AppSecNews
DAST Freemium Emerging

ZeroThreat

by ZeroThreat

Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.

Visit zerothreat.ai (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run ZeroThreat in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 5 points in this profile are not yet confirmed against vendor documentation.
  • Detection engine and whether it is proprietary or built on an open engine: confirm with vendor
  • Authentication handling and supported login flow types: verify
  • API specification formats accepted: verify
  • Integration list: unknown, confirm against vendor documentation
  • What the free tier includes versus paid tiers: verify feature boundaries, not cost

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

ZeroThreat is a hosted dynamic application security scanner. You register a target application, provide authentication details if testing behind a login, and the service crawls the application and runs attack checks against the discovered pages, forms and parameters, covering the common dynamic classes: injection, cross-site scripting, misconfiguration, information disclosure and transport and header weaknesses. API testing is offered alongside web application testing. Results are presented in a hosted console with severity ratings and remediation guidance.

The positioning emphasizes reducing the configuration effort that makes traditional DAST slow to adopt, particularly around authentication, and reducing triage burden by filtering low-value findings before they reach you. Beyond that general shape the specifics are not something to state with confidence here. The details that decide whether such a scanner earns a slot in your program, namely how it handles complex login flows, how API endpoints are enumerated, what the underlying detection engine is, and where findings can be sent, should be confirmed against vendor documentation and a trial run.

Where it fits

A hosted scanner of this shape runs on a schedule against internet-facing staging or production applications, operated by whoever owns application security, often in a team with no dedicated specialist. Because scanning originates from vendor infrastructure, internal applications behind a firewall are likely out of scope unless an agent or connector is offered, which is worth checking. As with any dynamic scanner, you need authorization to test, a defined scope and an exclusion list so destructive functionality is not triggered.

Strengths

  • A free entry tier lowers the barrier to trying dynamic scanning against a real application before committing to anything.
  • Hosted delivery removes scanner installation, maintenance and infrastructure work entirely.
  • Web application and API scanning are presented in one console rather than as separate exercises.

Limitations

  • The product is young and public technical detail is limited, so capability claims should be validated with a trial rather than accepted.
  • Automated dynamic scanning of any kind does not find broken access control, business logic abuse or multi-step workflow flaws.
  • Hosted scanning means your application traffic and any test credentials are handled by a third party, which is a data handling and procurement question.
  • Integration and workflow support are unconfirmed, so plan for manual export until you have verified otherwise.

Who it suits

Worth a trial for a small or mid-sized team that needs baseline dynamic coverage of an externally reachable application and does not want to run a scanner themselves. Not a fit for an enterprise needing mature integrations, internal network coverage and long-term reporting, and not a substitute for manual testing of authorization logic.

Used ZeroThreat? Recommend it under your own name and title.

Recommend this tool