HomeServices › OWASP ZAP

OWASP ZAP on a Mac

Open-source web-app security scanner (DAST) — spider, active scan, proxy · Security Tools

OWASP ZAP (Zed Attack Proxy) is the leading free, open-source web-application security scanner (DAST) — an intercepting proxy that spiders a site, runs passive and active scans for injection, XSS, misconfigurations and other OWASP-style issues, fuzzes inputs, and reports findings. Use the desktop GUI (brew install --cask zap), run it headless as a daemon (zap.sh -daemon -host 0.0.0.0 -port 8080) and drive it via its REST API / Automation Framework, or run it in CI with the Docker image (ghcr.io/zaproxy/zaproxy — baseline & full-scan). Point your browser at its proxy (127.0.0.1:8080) and trust its CA to inspect HTTPS. Complements the in-app Security Audit and the threat-intel tools here. Use ONLY against systems you're authorized to test.

Run OWASP ZAP with FrontierStack

FrontierStack lists OWASP ZAP in its Security Tools catalog. Install or connect it from one place, then monitor its status, ports and certificate, secure it with the firewall and Malware Audit, and back it up.

Run it all from one Mac app.

FrontierStack installs, monitors and secures the whole stack — locally and across your fleet — from a single native macOS app.

Download FrontierStack

Related in Security Tools