2.16.1 D-2025-09-18 https://github.com/zaproxy/zaproxy/releases/download/w2025-09-18/ZAP_WEEKLY_D-2025-09-18.zip ZAP_WEEKLY_D-2025-09-18.zip SHA-256:3af53f47f78bd4a5ee98a02ab180d53ac2dc6a2f7d003844098dbaf100cb0198 287767494 https://github.com/zaproxy/zaproxy/releases/download/v2.16.1/ZAP_2_16_1_windows-x32.exe ZAP_2_16_1_windows-x32.exe SHA-256:8437978b03c88f83933e07319dccb3c958c9db97ef8abc571e56c30938797e1a 245210624 https://github.com/zaproxy/zaproxy/releases/download/v2.16.1/ZAP_2_16_1_windows.exe ZAP_2_16_1_windows.exe SHA-256:d9aca657be405d5ac3cc82af576ea71cd9b35894c81e4a8dd696d56a69ce861d 245386752 https://github.com/zaproxy/zaproxy/releases/download/v2.16.1/ZAP_2.16.1_Linux.tar.gz ZAP_2.16.1_Linux.tar.gz SHA-256:5b2eb8319b085121a6e8ad50d69d67dbef8c867166f71a937bfc888d247a2ac1 234364899 https://github.com/zaproxy/zaproxy/releases/download/v2.16.1/ZAP_2.16.1.dmg ZAP_2.16.1.dmg SHA-256:79d7bc6db7e9583d3d90549791843998f0cf170ed975cfa01fac657f2e0d9120 262910572 Bug fix and enhancement release. https://www.zaproxy.org/docs/desktop/releases/2.16.1/ accessControl Access Control Testing Adds a set of tools for testing access control in web applications. ZAP Dev Team 10 accessControl-alpha-10.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.14.0.</li> <li>Maintenance changes.</li> <li>Link website alert pages and help (Issues 8189).</li> <li>The results table now presents the same context menu as other similar tables (History, Search, etc) facilitating copying URLs, etc (Issue 8356).</li> <li>Now has a table export button (Issue 8356).</li> <li>Adjusted some labels/titles to use title caps (Issue 2000 &amp; 8356).</li> </ul> <h3>Fixed</h3> <ul> <li>Now uses the General Font (Issue 8356), as set in the Display options.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/accessControl-v10/accessControl-alpha-10.zap SHA-256:8e068a789650cd31a5a4592cf57af3dbcb04b98f6fcd20bf752889c3843cbce8 https://www.zaproxy.org/docs/desktop/addons/access-control-testing/ https://github.com/zaproxy/zap-extensions/ 2024-03-25 597028 2.14.0 commonlib >= 1.17.0 & < 2.0.0 alertFilters Alert Filters Allows you to automate the changing of alert risk levels. ZAP Dev Team 24 alertFilters-release-24.zap release <h3>Changed</h3> <ul> <li>Use the alert reference for statistics.</li> <li>Workaround core issue that prevents the filters to be correctly applied (Issue 8888).</li> </ul> <h3>Added</h3> <ul> <li>Added parameter descriptions for the ZAP API.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/alertFilters-v24/alertFilters-release-24.zap SHA-256:33ca1609f8b63501d0e55c1c3a12ed3c9fadb63e1877b7142fde28aaad6cc4ff https://www.zaproxy.org/docs/desktop/addons/alert-filters/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 569827 2.16.0 pscan >= 0.1.0 & < 1.0.0 allinonenotes All In One Notes A simple extension to view all notes in one pane. David Vassallo 2 allinonenotes-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Update link to repository.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/allinonenotes-v2/allinonenotes-alpha-2.zap SHA-256:9e70d6e76b72692e9c0cb64002a692b710710e688ea2d8834818086300632d2a https://www.zaproxy.org/docs/desktop/addons/all-in-one-notes/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 249532 2.11.0 ascanrules Active scanner rules The release status Active Scanner rules ZAP Dev Team 74 ascanrules-release-74.zap release <h3>Added</h3> <ul> <li>QA CICD policy tag to selected rules.</li> </ul> <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> <li>The SQL Injection - Oracle (Time Based) rule now uses DBMS_SESSION.SLEEP instead of an &quot;expensive&quot; query.</li> </ul> <h3>Fixed</h3> <ul> <li>Hidden Files rule raising false positives if server returning 200 for files that don't exist (Issue 8434).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrules-v74/ascanrules-release-74.zap SHA-256:edfa48e56a914d72454c2f522be13a11f3bd6ad6cd9bb493ed6cfa727ec426f6 https://www.zaproxy.org/docs/desktop/addons/active-scan-rules/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 3301891 2.16.0 commonlib >= 1.36.0 & < 2.0.0 network >= 0.3.0 oast >= 0.7.0 ascanrulesAlpha Active scanner rules (alpha) The alpha status Active Scanner rules ZAP Dev Team 51 ascanrulesAlpha-alpha-51.zap alpha <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesAlpha-v51/ascanrulesAlpha-alpha-51.zap SHA-256:557f20c26571f2dfcc65d738a8057259c85950b55bcca2b9fc5c30d930760e50 https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-alpha/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 408700 2.16.0 commonlib >= 1.34.0 & < 2.0.0 ascanrulesBeta Active scanner rules (beta) The beta status Active Scanner rules ZAP Dev Team 62 ascanrulesBeta-beta-62.zap beta <h3>Added</h3> <ul> <li>QA CICD policy tag to selected rules.</li> </ul> <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v62/ascanrulesBeta-beta-62.zap SHA-256:96355c23e8b68b3fd2b359085bf3b8d99de67a6ff3749fd353eda2b24e5a57cc https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-beta/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 1783460 2.16.0 commonlib >= 1.36.0 & < 2.0.0 database >= 0.1.0 network >= 0.3.0 oast >= 0.7.0 attacksurfacedetector Attack Surface Detector The Attack Surface Detector analyzes web application source code to generate endpoints that can be used for penetration testing. Secure Decisions (Matthew DeLetto) 1.1.4 attacksurfacedetector-alpha-1.1.4.zap alpha Various incremental changes (see https://github.com/secdec/attack-surface-detector-zap/releases)<br> Fix un-handled exception when target unavailable & address various "house keeping" tasks.<br> https://github.com/zaproxy/zap-extensions/releases/download/2.7/attacksurfacedetector-alpha-1.1.4.zap SHA1:e21758c2cdcbc7806f44cc986a88360457eff82e https://github.com/secdec/attack-surface-detector-zap/wiki https://github.com/secdec/attack-surface-detector-zap/ 2019-03-07 15604948 2.7.0 authhelper Authentication Helper Helps identify and set up authentication handling ZAP Dev Team 0.29.0 authhelper-beta-0.29.0.zap beta <h3>Added</h3> <ul> <li>Add login word variant for Spanish.</li> <li>Log exception during authentication with diagnostics enabled.</li> <li>Add the statistics of the site of the verification URL to the Authentication Report.</li> <li>Add Authentication Report section for the domains accessed during the authentication.</li> </ul> <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404 and resolve redirection.</li> <li>Search also for login elements with ARIA role button.</li> <li>Show always the diagnostic HTTP messages in the Sites tree and History tab when importing the Authentication Report.</li> <li>Include the site in the site statistics of the Authentication Report.</li> </ul> <h3>Fixed</h3> <ul> <li>Collect the current value of the element's attributes for the authentication diagnostics.</li> <li>In the Authentication Report set authentication successful only when the login was verified with the indicators.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.29.0/authhelper-beta-0.29.0.zap SHA-256:c08a233d8a1a453dfc724f08d806a295095608b4ae6e7145d481621bbcfb108c https://www.zaproxy.org/docs/desktop/addons/authentication-helper/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 1509357 2.16.0 commonlib >= 1.35.0 & < 2.0.0 database >=0.8.0 & < 1.0.0 network >=0.23.0 pscan >= 0.1.0 & < 1.0.0 selenium 15.* zest >=48.9.0 authstats Authentication Statistics Records logged in/out statistics for all contexts in scope. ZAP Dev Team 2 authstats-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Dynamically unload the add-on.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/authstats-v2/authstats-alpha-2.zap SHA-256:cfb604c27f3a7a58e7b5aa55fe9f19a9ce5561fab3ef7d3f6c72845671fb5dcf https://www.zaproxy.org/docs/desktop/addons/authentication-statistics/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 247499 2.11.0 automation Automation Framework Automation Framework. ZAP Dev Team 0.53.0 automation-beta-0.53.0.zap beta <h3>Fixed</h3> <ul> <li>Correct Session Management script's path validation with variables.</li> <li>Correct default value for Active Scan option <code>handleAntiCSRFTokens</code> in templates and help.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.53.0/automation-beta-0.53.0.zap SHA-256:bd35aaf68720cc8d1dd8716cb8302c8f5a368edeb45e08738e63dd6f2a159700 https://www.zaproxy.org/docs/desktop/addons/automation-framework/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 2104232 2.16.0 commonlib >= 1.31.0 & < 2.0.0 network >= 0.15.0 & < 1.0.0 beanshell BeanShell Console Provides a BeanShell Console ZAP Dev Team 7 beanshell-beta-7.zap beta <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> <li>Improve permissions and space handling when saving.