ZAP The Zed Attack Proxy is one of the world’s most popular free security tools and is actively maintained by a dedicated international team of volunteers. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. It's also a great tool for experienced pentesters to use for manual security testing. For more details about ZAP see the new ZAP website at zaproxy.org
FEATURES
SIMILAR TOOLS
ARM TrustZone provides a secure execution environment for applications on ARM processors.
WordPress plugin to reduce comment spam with a smarter honeypot.
Reformat and re-indent bookmarklets, ugly JavaScript, and unpack scripts with options available via UI.
Yaramod is a library for parsing YARA rules into AST and building new YARA rulesets with C++ programming interface.
InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection
A tool for building and installing PhoneyC with optional Python version configuration and root privileges.
An integrated security platform that provides API discovery, runtime protection, security testing, and incident response capabilities for web applications, APIs, and AI systems.
Veracode is an intelligent software security platform that helps developers and security teams secure code, find and fix flaws, and automate remediation.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.