zaproxy/zaproxy
The ZAP by Checkmarx Core project observed · 2026-08-28
Health v2 · maintenance only
78/100
- Activity 99
- Release rhythm 37
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 169.0
- age_days: 4109
- days_rel: 261
- days_push: 7
- n_releases_24m: 3
Adoption not part of the score
15686 stars · 2625 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps during development and manual penetration testing. It supports automated scanning via Docker, GitHub Actions, an automation framework, and a comprehensive API/daemon mode, plus a desktop GUI.
Use cases
- scan my web application for security vulnerabilities
- run automated DAST scans in CI/CD pipeline
- perform manual penetration testing on a web app
- find OWASP Top 10 issues in my website
- proxy and inspect HTTP traffic from my browser
- automate security scanning of a web API
- quick reconnaissance scan of a URL
When to choose
- you need a free, open-source DAST scanner for web apps or APIs
- you want both automated CI/CD scanning and manual pentesting tools in one tool
- you need a Burp Suite alternative without commercial licensing
- you want extensive extensibility via community add-ons and a full API
When to avoid
- you need static source code analysis (SAST) rather than runtime scanning
- you need to scan non-HTTP protocols or thick desktop/mobile binaries
- you want a zero-configuration commercial product with vendor support guarantees
Facets
application · maturity stable
penetration-testing vulnerability-scanning security http-client proxy cli developer-tools security penetration-testing web-development developer-tools cross-platform jvm cli dast web-app-scanner owasp zap security-testing pentesting proxy-scanner api-scanning automation docker desktop web-server
7 sources
- readme: https://github.com/zaproxy/zaproxy · fetched 2026-08-28 · f87d291f30f2
- homepage: https://www.zaproxy.org · fetched 2026-08-29 · ec111901c5a6
- site_page: https://www.zaproxy.org/docs/zap-ownership · fetched 2026-08-29 · 91b99881930d
- site_page: https://www.zaproxy.org/docs/automate · fetched 2026-08-29 · 90089abb587a
- site_page: https://www.zaproxy.org/docs · fetched 2026-08-29 · eab1a0bea14a
- site_page: https://www.zaproxy.org/getting-started · fetched 2026-08-29 · e5f6969112af
- site_page: https://www.zaproxy.org/docs/statistics · fetched 2026-08-29 · 8d22703fd20a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| zaproxy/zaproxy | main | 78 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem