{"id":13422934,"url":"https://github.com/zaproxy/zaproxy","last_synced_at":"2026-01-21T12:05:29.867Z","repository":{"id":33176404,"uuid":"36817565","full_name":"zaproxy/zaproxy","owner":"zaproxy","description":"The ZAP by Checkmarx Core project","archived":false,"fork":false,"pushed_at":"2026-01-12T17:32:43.000Z","size":201664,"stargazers_count":14614,"open_issues_count":849,"forks_count":2491,"subscribers_count":396,"default_branch":"main","last_synced_at":"2026-01-12T18:56:25.343Z","etag":null,"topics":["appsec","dast","hacktoberfest","opensource","security","security-scanner","zap","zap-development","zaproxy"],"latest_commit_sha":null,"homepage":"https://www.zaproxy.org","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zaproxy.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":"CLA.md"},"funding":{"custom":["https://www.zaproxy.org/sponsor/"]}},"created_at":"2015-06-03T16:55:01.000Z","updated_at":"2026-01-12T15:30:58.000Z","dependencies_parsed_at":"2023-12-18T16:02:18.328Z","dependency_job_id":"25cefeaf-e1e1-4ddd-9992-285f10967fd0","html_url":"https://github.com/zaproxy/zaproxy","commit_stats":{"total_commits":6423,"total_committers":260,"mean_commits":"24.703846153846154","dds":0.5997197571228399,"last_synced_commit":"c17a6c70a8a701c78b2a50ae00ba1f50f738d2cd"},"previous_names":[],"tags_count":573,"template":false,"template_full_name":null,"purl":"pkg:github/zaproxy/zaproxy","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zaproxy%2Fzaproxy","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zaproxy%2Fzaproxy/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zaproxy%2Fzaproxy/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zaproxy%2Fzaproxy/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zaproxy","download_url":"https://codeload.github.com/zaproxy/zaproxy/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zaproxy%2Fzaproxy/sbom","scorecard":{"id":1236687,"data":{"date":"2025-07-07","repo":{"name":"github.com/zaproxy/zaproxy","commit":"3f7c51a83265a76bbb20995a168dde5bac2c2632"},"scorecard":{"version":"v5.2.1-18-gbb9c347d","commit":"bb9c347dff6349d986baab6578a46d68a5524c62"},"score":6.9,"checks":[{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: SECURITY.md:1","Info: Found linked content: SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: SECURITY.md:1","Info: Found text in security policy: SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#security-policy"}},{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 13 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":5,"reason":"badge detected: Passing","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql.yml:16","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql.yml:17","Info: jobLevel 'contents' permission set to 'read': .github/workflows/pr-labeler.yml:10","Warn: no topLevel permission defined: .github/workflows/check-zap-errors.yml:1","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: topLevel 'actions' permission set to 'write': .github/workflows/cla.yml:12","Warn: topLevel 'contents' permission set to 'write': .github/workflows/cla.yml:13","Warn: topLevel 'statuses' permission set to 'write': .github/workflows/cla.yml:15","Warn: no topLevel permission defined: .github/workflows/codeql.yml:1","Warn: no topLevel permission defined: .github/workflows/crowdin-upload-files.yml:1","Warn: no topLevel permission defined: .github/workflows/handle-release.yml:1","Warn: no topLevel permission defined: .github/workflows/pr-labeler.yml:1","Warn: no topLevel permission defined: .github/workflows/prepare-release-main-version.yml:1","Warn: no topLevel permission defined: .github/workflows/release-live-docker.yml:1","Warn: no topLevel permission defined: .github/workflows/release-main-docker.yml:1","Warn: no topLevel permission defined: .github/workflows/release-main-version.yml:1","Warn: no topLevel permission defined: .github/workflows/release-snap.yml:1","Warn: no topLevel permission defined: .github/workflows/release-weekly-docker.yml:1","Warn: no topLevel permission defined: .github/workflows/release-weekly.yml:1","Warn: no topLevel permission defined: .github/workflows/run-integration-tests.yml:1","Warn: no topLevel permission defined: .github/workflows/sonar.yml:1","Warn: no topLevel permission defined: .github/workflows/test-packaged-scans.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#token-permissions"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact w2025-07-07 not signed: https://api.github.com/repos/zaproxy/zaproxy/releases/230533285","Warn: release artifact w2025-06-30 not signed: https://api.github.com/repos/zaproxy/zaproxy/releases/228805033","Warn: release artifact w2025-06-24 not signed: https://api.github.com/repos/zaproxy/zaproxy/releases/227421164","Warn: release artifact w2025-06-23 not signed: https://api.github.com/repos/zaproxy/zaproxy/releases/227096003","Warn: release artifact w2025-06-16 not signed: https://api.github.com/repos/zaproxy/zaproxy/releases/225530243","Warn: release artifact w2025-07-07 does not have provenance: https://api.github.com/repos/zaproxy/zaproxy/releases/230533285","Warn: release artifact w2025-06-30 does not have provenance: https://api.github.com/repos/zaproxy/zaproxy/releases/228805033","Warn: release artifact w2025-06-24 does not have provenance: https://api.github.com/repos/zaproxy/zaproxy/releases/227421164","Warn: