awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
zaproxy avatar

zaproxy/zaproxy

0
View on GitHub↗
15,293 estrellas·2,576 forks·Java·Apache-2.0·6 vistaswww.zaproxy.org↗

Zaproxy

OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services.

The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

Features

  • Traffic Interception and Modification - Provides a proxy for capturing, redirecting, and actively altering network requests and responses in transit.
  • Web Application Security - Provides tools for testing, verifying, and scanning web applications and APIs for security vulnerabilities.
  • Web Security Testing - Provides automated scanning and auditing of web applications for common vulnerabilities.
  • Web Vulnerability Scanning - Identifies security weaknesses in web applications through automated vulnerability scanning.
  • Traffic Proxying - Acts as an intercepting proxy to capture and modify network traffic between a browser and a web application.
  • Application Surface Mapping - Builds a hierarchical model of target applications by discovering links and endpoints through spidering.
  • Dynamic Application Security Testing - Analyzes running web applications to identify security flaws that only appear during execution.
  • Passive Analysis Pipelines - Monitors existing traffic flows in the background to identify security flaws without altering requests.
  • Penetration Testing Frameworks - Provides a comprehensive framework for automating the discovery and exploitation of web security weaknesses.
  • Security Analysis Tools - Performs automated inspection of traffic and application behavior to identify potential security weaknesses.
  • Security Testing Tools - Ships a specialized set of tools to actively probe and exploit vulnerabilities for professional penetration testing.
  • Web Application Penetration Testing - Enables systematic identification and validation of security flaws in web services through manual probing.
  • Active Scanning Engines - Implements an active scanning engine that sends malicious payloads to identify web vulnerabilities.
  • Pipeline Security - Integrates automated vulnerability scanning directly into CI/CD deployment workflows.
  • Session State Simulation - Simulates verified sessions by maintaining and injecting authentication tokens and cookies during scans.
  • Plugin-Based Architectures - Utilizes a plugin-based architecture to allow extending core functionality with new security tests and toolsets.
  • Containerized Security Environments - Docker image for the OWASP Zed Attack Proxy
  • Vulnerability Environments - Automated web application security testing proxy.
  • API Testing and Validation - Automated scanner for identifying security vulnerabilities in APIs.
  • Security Frameworks - Core project for automated web application security testing.
  • Web Security Tools - Integrated penetration testing tool for finding web vulnerabilities.
  • Dynamic Analysis - Open-source web application vulnerability scanner with CI/CD support.
  • General Web Scanners - Industry-standard intercepting proxy and automated vulnerability scanner.
  • Security and Encryption - Performs integrated web application penetration testing.
  • Security Auditing - Web application security testing and vulnerability scanning proxy.
  • Security Testing - Intercepting proxy for HTTP manipulation and security scanning.
  • Traffic Interception - Manipulator-in-the-middle proxy for web security testing.
  • Traffic Proxying and Interception - Core OWASP project for web application security testing.
  • Vulnerability Scanners - Popular open-source web security testing tool.

Historial de estrellas

Gráfico del historial de estrellas de zaproxy/zaproxyGráfico del historial de estrellas de zaproxy/zaproxy

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a Zaproxy

Proyectos open-source similares, clasificados según cuántas características comparten con Zaproxy.
  • andresriancho/w3afAvatar de andresriancho

    andresriancho/w3af

    4,850Ver en GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    Ver en GitHub↗4,850
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Ver en GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    Ver en GitHub↗3,020
  • dstotijn/hettyAvatar de dstotijn

    dstotijn/hetty

    11,485Ver en GitHub↗

    Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit

    Go
    Ver en GitHub↗11,485
  • sqlmapproject/sqlmapAvatar de sqlmapproject

    sqlmapproject/sqlmap

    37,676Ver en GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    Pythondatabasedetectionexploitation
    Ver en GitHub↗37,676
Ver las 30 alternativas a Zaproxy→

Preguntas frecuentes

¿Qué hace zaproxy/zaproxy?

OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services.

¿Cuáles son las características principales de zaproxy/zaproxy?

Las características principales de zaproxy/zaproxy son: Traffic Interception and Modification, Web Application Security, Web Security Testing, Web Vulnerability Scanning, Traffic Proxying, Application Surface Mapping, Dynamic Application Security Testing, Passive Analysis Pipelines.

¿Qué alternativas de código abierto existen para zaproxy/zaproxy?

Las alternativas de código abierto para zaproxy/zaproxy incluyen: andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… dstotijn/hetty — Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic… sqlmapproject/sqlmap — This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It… hackmanit/web-cache-vulnerability-scanner — This project is an automated security scanner designed to identify vulnerabilities within web caching layers. It… chaitin/xray — Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology…