The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




The best Penetration Testing alternative to Burp Suite is Zed Attack Proxy (ZAP), which is both free and Open Source. If that doesn't suit you, our users have ranked more than 25 alternatives to Burp Suite and 13 are Penetration Testing Tools so hopefully you can find a suitable replacement. Other interesting Penetration Testing Tool alternatives to Burp Suite are HTTP Toolkit, Caido, Astra Pentest and Intruder.
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.




HTTP Toolkit is a beautiful, cross-platform & open-source HTTP(S) debugging proxy, analyzer & client, with built-in support for modern tools and automatic interception for clients from Docker to Android to iOS.




Caido is a cutting-edge web application security tool that enables users to efficiently identify and assess potential vulnerabilities in their web applications. It can be easily integrated into both personal and enterprise environments, making it adaptable to a wide range of...



Astra’s Pentest is a comprehensive penetration testing solution with an intelligent automated vulnerability scanner coupled with in-depth manual pentesting.


Intruder is a security monitoring platform for internet-facing systems.
Intruder provides an easy to use security solution which continually scans your digital assets, highlighting vulnerabilities and outlining remediation advice in simple terms.


Find security vulnerabilities right from your browser. Experience the next generation security tools without the need to install any additional software.




Put yourself in the shoes of a hacker! Without technical expertise, launch an audit to detect security flaws on your website or web application. Online website vulnerability scanner. No installation required. ISO & RGPD compliant. How to avoid hackers?

this is a scanner not a manual testing proxy


Probely is a top-tier cloud-based DAST Scanner designed for DevOps, empowering Security and Development teams to work together to secure their web applications and APIs.




TEQNIX is a platform with a number of tools and strategies for penetration testers, red teamers and secops. It promotes automation with scanners and utilities and also assist in a real-time attack situation.



Websecurify is a powerful web application security testing environment designed from the ground up to provide the best combination of automatic and manual vulnerability testing technologies.
SmartScanner is an AI-powered web vulnerability scanner for testing security of web sites and applications.


Human-in-the-loop penetration testing enhanced with AI. Identify vulnerabilities faster, reduce risk, and stay audit-ready with actionable reports and real-time visibility.



this is a scanner not a proxy used for manual app testing