release artifact w2025-06-23 does not have provenance: https://api.github.com/repos/zaproxy/zaproxy/releases/227096003","Warn: release artifact w2025-06-16 does not have provenance: https://api.github.com/repos/zaproxy/zaproxy/releases/225530243"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#branch-protection"}},{"name":"Binary-Artifacts","score":9,"reason":"binaries present in source code","details":["Warn: binary detected: gradle/wrapper/gradle-wrapper.jar:1"],"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#binary-artifacts"}},{"name":"Vulnerabilities","score":8,"reason":"2 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: PYSEC-2021-142 / GHSA-8q59-q68h-6hv4","Warn: Project is vulnerable to: PYSEC-2018-49 / GHSA-rprw-h62v-c2w7"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#vulnerabilities"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release-live-docker.yml:9"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#packaging"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":4,"reason":"dependency not pinned by hash detected -- score normalized to 4","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-zap-errors.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/check-zap-errors.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/ci.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/codeql.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/crowdin-upload-files.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/crowdin-upload-files.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/crowdin-upload-files.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/crowdin-upload-files.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/handle-release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/handle-release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/handle-release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/handle-release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-labeler.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/pr-labeler.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-release-main-version.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/prepare-release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-release-main-version.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/prepare-release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-live-docker.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-live-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-live-docker.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-live-docker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-main-docker.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-main-docker.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-docker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-main-version.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-main-version.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-main-version.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-main-version.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-main-version.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-snap.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-snap.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-weekly-docker.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-weekly-docker.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-weekly-docker.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-weekly-docker.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-weekly.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-weekly.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-weekly.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-weekly.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-weekly.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/release-weekly.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-integration-tests.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/run-integration-tests.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/sonar.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/sonar.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-packaged-scans.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/test-packaged-scans.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-packaged-scans.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/zaproxy/zaproxy/test-packaged-scans.yml/main?enable=pin","Warn: containerImage not pinned by hash: docker/Dockerfile-bare:3","Warn: containerImage not pinned by hash: docker/Dockerfile-bare:25","Warn: containerImage not pinned by hash: docker/Dockerfile-live:3","Warn: containerImage not pinned by hash: docker/Dockerfile-live:37","Warn: containerImage not pinned by hash: docker/Dockerfile-stable:3","Warn: containerImage not pinned by hash: docker/Dockerfile-stable:37","Warn: containerImage not pinned by hash: docker/Dockerfile-tests:3","Warn: containerImage not pinned by hash: docker/Dockerfile-tests:20: pin your Docker image by updating ghcr.io/zaproxy/zaproxy:nightly to ghcr.io/zaproxy/zaproxy:nightly@sha256:7ea10c7d808c258c277ccb460c879828ee4b4470de405a15c0284800375eb320","Warn: containerImage not pinned by hash: docker/Dockerfile-weekly:3","Warn: containerImage not pinned by hash: