Security Scanning
OWASP ZAP
An open-source web application security scanner that performs dynamic application security testing against a running application.
Problem it solves
Why it exists.
It finds runtime web vulnerabilities that static analysis may miss because they depend on deployed behavior and responses.
Optimized for
Where it shines.
Staging environments and CI security checks for web applications and APIs.
Use with care
Where not to use it.
Do not scan production without authorization, safe boundaries, and traffic controls; validate findings before treating them as exploitable.
Components
What it is made of.
- Spider
- Active scanner
- Passive scanner
- Proxy
- API scanning
Process
How it works.
- ZAP explores the running application
- Passive rules inspect observed traffic
- Active tests send controlled probes
- Findings are reported for triage and remediation