Back to Secrets Management

OWASP ZAP

Open-source web application security scanner for finding vulnerabilities automatically.

Free and open-source (Apache 2.0)

OWASP ZAP (Zed Attack Proxy) is a free, open-source web application security scanner maintained by OWASP. It actively scans web applications during development and testing for vulnerabilities like SQL injection, cross-site scripting (XSS), and broken authentication. Features: automated scanner, manual intercepting proxy, API scanning, and CI/CD integration.

  • Best for: Secrets Management
  • Pricing: Free and open-source (Apache 2.0)

Disclosure: We may earn a commission if you click this link and make a purchase, at no additional cost to you.

Visit OWASP ZAP

OWASP ZAP Hub

Features

Audit Logging

Track all secret access and changes

CI/CD Integration

Native integration with CI/CD pipelines

Dynamic Secrets

Generate short-lived credentials on demand

Encryption at Rest

Secrets encrypted in storage

End-to-End Encryption

Client-side encryption before storage

Kubernetes Integration

Native K8s secret injection

Multi-Cloud Sync

Sync secrets across cloud providers

RBAC

Role-based access control for secrets

Secret Rotation

Automatic credential rotation on schedule

Self-Hosted Option

Run on your own infrastructure

Best For

Find the right DevOps tools for your specific needs. OWASP ZAP is featured in these buying guides:

Related Links