![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHWfjiGESw7ZFpnbtkzChuekR_A71obdUyz1NKeLfzuTIlq3XcLKuYyzvjo4J3BRdU0OBAYe02wRAkibA3cT4fPwRzZ989ZunicuuCaxGOAleJeBpyhfblUbIUA2_sIMfLYLEz4eGQTfY/s1600/zap-banner.png)
Some of ZAP’s features:
- Intercepting Proxy
- Automated scanner
- Passive scanner
- Brute Force scanner
- Spider
- Fuzzer
- Port scanner
- Dynamic SSL certificates
- API
- Beanshell integration
Some of ZAP’s characteristics:
- Easy to install (just requires java 1.6)
- Ease of use a priority
- Comprehensive help pages
- Fully internationalized
- Under active development
- Open source
- Free (no paid for ‘Pro’ version)
- Cross platform
- Involvement actively encouraged