docker/Dockerfile-weekly:24","Warn: pipCommand not pinned by hash: docker/Dockerfile-live:70-79","Warn: pipCommand not pinned by hash: docker/Dockerfile-stable:64-72","Warn: pipCommand not pinned by hash: docker/Dockerfile-weekly:54","Warn: pipCommand not pinned by hash: .github/workflows/test-packaged-scans.yml:22","Warn: pipCommand not pinned by hash: .github/workflows/test-packaged-scans.yml:23","Info:   0 out of  30 GitHub-owned GitHubAction dependencies pinned","Info:  28 out of  32 third-party GitHubAction dependencies pinned","Info:   0 out of  10 containerImage dependencies pinned","Info:   0 out of   5 pipCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (30) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/bb9c347dff6349d986baab6578a46d68a5524c62/docs/checks.md#sast"}}]},"last_synced_at":"2025-09-01T15:22:01.451Z","repository_id":33176404,"created_at":"2025-09-01T15:22:01.451Z","updated_at":"2025-09-01T15:22:01.451Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28632781,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-21T04:47:28.174Z","status":"ssl_error","status_checked_at":"2026-01-21T04:47:22.943Z","response_time":86,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["appsec","dast","hacktoberfest","opensource","security","security-scanner","zap","zap-development","zaproxy"],"created_at":"2024-07-30T23:01:00.106Z","updated_at":"2026-01-21T12:05:29.847Z","avatar_url":"https://github.com/zaproxy.png","language":"Java","readme":"# [![](https://raw.githubusercontent.com/wiki/zaproxy/zaproxy/images/zap-by-checkmarx.png)](https://www.zaproxy.org)\n[![License](https://img.shields.io/badge/license-Apache%202-4EB1BA.svg)](https://www.apache.org/licenses/LICENSE-2.0.html)\n[![GitHub release](https://img.shields.io/github/release/zaproxy/zaproxy.svg)](https://www.zaproxy.org/download/)\n[![Java CI](https://github.com/zaproxy/zaproxy/actions/workflows/ci.yml/badge.svg)](https://github.com/zaproxy/zaproxy/actions/workflows/ci.yml)\n[![CII Best Practices](https://bestpractices.coreinfrastructure.org/projects/24/badge)](https://bestpractices.coreinfrastructure.org/projects/24)\n[![Github Releases](https://img.shields.io/github/downloads/zaproxy/zaproxy/latest/total.svg?maxAge=2592000)](https://zapbot.github.io/zap-mgmt-scripts/downloads.html)\n[![javadoc](https://javadoc.io/badge2/org.zaproxy/zap/javadoc.svg)](https://javadoc.io/doc/org.zaproxy/zap)\n[![CodeQL](https://github.com/zaproxy/zaproxy/actions/workflows/codeql.yml/badge.svg)](https://github.com/zaproxy/zaproxy/actions/workflows/codeql.yml)\n[![Quality Gate Status](https://sonarcloud.io/api/project_badges/measure?project=zaproxy_zaproxy\u0026metric=alert_status)](https://sonarcloud.io/dashboard?id=zaproxy_zaproxy)\n[![Open Source Helpers](https://www.codetriage.com/zaproxy/zaproxy/badges/users.svg)](https://www.codetriage.com/zaproxy/zaproxy)\n[![Twitter Follow](https://img.shields.io/twitter/follow/zaproxy.svg?style=social\u0026label=Follow\u0026maxAge=2592000)](https://twitter.com/zaproxy)\n\n![Integration Tests](https://github.com/zaproxy/zaproxy/actions/workflows/run-integration-tests.yml/badge.svg)\n![Docker Live Release](https://github.com/zaproxy/zaproxy/actions/workflows/release-live-docker.yml/badge.svg)\n\nThe Zed Attack Proxy (ZAP) by Checkmarx is the world’s most widely used web app scanner. \nFree and open source. A community based GitHub Top 1000 project that anyone can contribute to.\n\nIt can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. \nIt's also a great tool for experienced pentesters to use for manual security testing.\n\n[![](https://raw.githubusercontent.com/wiki/zaproxy/zaproxy/images/ZAP-Download.png)](https://www.zaproxy.org/download/)\n\nFor more details about ZAP see the website: [zaproxy.org](https://www.zaproxy.org/)\n\n[![](https://raw.githubusercontent.com/wiki/zaproxy/zaproxy/images/zap-website.png)](https://www.zaproxy.org/)\n","funding_links":["https://www.zaproxy.org/sponsor/"],"categories":["API Testing","Tools","Docker images for Penetration Testing","Java","Security Testing","Uncategorized","Network","\u003ca id=\"683b645c2162a1fce5f24ac2abfa1973\"\u003e\u003c/a\u003e漏洞\u0026\u0026漏洞管理\u0026\u0026漏洞发现/挖掘\u0026\u0026漏洞开发\u0026\u0026漏洞利用\u0026\u0026Fuzzing","security","Weapons","Software","Инструменты","Miscellaneous","Java (504)","Application Security","HarmonyOS","工具","扫描器、资产收集、子域名","AppSec Tools","安全","Application Recommendation","Docker Containers","Awesome Penetration Testing (\"https://github.com/Muhammd/Awesome-Pentest\")","Table of Contents","API \u0026 Dynamic Testing (DAST)","hacktoberfest","Runtime Analysis"],"sub_categories":["Desktop","Docker for Penetration Testing",".NET","Uncategorized","Docker Images for Penetration Testing \u0026 Security","\u003ca id=\"c0bec2b143739028ff4ec439e077aa63\"\u003e\u003c/a\u003e漏洞扫描\u0026\u0026挖掘\u0026\u0026发现","All","Dynamic Analysis","Security","Tools","Динамические анализаторы приложений (DAST)","Vulnerability Scanners","DAST","Windows Manager","有关渗透测试和安全方面的Docker镜像","网络服务_其他","🔒 Cybersecurity","Docker Containers of Penetration Testing Distributions and Tools","Runtime Security"],"project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzaproxy%2Fzaproxy","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzaproxy%2Fzaproxy","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzaproxy%2Fzaproxy/lists"}