Download OWASP ZAP – Free Web Application Security Scanner

OWASP ZAP is the world's most popular free open-source web application security scanner with active/passive scanning, intercepting proxy, spider, and CI/CD API integration.

Download
  • Publisher:
    OWASP Foundation
  • Version:
    2.16.1
  • License:
    Free
  • File Size:
    216 MB
  • Downloads:
    2451
  • Updated:
    22/09/2025
  • Requirements:
    Windows7,8,10,11

OWASP ZAP (Zed Attack Proxy) is the world’s most widely used free and open-source web application security scanner, developed under the OWASP (Open Web Application Security Project) umbrella. It is designed to help security professionals and developers find vulnerabilities in web applications during development and penetration testing, acting as a man-in-the-middle proxy between the browser and the web application.

ZAP provides both an easy-to-use graphical interface and a powerful command-line API, making it suitable for both manual security testing by beginners and automated security scanning in CI/CD pipelines by experienced DevSecOps teams. Its active and passive scanning engines detect a wide range of security issues including SQL injection, XSS, CSRF, insecure headers, and many OWASP Top 10 vulnerabilities.

With a rich marketplace of community-developed add-ons, ZAP can be extended with additional scanning rules, authentication handlers, reporting formats, and integration plugins. It is used by security professionals worldwide and is the go-to tool recommended by OWASP for web application penetration testing.

Key Features

  • Intercepting proxy to inspect and modify HTTP/HTTPS traffic between browser and target application.
  • Active scanner to automatically detect vulnerabilities including SQL injection, XSS, CSRF, and more.
  • Passive scanner that analyzes traffic without sending additional requests, safe for production use.
  • Spider and AJAX spider for comprehensive web application crawling and link discovery.
  • Fuzzer for automated testing of inputs with custom payloads and attack patterns.
  • REST API and command-line interface for CI/CD pipeline integration and automation.
  • Extensive add-on marketplace for additional scanning rules, authentication, and reporting.
OWASP ZAP web application security scanner main interface OWASP ZAP active scan results showing discovered vulnerabilities

How to Install

  1. Ensure Java 11 or later is installed on your system.
  2. Download the OWASP ZAP installer for your operating system from the link below.
  3. Run the installer and follow the setup wizard to complete installation.
  4. Launch ZAP and choose between the GUI mode for manual testing or headless mode for automation.
  5. Configure your browser to use ZAP as an HTTP proxy (default: localhost:8080) to start intercepting and scanning traffic.

Frequently Asked Questions about OWASP ZAP – Free Web Application Security Scanner

Is OWASP ZAP – Free Web Application Security Scanner free?

OWASP ZAP – Free Web Application Security Scanner is completely free to download and use — no registration or payment required.

What are the system requirements for OWASP ZAP – Free Web Application Security Scanner?

Minimum requirements: Windows7,8,10,11. A modern PC with at least 2GB RAM is recommended.

What is the latest version of OWASP ZAP – Free Web Application Security Scanner?

The latest version is 2.16.1, updated on 22/09/2025.

Is OWASP ZAP – Free Web Application Security Scanner safe to download?

Yes. All software listed on download.viet33.com is sourced directly from the official developer and verified before publishing. No bundled adware or malware.

Does OWASP ZAP – Free Web Application Security Scanner work on Windows 11?

Yes, OWASP ZAP – Free Web Application Security Scanner is compatible with Windows7,8,10,11, including Windows 11.

Other Versions
Search: