Home › Services › OWASP ZAP

OWASP ZAP on a Mac

Open-source web-app security scanner (DAST); spider, active scan, proxy · Security Tools

OWASP ZAP (Zed Attack Proxy) is the leading free, open-source web-application security scanner (DAST); an intercepting proxy that spiders a site, runs passive and active scans for injection, XSS, misconfigurations and other OWASP-style issues, fuzzes inputs, and reports findings. Use the desktop GUI (brew install --cask zap), run it headless as a daemon (zap.sh -daemon -host 0.0.0.0 -port 8080) and drive it via its REST API / Automation Framework, or run it in CI with the Docker image (ghcr.io/zaproxy/zaproxy; baseline & full-scan). Point your browser at its proxy (127.0.0.1:8080) and trust its CA to inspect HTTPS. Complements the in-app Security Audit and the threat-intel tools here. Use ONLY against systems you're authorized to test.

Run OWASP ZAP with FrontierStack

Install or connect OWASP ZAP; then check its status, ports and certificate from FrontierStack. The same screen links to firewall checks, Malware Audit and backups where they apply.

Run it from your Mac.

FrontierStack installs, monitors and secures services on this Mac and on linked servers.

Download FrontierStack

Apple notarized · Safe & secure · macOS 13 Ventura+

Related in Security Tools