We Want Better
Compare

Compare anything, side by side

Pick up to 4 security testing and we'll lay out their specifications side by side. Apples to apples only — once you pick the first item, the picker locks to its category so you don't end up comparing Selenium with OWASP Top 10.

Your selection — Security Testing

1 of 4 selected

Clear all
OWASP ZAP ×
Locked to Security Testingstart over to switch.
×

OWASP ZAP

OWASP

Open Source Free Tier Self-Hosted

Free, open-source web app security scanner.

Visit website ↗
Side-by-side

Specification comparison

Schema: Tools. Missing values are marked "Not available yet" — those are next on our research list.

Rating key: Positive / Free / Fast Limited / Moderate Difficult / Steep Informational
Attribute
OWASP ZAP
OWASP
×
Pricing Free
Free tier / OSS 100%
open source
License Apache
2.0
Testing type Security / DAST
Languages / SDKs Python, Groovy (ZAP scripting API)
Supported platforms Windows, macOS, Linux, Docker
Parallel testing Yes
— headless/daemon mode
Speed Moderate
Key integrations Jenkins, GitHub Actions, Azure DevOps, Selenium
Learning curve Moderate
Community / Support Very
large — OWASP global community
Maintained by OWASP / Software Security Project
First released 2010
Latest version See website
Best suited for Free DAST scanning in CI/CD pipelines
Official site www.zaproxy.org ↗

Missing something?

Submit a tool, certification or service provider and we'll add it to the catalogue.