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/beanshell-v7/beanshell-beta-7.zap SHA-256:0a83cb7d0369ccef50768ccbda1e6c6d82b9f4e3bd9372b38fd32cc21f6a30fb https://www.zaproxy.org/docs/desktop/addons/bean-shell/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 577838 2.11.0 browserView Browser View Adds an option to render HTML responses like a browser ZAP Dev Team 6 browserView-alpha-6.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> <li>Make missing JavaFX logging less verbose in regular use.</li> <li>Update help with the requirements to use the add-on.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/browserView-v6/browserView-alpha-6.zap SHA-256:e53cfde3a009a4be2e40c84ac02e05114505160bd2bab6cbb42416ab9a65b16c https://www.zaproxy.org/docs/desktop/addons/browser-view/ https://github.com/zaproxy/zap-extensions/ 2023-03-13 197667 2.12.0 bruteforce Forced Browse Forced browsing of files and directories using code from the OWASP DirBuster tool ZAP Dev Team 18 bruteforce-beta-18.zap beta <h3>Fixed</h3> <ul> <li>Error logs to always include stack trace.</li> <li>Address performance issue when checking responses.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/bruteforce-v18/bruteforce-beta-18.zap SHA-256:547d4f1c69b745313d5986fbe4ac9167072460c8b2e1262181da156405f08069 https://www.zaproxy.org/docs/desktop/addons/forced-browse/ https://github.com/zaproxy/zap-extensions/ 2025-08-27 552972 2.16.0 commonlib >= 1.23.0 & < 2.0.0 bugtracker Bug Tracker Bug Tracker extension. ZAP Dev Team 4 bugtracker-alpha-4.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.1.</li> <li>Dependency updates.</li> <li>Maintenance changes.</li> <li>Updated to use PAT not password (https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/bugtracker-v4/bugtracker-alpha-4.zap SHA-256:37c57f8e7f4a1608500527ac1831f8b078427f804ea04ad5790a2970e3e1b722 https://www.zaproxy.org/docs/desktop/addons/bug-tracker/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 3707425 2.11.1 callgraph Call Graph Allows the user to view a call graph of the selected resources Colm O'Flaherty 5 callgraph-alpha-5.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/callgraph-v5/callgraph-alpha-5.zap SHA-256:0874ce5aad0c4bbf28f72627a4940759d328396e12b7d6a5596f2e41bf24dc4e https://www.zaproxy.org/docs/desktop/addons/call-graph/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 925930 2.11.0 callhome Call Home Handles all of the calls to ZAP services. ZAP Dev Team 0.15.0 callhome-release-0.15.0.zap release <h3>Added</h3> <ul> <li>LLM, and Value Generator (Form Handler) stats to telemetry.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/callhome-v0.15.0/callhome-release-0.15.0.zap SHA-256:e564cf47bc4ac4c7d3af6fc9dd7d2832a0d64269cdb93fc06a3f89e6b4cc6821 https://www.zaproxy.org/docs/desktop/addons/call-home/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 322826 2.16.0 client Client Side Integration Exposes client (browser) side information in ZAP using Firefox and Chrome extensions. ZAP Dev Team 0.17.0 client-alpha-0.17.0.zap alpha <h3>Added</h3> <ul> <li>Edge recorder link to help.</li> <li>Support for stopping the spiderCient automation job.</li> <li>Support for configuring the client passive scan rules via the passiveScan-config Automation Framework job. This add-on now depends on the pscan add-on.</li> </ul> <h3>Changed</h3> <ul> <li>Updated Chrome and Firefox extensions to v0.1.6.</li> <li>Reduce warnings when passive scanning.</li> </ul> <h3>Fixed</h3> <ul> <li>Error logs to always include stack trace.</li> <li>Log Firefox missing at debug instead of error.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/client-v0.17.0/client-alpha-0.17.0.zap SHA-256:15ef35db74057dd2911eedf9ef755d88a6024653f1f802486b2fe6a7b072a4a2 https://www.zaproxy.org/docs/desktop/addons/client-side-integration/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 2726602 2.16.0 commonlib >=1.23.0 network >=0.8.0 pscan >=0.4.0 selenium >=15.14.0 commonlib Common Library A common library, for use by other add-ons. ZAP Dev Team 1.36.0 commonlib-release-1.36.0.zap release <h3>Added</h3> <ul> <li>QA CICD policy tag.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.36.0/commonlib-release-1.36.0.zap SHA-256:d52b7d025b88c7e7140ddaa1e34542c53a292476a985075ca1c5df26ab2df408 https://www.zaproxy.org/docs/desktop/addons/common-library/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 11276273 2.16.0 communityScripts Community Scripts Useful ZAP scripts written by the ZAP community. ZAP Community 19 communityScripts-alpha-19.zap alpha <h3>Added</h3> <ul> <li>extender/arpSyndicateSubdomainDiscovery.js - uses the API of <a href="https://www.subdomain.center/">ARPSyndicate's Subdomain Center</a> to find and add subdomains to the Sites Tree.</li> <li>passive/JavaDisclosure.js - Passive scan for Java error messages leaks</li> <li>httpsender/RsaEncryptPayloadForZap.py - A script that encrypts requests using RSA</li> <li>selenium/FillOTPInMFA.js - A script that fills the OTP in MFA</li> <li>authentication/KratosApiAuthentication.js - A script to authenticate with Kratos using the API flow</li> <li>authentication/KratosBrowserAuthentication.js - A script to authenticate with Kratos using the browser flow</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.15.0.</li> <li>Use Prettier to format all JavaScript scripts.</li> <li>Update the following scripts to implement the <code>getMetadata()</code> function with revised metadata: <ul> <li>active/Cross Site WebSocket Hijacking.js</li> <li>active/cve-2019-5418.js</li> <li>active/gof_lite.js</li> <li>active/JWT None Exploit.js</li> <li>active/SSTI.js</li> <li>passive/clacks.js</li> <li>passive/CookieHTTPOnly.js</li> <li>passive/detect_csp_notif_and_reportonly.js</li> <li>passive/detect_samesite_protection.js</li> <li>passive/f5_bigip_cookie_internal_ip.js</li> <li>passive/find base64 strings.js</li> <li>passive/Find Credit Cards.js</li> <li>passive/Find Emails.js</li> <li>passive/Find Hashes.js</li> <li>passive/Find HTML Comments.js</li> <li>passive/Find IBANs.js</li> <li>passive/Find Internal IPs.js</li> <li>passive/find_reflected_params.py</li> <li>passive/HUNT.py</li> <li>passive/Mutliple Security Header Check.js</li> <li>passive/google_api_keys_finder.js</li> <li>passive/JavaDisclosure.js</li> <li>passive/Report non static sites.js</li> <li>passive/RPO.js</li> <li>passive/s3.js</li> <li>passive/Server Header Disclosure.js</li> <li>passive/SQL injection detection.js</li> <li>passive/Telerik Using Poor Crypto.js</li> <li>passive/Upload form discovery.js</li> <li>passive/X-Powered-By_header_checker.js</li> </ul> </li> <li>httpsender/Alert on Unexpected Content Types.js now checks for common content-types (<code>json</code>, <code>xml</code>, and <code>yaml</code>) more consistently.</li> <li>targeted/request_to_xml.js no longer uses deprecated method to show the message in the editor dialogue.</li> </ul> https://github.com/zaproxy/community-scripts/releases/download/v19/communityScripts-alpha-19.zap SHA-256:f96502b471dd349ae2fceba4a68bde9465091580040ad8798e13bb176030bbba https://www.zaproxy.org/docs/desktop/addons/community-scripts/ https://github.com/zaproxy/community-scripts/ 2024-07-01 475346 2.15.0 coreLang Core Language Files Translations of the core language files ZAP Dev Team 15 coreLang-release-15.zap release <h3>Changed</h3> <ul> <li>Update the languages files from Crowdin.</li> <li>Update minimum ZAP version to 2.11.1.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/coreLang-v15/coreLang-release-15.zap SHA-256:d8258b914ffc95820dd045acf56677668a8cbbfc759290f72e30210056dfb88c https://crowdin.com/project/zaproxy https://github.com/zaproxy/zap-extensions/ 2022-02-14 4616009 2.11.1 custompayloads Custom Payloads Ability to add, edit or remove payloads that are used i.e. by active scanners ZAP Dev Team 0.15.0 custompayloads-release-0.15.0.zap release <h3>Added</h3> <ul> <li>Added support for adding payloads which are disabled by default.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.15.0/custompayloads-release-0.15.0.zap SHA-256:57f8dd2b1140626005c8ffc8768259e0964a31e716c75569a6cca53e4bcee4e6 https://www.zaproxy.org/docs/desktop/addons/custom-payloads/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 333565 2.16.0 commonlib >= 1.17.0 & < 2.0.0 database Database Provides database engines and related infrastructure. ZAP Dev Team 0.8.0 database-alpha-0.8.0.zap alpha <h3>Changed</h3> <ul> <li>Allow other add-ons to use Flyway for database migration tasks.