Back to Secrets Management

OWASP ZAP

Open-source web application security scanner for finding vulnerabilities automatically.

Free and open-source (Apache 2.0)

OWASP ZAP (Zed Attack Proxy) is a free, open-source web application security scanner maintained by OWASP. It actively scans web applications during development and testing for vulnerabilities like SQL injection, cross-site scripting (XSS), and broken authentication. Features: automated scanner, manual intercepting proxy, API scanning, and CI/CD integration.

  • Best for: Secrets Management
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit OWASP ZAP

OWASP ZAP Hub

Features

✗

Audit Logging

Track all secret access and changes

✗

CI/CD Integration

Native integration with CI/CD pipelines

✗

Dynamic Secrets

Generate short-lived credentials on demand

✗

Encryption at Rest

Secrets encrypted in storage

✗

End-to-End Encryption

Client-side encryption before storage

✗

Kubernetes Integration

Native K8s secret injection

✗

Multi-Cloud Sync

Sync secrets across cloud providers

✗

RBAC

Role-based access control for secrets

✗

Secret Rotation

Automatic credential rotation on schedule

✗

Self-Hosted Option

Run on your own infrastructure

Best For

Find the right DevOps tools for your specific needs. OWASP ZAP is featured in these buying guides:

Related Links