Skip to content
Nexera Nexera
General-purpose scanner

OWASP ZAP

The most widely used open-source web application scanner.

01

What it does

ZAP crawls your entire site and actively attacks its own forms, parameters, headers and sessions, testing thousands of ways an attacker could break your specific code — from injection and cross-site scripting to broken authentication and insecure configuration.

02

What data you get

A ranked list of findings with severity, the exact URL and parameter affected, evidence of the issue, and a description of how to reproduce and fix each one.

03

Why it matters to your site

This is the broadest look at flaws that live in code you wrote or configured — the ones no public vulnerability database can warn you about because they are unique to your site.