It's been two months since this profile received a new review
Leave a Review
Compare this with other toolsSave it to your board and evaluate your options side by side.
Save to board

ZAP by Checkmarx Reviews & Product Details

Profile Status

This profile is currently managed by ZAP by Checkmarx but has limited features.

Are you part of the ZAP by Checkmarx team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Pricing

Pricing provided by ZAP by Checkmarx.

Open source

Free
Product Avatar Image

Have you used ZAP by Checkmarx before?

Answer a few questions to help the ZAP by Checkmarx community

ZAP by Checkmarx Reviews (13)

Reviews

ZAP by Checkmarx Reviews (13)

4.7
12 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise the ease of use and automation features of ZAP, highlighting its effectiveness for web application security scanning. Many appreciate its integration capabilities with CI/CD tools, making it suitable for various testing environments. However, a common limitation noted is the lack of comprehensive documentation, which can hinder new users.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
UI
Mid-Market (51-1000 emp.)
"A tool I use just for Web/API Security Automation"
What do you like best about ZAP by Checkmarx?

The detection mechanisms developed for ZAP are quite effective. It's easy to initiate an active scan or start crawling, and the built-in integration with Firefox is convenient. However, I find the user interface to be cluttered, so I primarily use it only for Active scans. Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

THe UI can surely be made clearer similar to burp, and it would just outstand burp in a blink of an eye. Specially the request response windows are too narrow and tools and settings are just plain dropdown lists which is not so great to be navigating through. Review collected by and hosted on G2.com.

Abhinav N.
AN
Cyber Security Analyst
Computer & Network Security
Small-Business (50 or fewer emp.)
"the best web application security scanner"
What do you like best about ZAP by Checkmarx?

Zap is one of the best web application security scanner ithink it has more features than burpsuite. ZAP has more automated scan features and the spider fuzz and ajax spider they are really amazing . i like recommend using ZAP for automated scans. Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

ZAP does not have a browser . like burpsuite zap needs to implement that Review collected by and hosted on G2.com.

VishNu C.
VC
Digital Marketing Executive
Small-Business (50 or fewer emp.)
"Best Free web app penetration testing App"
What do you like best about ZAP by Checkmarx?

The owasp zap can be even use in windows and we don't need any Linux OS also it is very easy to use and it's free of cost.We can also customise zap according to our testing need switch certain scripts. Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

Owasp has only some limited automated tasks and may not have new features like all other web pen testing apps Review collected by and hosted on G2.com.

Mohammed N.
MN
Penetration Tester
Small-Business (50 or fewer emp.)
"Best tool for scanning Website"
What do you like best about ZAP by Checkmarx?

As a seurity reasercher this tool has help me to scan the website.ones the scan is completed you can generate the report.the automated scan feture is really good,if your a begginner you don't have much knowledge in security scan you can try this tool.very user friendly and easy to understand all the fetures.

very easy to install.more you use you will be masterthe tool. Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

This tool give some false positive findings thats the we need to check all the finding is true or not moreover its a great tool for web application assessment. Review collected by and hosted on G2.com.

Jay P.
JP
Cyber Security Intern
Small-Business (50 or fewer emp.)
"OWasp Zap Proxy for web penetrations testing"
What do you like best about ZAP by Checkmarx?

Owasp zap proxy is the best recon and penetration testing tool which contains the all things from manual testing to auatomation testing . for me specialy automatic testing is the best testing with ajax spider and active scanning perform the all vulnerability test which is really good. Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

sometimes in automation testing it give false positive but to avoid that thing we have to configure all scanning and moreover install some scripts to reduce it. but overall this tool is all in one Review collected by and hosted on G2.com.

Gopi  K.
GK
SDE-3
Hospital & Health Care
Small-Business (50 or fewer emp.)
"ZAP is open source user friendly efficient pentesting tool."
What do you like best about ZAP by Checkmarx?

1. It is open source

2. Customizable dashboards and user friendly interface

3. Active and Passive automated Scanning provided along with proxy interception support.

4. easy integration with CI/CD piplelines Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

1. It is resource intensive and takes considerable amount of time for big applications

2. Issue with False positives leading to need of manual intervention many times Review collected by and hosted on G2.com.

Muhammad M.
MM
Penetration Tester
Small-Business (50 or fewer emp.)
"A free web scanner with amazing futures"
What do you like best about ZAP by Checkmarx?

OWASP zap is world best web app security scanner, and it is open source, and also it's powered by OWASP, the best thing is it's free Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

Almost is really good but Some time its gives false positive Review collected by and hosted on G2.com.

Ashwin  H.
AH
Cloud Associate - QA
Information Technology and Services
Enterprise (> 1000 emp.)
"Good product for security testing"
What do you like best about ZAP by Checkmarx?

It is easy to use and there are different types of attacks present which can be done in easier way Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

Until now the product is good so no negative remark Review collected by and hosted on G2.com.

Verified User in Computer Software
UC
Enterprise (> 1000 emp.)
"Recommend for security scans"
What do you like best about ZAP by Checkmarx?

Support for Active, Passive and Fuzzy scans via Desktop app as well as it can be used via API bindings which can be further integrated in pipelines and can be scheduled as required Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

For using OWASP ZAP little more crisp documentation is required though we will get best community support.

Application can be used by beginer but for getting expertise we need some more documentation. Review collected by and hosted on G2.com.

Vijudev V.
VV
Mid-Market (51-1000 emp.)
"ZAP integration in CICD process for SecOps"
What do you like best about ZAP by Checkmarx?

Easy to integrate with the CICD tools like Jenkins, Number of features like different scan methods Review collected by and hosted on G2.com.

What do you dislike about ZAP by Checkmarx?

about the documentation available in the websites Review collected by and hosted on G2.com.

People Icons

Start a Discussion about ZAP by Checkmarx

Have a software question? Get answers from real users and experts.

Start a Discussion

Pricing Options

Pricing provided by ZAP by Checkmarx.

Open source

Free
ZAP by Checkmarx Comparisons
Product Avatar Image
Metasploit
Compare Now
Product Avatar Image
Acunetix by Invicti
Compare Now
Product Avatar Image
Invicti (formerly Netsparker)
Compare Now
ZAP by Checkmarx Features
API / Integrations
Extensibility
Reporting and Analytics
Issue Tracking
Reconnaissance
Vulnerability Scan
Command-Line Tools
Manual Testing
Test Automation
Product Avatar Image
ZAP by Checkmarx