The free, open-source DAST scanner that attacks your running application.
ZAP (Zed Attack Proxy) is an intercepting proxy and dynamic scanner that probes a running application for injection, misconfiguration, authentication and session flaws. It can run as an automated baseline scan in CI or as an interactive tool for manual security testing, and it is the standard free option in the category.
Best for
Free and open source
Open sourceFree tier: Everything, self-hosted
What drives the bill: Free and open source. You pay in engineering time and CI minutes.
Check current pricing on Checkmarx / OWASP’s siteFigures are indicative and were last reviewed August 2026. Vendors change pricing often; confirm before you commit.
No reviews of OWASP ZAP yet. If you have used it in anger, yours would be the first.
If OWASP ZAP is not the right fit, these solve the same problem differently.
Security Testing
The professional web security tester's tool of choice, plus an enterprise scanner.
Security Testing
DAST with proof-based scanning that confirms a vulnerability is real before reporting it.
Security Testing
Enterprise application security platform: SAST, SCA, DAST, IaC and API security.