Ross ROSS = Recommend OSS · open-source software intelligence for agents

zaproxy/zaproxy

The ZAP by Checkmarx Core project observed · 2026-08-28

github.com/zaproxy/zaproxy · homepage · Java · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

78/100

  • Activity 99
  • Release rhythm 37
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: 169.0
  • age_days: 4109
  • days_rel: 261
  • days_push: 7
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

15686 stars · 2625 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps during development and manual penetration testing. It supports automated scanning via Docker, GitHub Actions, an automation framework, and a comprehensive API/daemon mode, plus a desktop GUI.

Use cases

  • scan my web application for security vulnerabilities
  • run automated DAST scans in CI/CD pipeline
  • perform manual penetration testing on a web app
  • find OWASP Top 10 issues in my website
  • proxy and inspect HTTP traffic from my browser
  • automate security scanning of a web API
  • quick reconnaissance scan of a URL

When to choose

  • you need a free, open-source DAST scanner for web apps or APIs
  • you want both automated CI/CD scanning and manual pentesting tools in one tool
  • you need a Burp Suite alternative without commercial licensing
  • you want extensive extensibility via community add-ons and a full API

When to avoid

  • you need static source code analysis (SAST) rather than runtime scanning
  • you need to scan non-HTTP protocols or thick desktop/mobile binaries
  • you want a zero-configuration commercial product with vendor support guarantees

Facets

application · maturity stable

penetration-testing vulnerability-scanning security http-client proxy cli developer-tools security penetration-testing web-development developer-tools cross-platform jvm cli dast web-app-scanner owasp zap security-testing pentesting proxy-scanner api-scanning automation docker desktop web-server

7 sources

Member repositories

RepositoryRoleHealth v2
zaproxy/zaproxymain78

For agents

markdown · JSON · MCP: product_card(name="zaproxy/zaproxy")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem