilities/Services Company
1%

Compare OWASP Zap with alternative products

Learn more about OWASP Zap

OWASP Zap customers

Related questions

 
OWASP Zap Reviews Summary
Author infoRatingReview Summary
Project Manager at Al Hassan LLC4.0We primarily use OWASP Zap for web application security testing due to its simplicity and effective scanning features. However, it needs better alignment with CVSS scores. We also use Burp Suite and Nessus for comprehensive vulnerability analysis.
Technical Analyst at Hexaware Technologies Limited4.0I've worked with OWASP Zap for years, finding it effective overall, though it has limitations compared to Burp Suite, particularly in scan engines, authentication, and reporting. Its open-source nature allows for integrations but needs improvements, especially for APIs.
Delivery Head - DevOps at Datamato Technologies3.5I find OWASP Zap effective for scanning code vulnerabilities, whether manually or via CI/CD. However, it should improve false positive reduction and expand coverage. GitLab Ultimate and other tools are viable alternatives, offering comprehensive scanning features.
Head Of Information Security at Aura4.5I use OWASP Zap for DevSecOps in pipelines, employing its add-ons for tasks like brute forcing. The reporting feature is beneficial, although improvements like noise cancellation and a cloud version could enhance its utility, especially for larger tests.
Researcher in Cyber Security at Sekolah Tinggi Ilmu Statistik BPS4.0I use OWASP Zap for vulnerability scanning because it offers valuable features for free, like the Zap HUD for manual exploration. However, it needs improved algorithms to reduce false positives and better integration options with tools like Burp Suite.
Cloud Solutions Architect at TANGENT SOLUTIONS4.5I use OWASP Zap within our DevOps process to securely develop apps by integrating security testing into our pipeline. Its automated scans and code crawler are valuable, despite occasional false positives. The active community and constant improvements make it indispensable.
Elite Global CISO at Scybers4.0We use OWASP Zap for scanning pipelines and find it beneficial, as it helps in identifying and fixing vulnerabilities. Our clients provide positive feedback, though the technical support team could improve by offering proactive guidance on feature usage.
Application Security Consultant at a tech services company with 10,001+ employees4.0I use OWASP Zap for security testing, valuing its open-source nature. It improved our security, but I desire more updates, better learning, and a more user-friendly UI, prompting our transition to Burp Suite.
Head Of Development at VALOORES4.0I use OWASP Zap to test our AML product's source code for vulnerabilities. The clear reports, useful plugins, and solutions are highlights, though customizable reports and optimized execution times would improve its utility.
Cyber Security Engineer at a transportation company with 10,001+ employees3.5I use OWASP Zap primarily for analysis, enjoying its integration with Portswigger Burp and leveraging its extensions. It’s stable, easy to set up, and scalable. However, support has declined over time, and more extensions would be appreciated.
Amit Beniwal - PeerSpot reviewer
Amit Beniwal
Project Manager at Al Hassan LLC
Nov 11, 2024
Simplifies vulnerability discovery and has high quality support
NK
Nithin-K
Technical Analyst at Hexaware Technologies Limited
May 15, 2025
Open source testing tool empowers manual activities and has room to improve integration and reporting features
Prasant Pokarnaa - PeerSpot reviewer
Prasant Pokarnaa
Delivery Head - DevOps at Datamato Technologies
Nov 1, 2024
Effective vulnerability identification enhances security scans but AI-driven enhancements are needed
Arther Magaya - PeerSpot reviewer
Arther Magaya
Head Of Information Security at Aura
Apr 8, 2025
Customization and reporting streamline security testing in pipelines
PN
FA9
Researcher in Cyber Security at Sekolah Tinggi Ilmu Statistik BPS
Mar 11, 2024
Offers automated scanning feature and spidering capabilities have improved our security testing
DD
Delmain Deyzel
Cloud Solutions Architect at TANGENT SOLUTIONS
Mar 19, 2024
Enables to perform general health checks and ensure the sites are secure
NathanNV - PeerSpot reviewer
NathanNV
Elite Global CISO at Scybers
Oct 17, 2023
A stable and available solution that helps users scan and fix vulnerabilities in the pipeline
AnkithKumar - PeerSpot reviewer
AnkithKumar
Application Security Consultant at a tech services company with 10,001+ employees
Jun 22, 2022
Great for automating and testing and has tightened our security
Gebran Hadchity - PeerSpot reviewer
Gebran Hadchity
Head Of Development at VALOORES
Jun 13, 2023
An easy-to-install product that discovers more vulnerabilities than any other tool in the market
reviewer1753959 - PeerSpot reviewer
reviewer1753959
Cyber Security Engineer at a transportation company with 10,001+ employees
Mar 16, 2023
Good functionality and works well with Portswigger Burp but it needs to add more extensions