SE Radio 568: Simon Bennetts on OWASP Dynamic Application Security Testing Tool ZAP

Topics covered
Popular Clips
Episode Highlights
Open Source Challenges
Maintaining an open source project like ZAP comes with its own set of challenges, particularly in terms of resource allocation and community involvement. shares that while ZAP has a small core team, the tool's success heavily relies on contributions from the broader community 1. Funding remains a significant hurdle, as Bennetts notes the difficulty in securing financial support to sustain ongoing development efforts 2. He emphasizes the need for more companies to sponsor work on ZAP, similar to how Jit supports his efforts 1.
Raising money has never been one of our strengths, I'm afraid.
---
Despite these challenges, ZAP's status as a flagship project of OWASP highlights its importance and widespread use in the industry.
Community Contributions
Community contributions are vital to the growth and adaptation of ZAP, allowing it to remain competitive with commercial tools. explains that ZAP's open-source nature and community-based approach enable anyone to get involved, which is a key differentiator from other tools 3. The project encourages contributions beyond coding, including documentation and testing, making it accessible to a wide range of contributors 4.
We want people to get involved and we'll be very happy to help you.
---
Bennetts also highlights the importance of scripting capabilities, which allow users to customize ZAP to meet specific needs, further enhancing its utility and appeal.
Related Episodes


SE-Radio-Episode-309-Zane-Lackey-on-Application-Security
Answers 383 questions

SE Radio 642: Simon Wijckmans on Third-Party Browser Script Security
Answers 383 questions
SE Radio 589: Zac Hatfield-Dodds on Property-Based Testing in Python
Answers 383 questions

Episode 128: Web App Security with Bruce Sams
Answers 383 questions
Episode-467-Kim-Carter-on-Dynamic-Application-Security-Testing
Answers 383 questions

SE-Radio Episode 288: DevSecOps
Answers 383 questions

Episode 514: Vandana Verma on the Owasp Top 10
Answers 383 questions

SE Radio 648: Matthew Adams on AI Threat Modeling and Stride GPT
Answers 383 questions

SE-Radio Episode 330: Natalie Silvanovich on Attack Surface Reduction
Answers 383 questions

Episode 427: Sven Schleier and Jeroen Willemsen on Mobile Application Security
Answers 383 questions

SE Radio 581: Zach Lloyd on Terminal Emulators
Answers 383 questions

SE Radio 635: Stevie Caldwell on Zero-Trust Architecture
Answers 383 questions

SE Radio 572: Gregory Kapfhammer on Flaky Tests
Answers 383 questions
Episode 173: Feature-Oriented Software Development with Sven Apel – Pt 2
Answers 383 questions

SE Radio 637: Steve Smith on Software Quality
Answers 383 questions














