IT Central Station is now PeerSpot: Here's why

Is OWASP Zap better than PortSwigger Burp Suite Pro?

Subdirector de Seguridad Informática e Infraestructura at a financial services firm with 201-500 employees

I would like to know if nowadays (2021) the license of Burp Suite Pro is worth the cost. Is it a good option to use OWASP Zap instead for testing security in web applications?

PeerSpot user
35 Answers

reviewer1526550 - PeerSpot reviewer
Top 5LeaderboardReal User

Yes OWASP ZAP is a good option as it's an open source so always preferred but Burp Suite Pro  will give you more options, its one of the best tool to have for pentesters so defo worth it.

Avinash-Kumar - PeerSpot reviewer
Real User

First things first both are having their own merits, however in my personal experience ZAP can replace your burpsuite for sure considering the License. Also as the latest ZAP versions are covering more advanced techniques and spidering patterns with lots of options in it, it is worth considering ZAP. However remember that burpsuite from latest versions with inbuilt chromium and it's emerging plugin support (Installable jars) you can use burp to the fullest and you can keep it as a swiss knife for your web and app pentesting. Couple of extensions in burp pro are interesting especially the race condition one. I always prefer using Burp and at instances I go with ZAP.

Buyer's Guide
OWASP Zap vs. PortSwigger Burp Suite Professional
July 2022
Find out what your peers are saying about OWASP Zap vs. PortSwigger Burp Suite Professional and other solutions. Updated: July 2022.
622,645 professionals have used our research since 2012.