← All website monitoring tools
OWASP ZAP
Most popular free open-source DAST scanner — active/passive web scanning, intercepting proxy, CI/CD integration.
Free tier: fully free, open-source (Apache 2.0)
What it does well
- Completely free and open-source under the Apache 2.0 license with no feature restrictions.
- Extensive functionality through a large marketplace of free add-ons for various scanning needs.
- Offers multiple operational modes, including a desktop GUI, daemon mode, and CI/CD automation.
Where it falls short
- Self-hosted only, requiring users to manage installation, updates, and system resources themselves.
- Can generate a high number of false positives without careful tuning and context configuration.
- Lacks dedicated enterprise support; relies on community forums and documentation for help.
Alternatives to OWASP ZAP
Template-driven fast scanner — community templates cover thousands of CVEs. Free CLI, paid managed cloud.
Nikto
freeLong-running open-source web server scanner — checks 6,700+ dangerous files and outdated software.
Burp Suite
freemiumIndustry-standard pentest proxy — free Community for manual work, Pro $449/yr per user, Enterprise from $6,995/yr.
Pentest-Tools.com
freemiumOnline toolkit of 25+ pentest scanners (web, network, recon) — paid plans from $93/mo with unlimited scans.