Back to library
Test & PolishToolOpen sourceFree

OWASP ZAP

A free open web-application security scanner with a proxy, spiders, active and passive rules, API scanning, an automation framework, add-ons, and CI-friendly Docker images.

Visit official siteContent record updated Aug 3, 2026Official site reached automatically · Checked Aug 3, 2026

Why it’s here

Indie games with accounts, leaderboards, payments, or content administration can repeat DAST against HTTP surfaces and catch configuration, header, and input problems missed by unit tests.

Best fit

Testing, performance, accessibility, and diagnostics expose friction before launch.

quality-assuranceprivacyautomation

Before you commit

Active scans send hostile requests and must run only against authorized, recoverable test systems; authentication, business logic, and false positives need human analysis, and rules require updates.

Search resources

Type to search the entire resource library

    Privacy settings

    This first release does not use behavioral analytics, advertising, or third-party tracking. Only your language choice and home-section state are stored in your browser.