Best ZAP MCP Servers
Zap (OWASP ZAP) is an open-source web application security scanner that helps find vulnerabilities in web applications during development and testing.
Why this server?
Enables creation and validation of workflow diagrams using FlowZap's visual diagramming tool and FlowZap Code DSL, generating shareable playground URLs for workflow visualizations.
AlicenseAqualityDmaintenanceEnables AI assistants to create and validate workflow diagrams using FlowZap's text-based DSL. Generates shareable playground URLs for visualizing flowcharts, process diagrams, and CI/CD pipelines through natural language descriptions.Last updated71255MITWhy this server?
Offers full integration with OWASP ZAP proxy for processing requests, conducting spider scans, performing active security scanning, and managing vulnerability alerts.
AlicenseBqualityAmaintenanceAI-powered bug bounty hunting platform that integrates security tools (OWASP ZAP, Caido, Burp Suite) for automated reconnaissance, vulnerability testing, JavaScript analysis, and finding management with PostgreSQL storage.Last updated4735MITWhy this server?
Provides tools for dynamic application security testing (DAST) using OWASP ZAP to identify vulnerabilities in running web applications.
AlicenseBqualityDmaintenanceAn MCP server that integrates SAST, DAST, and SCA security tools to enable AI-driven vulnerability scanning and automated security reporting. It allows AI assistants to execute and analyze results from tools like Semgrep, OWASP ZAP, and Trivy within a DevSecOps workflow.Last updated6MITWhy this server?
Leverages OWASP ZAP for web application penetration testing including SQL injection, XSS, and CSRF vulnerability detection
FlicenseBqualityDmaintenanceEnables security auditing, penetration testing, and compliance validation with tools like Semgrep, Trivy, Gitleaks, and OWASP ZAP. Features strict project boundary enforcement and supports OWASP, CIS, and NIST compliance frameworks.Last updated7Why this server?
Integrates OWASP ZAP for dynamic application security testing (DAST) with support for multiple authentication modes and parallel scanning.
Why this server?
Integrates OWASP ZAP for dynamic application security testing (DAST) to perform automated security scans on web applications.
Alicense-qualityDmaintenanceIntegrates SAST, DAST, IAST, and SCA security testing tools for AI-powered DevSecOps automation, enabling comprehensive security scanning and reporting through natural language interfaces.Last updated16MITWhy this server?
Provides access to ZAP's RAG search modes (PLAIN, HYBRID, HYBRID_RERANK) for retrieving code context from a local SQLite index built by the ZAP IntelliJ plugin.
Alicense-qualityBmaintenanceRead-only MCP server that exposes ZAP's RAG search modes (plain, hybrid, hybrid_rerank) for agents to perform semantic code retrieval.Last updatedApache 2.0Why this server?
Integrates with OWASP ZAP to perform dynamic application security testing (DAST) against running web components to identify potential security exposures.
Alicense-qualityDmaintenanceAn automated security engineer that integrates with AI coding assistants to perform vulnerability scanning, static analysis, and AI-driven remediation. It also provides tools for recording and executing self-healing web tests using Playwright, including visual regression and test discovery.Last updated68Apache 2.0Why this server?
Integrates OWASP ZAP for automated web application security scanning and vulnerability detection.
Alicense-qualityDmaintenanceProfessional security testing server with 50+ integrated tools for web application vulnerability scanning, reconnaissance, fuzzing, and API testing. Enables comprehensive bug bounty hunting workflows including subdomain enumeration, XSS/SQLi detection, and automated security assessments.Last updatedMIT