Icon

Zed Attack Proxy (ZAP)

Zed Attack Proxy (ZAP) is the world’s leading open-source web application security scanner, designed to make security testing easy and efficient for developers, testers, and security professionals.
Latest: 2.17.0 GitHub
Last checked: Jun 9, 2026 12:10am
Rank: 316/15140
Also monitored via:
Site Monitor Winget
Follow to track new versions in your feed.
Report

Overview

0
License: Open SourceWinget: Available

Version & Lifecycle

0
Current: 2.17.0 N-2: 0.7.6 Avg cadence: Every 494 days

Top Contributors

Top sitewide contributors:

  1. Anbarasan
  2. nico_k
  3. Bob
  4. Vigneshwaran

Community Notes

Deployment tip • May 5, 2026
0

ZAP Java 17 prerequisite and update close requirement

For managed Zed Attack Proxy (OWASP ZAP) Windows deployments, verify the Java runtime and close the desktop app before attempting an update. The official ZAP download page states that the Windows and Linux builds require Java 17 or higher to run; package detection should confirm the matching Java runtime architecture before treating installer failures as ZAP-specific.

The Windows ZAP EXE packages can return Exit Code 1 when ZAP is open during update. In Intune/ConfigMgr packaging, add a prerequisite/detection check for the matching Java runtime architecture and use a pre-close or user-notification workflow for the ZAP process before launching the update.

Release Notes & Updates

0
Avg cadence:
Updates • 0

Help us match vulnerabilities

No vulnerability match yet. Pick the right product:

Looking for matching products…
Don’t see it? Paste a CPE

Also known as

Other names people use for this app — helps search and matching.

ZAPln-zap ZAP

Notes

0

ZAP is maintained by Checkmarx and is widely used for web app and API security testing. It started in September 2024 according to recent data.