Back to library
Test & PolishToolOpen sourceFree

OWASP ZAP

A free open web-application security scanner with a proxy, spiders, active and passive rules, API scanning, an automation framework, add-ons, and CI-friendly Docker images.

Visit official site
Content updated Aug 3, 2026Automated check reached the official site · Checked Aug 24, 2026

Why use it

Indie games with accounts, leaderboards, payments, or content administration can repeat DAST against HTTP surfaces and catch configuration, header, and input problems missed by unit tests.

Where it fits

Use testing, performance, accessibility, and diagnostic tools to remove problems players will notice.

quality-assuranceprivacyautomation

What to check

Active scans send hostile requests and must run only against authorized, recoverable test systems; authentication, business logic, and false positives need human analysis, and rules require updates.

Search the site

Search resources and field guides

    Privacy settings

    Your language choice, open home-page sections, favorites, comparisons, and recent views stay in this browser. Nothing is uploaded.