What it does
ZAP, the Zed Attack Proxy, is an intercepting proxy first. You route a browser or an application client through it and every request and response passes under inspection. Passive scanning runs over that traffic without sending anything extra, flagging missing security headers, cookie flag problems and information disclosure. Because it is a proxy, anything you exercise by hand becomes part of the tested surface, which is why it complements manual testing rather than replacing it.
Active scanning is the second half. From the site tree, built by proxied traffic, the traditional spider, or the AJAX spider that drives a real browser to reach script-generated content, ZAP injects payloads into parameters, headers and bodies and evaluates responses against its rule set: injection, cross-site scripting, path traversal, command execution and more. Almost all of this is extensible. Add-ons from a managed marketplace provide extra rules and protocol support, scan rules can be written in several scripting languages, and the Automation Framework expresses an entire scan as a YAML plan so the same configuration runs on a laptop and in CI. Packaged Docker scans and a control API cover headless and pipeline use.
Where it fits
ZAP spans the whole range. A tester runs the desktop application with a browser proxied through it during an assessment, using the manual request editor, fuzzer and break points. A development team runs the packaged baseline or full scan as a pipeline step against a deployed staging instance. A platform team drives it through its API. The only hard prerequisite is a reachable target and, for meaningful depth, an authentication configuration.
Strengths
- The proxy model means manual exploration and automated scanning reinforce each other rather than being separate exercises.
- The AJAX spider drives a real browser, which is what makes single-page applications reachable at all.
- Deeply scriptable: custom scan rules, an automation plan format and a complete API, so it fits automation you already have.
- Free and open with a large user base, so problems are usually already documented somewhere.
Limitations
- Active scanning produces meaningful false positives and needs a human who understands the findings, the cost of an open rule set with no confirmation step.
- Authentication and session configuration for modern applications is genuinely fiddly and the most common reason scans return shallow results.
- No multi-application management, findings history or triage workflow out of the box. You build or buy that separately.
Who it suits
The default choice for penetration testers, application security engineers and engineering teams that want capable dynamic testing without a purchase, and who have someone able to interpret the output. Less suitable for an organization wanting managed scanning of a large portfolio with curated findings and no in-house expertise to tune it.
Used ZAP? Recommend it under your own name and title.
Recommend this tool