Open Source Zed Attack Proxy (ZAP) AlternativesPenetration Testing Tools and other similar apps like Zed Attack Proxy (ZAP)

The best open source alternative to Zed Attack Proxy (ZAP) is mitmproxy. If that doesn't suit you, our users have ranked more than 25 alternatives to Zed Attack Proxy (ZAP) and ten of them is open source so hopefully you can find a suitable replacement. Other interesting open source alternatives to Zed Attack Proxy (ZAP) are HTTP Toolkit, Lonkero, Nikto and w3af.

Copy a direct link to this comment to your clipboard
Zed Attack Proxy (ZAP) alternatives page was last updated

Alternatives list

  1. mitmproxy icon
     78 likes

    mitmproxy is an SSL-capable man-in-the-middle proxy for HTTP. It provides a console interface that allows traffic flows to be inspected and edited on the fly. It also features mitmdump, a commandline tool that provides a tcpdump-like interface for saving, viewing and...

    23 mitmproxy alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Platforms

    • Mac
    • Windows
    • Linux
    • Flathub
    • Flatpak
     
  2. HTTP Toolkit icon
     99 likes

    HTTP Toolkit is a beautiful, cross-platform & open-source HTTP(S) debugging proxy, analyzer & client, with built-in support for modern tools and automatic interception for clients from Docker to Android to iOS.

    50 HTTP Toolkit alternatives

    Cost / License

    Platforms

    • Mac
    • Windows
    • Linux
    • Android
    • iPhone
    • Docker
     
  3. Lonkero icon
     1 like

    Lonkero is a high-performance web vulnerability scanner built in Rust for penetration testers and bug bounty hunters who are tired of slow, bloated tools that generate hundreds of false positives.

    Cost / License

    • Freemium
    • Open Source

    Platforms

    • Mac
    • Windows
    • Linux
    • Self-Hosted
    • Rust
     
  4. Nikto icon
     21 likes

    Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files/CGIs, checks for outdated versions of over 1000 servers, and version specific problems on over 270 servers.

    21 Nikto alternatives

    Cost / License

    • Free
    • Open Source

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
     
  5. w3af icon
     16 likes

    w3af is a Web Application Attack and Audit Framework.

    Cost / License

    • Free
    • Open Source

    Platforms

    • Windows
    • Linux
     
  6. nuclei icon
     2 likes

    Nuclei is used to send requests across targets based on a template, leading to zero false positives and providing fast scanning on a large number of hosts. Nuclei offers scanning for a variety of protocols, including TCP, DNS, HTTP, SSL, File, Whois, Websocket, Headless etc.

    26 nuclei alternatives

    Cost / License

    • Free
    • Open Source (MIT)

    Application type

    Platforms

    • Mac
    • Windows
    • Linux
     
  7. James icon
     5 likes

    James is a HTTP Proxy and Monitor that enables developers to view and intercept requests made from the browser. It is an open-source alternative to the popular developer tool Charles.

    Cost / License

    • Free
    • Open Source

    Alerts

    • Discontinued

    Platforms

    • Mac
    • Windows
    • Linux
    • React
    • Electron / Atom Shell
    • Node.JS
     
  8. skipfish icon
     13 likes

    A fully automated, active web application security reconnaissance tool. Key features: High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.

    Cost / License

    • Free
    • Open Source

    Application type

    Alerts

    • Discontinued

    Platforms

    • Mac
    • Windows
    • Linux
    • BSD
     
  9. WHID Injector was born from the need for cheap and dedicated hardware that could be remotely controlled in order to conduct HID attacks. WHID stands for WiFi HID Injector. It is a cheap but reliable piece of hardware designed to fulfill pentesters needs related to HID Attacks...

    Cost / License

    Application type

    Platforms

    • APKPure
     
  10. Tamper Data icon
     5 likes

    Firefox add-on that lets you change headers and request parameters before they're sent to the server. Unlike proxy request modifiers, it's integrated into the browser, so it has no problem with HTTPS connections, client authentication certificates, or other features that...

    Cost / License

    • Free
    • Open Source

    Application type

    Alerts

    • Discontinued

    Platforms

    • Mac
    • Windows
    • Linux
    • Firefox
     
10 of 10 Zed Attack Proxy (ZAP) alternatives