OWASP ZAP versions

Security tools to find security vulnerabilities in your web applications
2.5
Jun 7, 2016
Review
2.4
Apr 16, 2015
Editorial review
rating
2.3
Apr 10, 2014
2.2
Sep 12, 2013
2.1
Apr 23, 2013
2.0
Jan 31, 2013
1.4
Apr 15, 2012
Sep 30, 2013
1.3
Jul 7, 2011
1.2
Feb 25, 2011

What's new

v2.4 [Apr 16, 2015]
Enhancements:
Issue 1576 : Define URL path elements as 'non structural'
Issue 1711 : Feature request: Option to specify number of token to be generated.
Issue 1768 : Update to use a more recent user-agent
Issue 1894 : ZAP only scans "User-Agent", "Referer", and "Host" request headers
Issue 1911 : Search AJAX spider requests
Issue 1913 : Pass all params across to zap.sh - debian package
Issue 1914 : Multiple add-on directories
Issue 1920 : Report the host:port ZAP is listening on in daemon mode, or exit if it cant
Issue 1927 : Enhancement: Break only for in-scope URLs.
Issue 1944 : Chart responses per second in ascan progress
Issue 1953 : Allow to spider a context through the ZAP API
Issue 1962 : Install and update add-ons from the command line
Issue 1975 : RC4-SHA SSL cipher suite not supported
Issue 1980 : Add ZAP CLI to Docker images
Issue 1985 : Bring up the Modify dialog if the user doubles on a row in a AbstractMultipleOptionsBaseTablePanel
Issue 2009 : Add Online links to the FAQ and Newsletter pages
Issue 2084 : Warn users if they are probably using out of date versions
Issue 2086 : Report request counts per plugin
Issue 2088 : Support an 'update all' button for installing all updated add-ons
Issue 2094 : Support a '-addoninstallall' command line option
Issue 2102 : Allow ajax spider options to be set via the API
Bug fixes:
Issue 1070 : Breaking on custom URL with query parameters does not work.
Issue 1555 : SAXParseException while generating the report
Issue 1617 : ZAP 2.4.0 throws HeadlessExceptions when running in daemon mode on headless machine
Issue 1877 : fix path to .ZAP_JVM.properties in zap.sh
Issue 1893 : Regression: Can't disable and enable specific scanners through the API
Issue 1910 : API does not return content in the expected encoding, on errors
Issue 1917 : Request and Response tabs dont scale the text
Issue 1939 : Scripts - Save Button Enablement Issue
Issue 1949 : Script with missing type prevents scripts and templates from being loaded
Issue 1950 : Connection closed without response, with an Authentication script with errors
Issue 1951 : Exception when trying to add users before loading an authentication script
Issue 1960 : Active Scan dialogue might use outdated scan policy
Issue 1969 : Issues with installation of scanners
Issue 1970 : Installed add-on dependencies might not be taken into account when installing add-ons
Issue 1973 : Returned HAR/list does not contain correct redirection messages
Issue 1981 : Spider might not report the correct number of URIs found
Issue 2005 : Active scanning incorrectly performed on sibling nodes
Issue 2044 : Issues in Hirschberg's algorithm implementation
Issue 2045 : Dont copy old configs if -dir option used
Issue 2052 : Authentication changes done through the API not saved to session

Alternative downloads

soapUI
soapUI
Free
rating

Create end-to-end tests on REST and SOAP APIs, and other web services.

OWASP Zed Attack Proxy
OWASP Zed Attack Proxy
Free
rating

Find security vulnerabilities in web applications.

Splint
Splint
Free
rating

A tool for statically checking C programs for security vulnerabilities.

Email Spider
Email Spider
rating

It provides database integration for easy sorting and protecting your data!

AppPerfect App Test
AppPerfect App Test
rating

A fully Automated Functional testing and Regression testing software