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/database-v0.8.0/database-alpha-0.8.0.zap SHA-256:c8e89451c763b1b399d9f801c8f230979d4569f849ff670d004dc2007399ba19 https://www.zaproxy.org/docs/desktop/addons/database/ https://github.com/zaproxy/zap-extensions/ 2025-03-04 23094734 2.16.0 dev Dev Add-on An add-on to help with development of ZAP. ZAP Dev Team 0.10.0 dev-alpha-0.10.0.zap alpha <h3>Added</h3> <ul> <li>Basic CSRF test app.</li> <li>Page with input elements that appear after a delay and off the displayed screen.</li> <li>Auth app which uses multiple (faked) domains.</li> <li>An auth example where there's a div that may obscure the login fields.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/dev-v0.10.0/dev-alpha-0.10.0.zap SHA-256:f749b0ec8d593fc16ec5798ce1e3668ceeb7d965dcaf029ae039acf5ebabe09a https://www.zaproxy.org/docs/desktop/addons/dev-add-on/ https://github.com/zaproxy/zap-extensions/ 2025-05-15 182901 2.16.0 commonlib >=1.17.0 network >=0.7.0 diff Diff Displays a dialog showing the differences between 2 requests or responses. It uses diffutils and diff_match_patch ZAP Dev Team 17 diff-beta-17.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/diff-v17/diff-beta-17.zap SHA-256:6629fdcd55e509dfaf1e1004204b3dca5a75bfb1593c11bd8281bd7c7fd367b9 https://www.zaproxy.org/docs/desktop/addons/diff/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 693148 2.16.0 commonlib >=1.23.0 directorylistv1 Directory List v1.0 List of directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 9 directorylistv1-release-9.zap release <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv1-v9/directorylistv1-release-9.zap SHA-256:71e5b57bcf89774267375426f2e67f789cf13a4b69c97c8946a325fa321d18ce https://www.zaproxy.org/docs/desktop/addons/directory-list-v1.0/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 961164 2.16.0 directorylistv2_3 Directory List v2.3 Lists of directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 4 directorylistv2_3-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3-v4/directorylistv2_3-release-4.zap SHA-256:3a8b04b9363b57acd9cf8cd67abce4c630f986e2b492a1ebd01eaa9587a0a199 https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 8722229 2.11.0 directorylistv2_3_lc Directory List v2.3 LC Lists of lower case directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 4 directorylistv2_3_lc-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3_lc-v4/directorylistv2_3_lc-release-4.zap SHA-256:2603580ba53673c31800ef7373e7cc09de759369b6f8fb43cc9e5024ad5d9af4 https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3-lc/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 7569974 2.11.0 domxss DOM XSS Active scanner rule DOM XSS Active scanner rule Aabha Biyani, ZAP Dev Team 22 domxss-release-22.zap release <h3>Changed</h3> <ul> <li>Allow to use Edge.</li> <li>Depend on newer version of Selenium add-on.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/domxss-v22/domxss-release-22.zap SHA-256:8acb646338b259eb31f3ca9b4ffd54a94e89b6a58fa7726d45c37c5cced42e17 https://www.zaproxy.org/docs/desktop/addons/dom-xss-active-scan-rule/ https://github.com/zaproxy/zap-extensions/ 2025-07-10 285349 2.16.0 commonlib >= 1.29.0 & < 2.0.0 network >=0.1.0 selenium >= 15.39.0 encoder Encoder Adds encode/decode/hash dialog and support for scripted processors as well ZAP Dev Team 1.7.0 encoder-release-1.7.0.zap release <h3>Fixed</h3> <ul> <li>Address malformed HTML in the help.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/encoder-v1.7.0/encoder-release-1.7.0.zap SHA-256:8ef98c344fc5ebd3362d9a4fc4bda9ebaffb0d35136a40499a2fda21cadb5715 https://www.zaproxy.org/docs/desktop/addons/encode-decode-hash/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 504247 2.16.0 commonlib >=1.23.0 evalvillain Eval Villain Adds the Eval Villain extension to Firefox when launched from ZAP. Dennis Goodlett and the ZAP Dev Team 0.4.0 evalvillain-alpha-0.4.0.zap alpha <h3>Changed</h3> <ul> <li>Updated with new version of Eval Villain.</li> <li>Update minimum ZAP version to 2.15.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/evalvillain-v0.4.0/evalvillain-alpha-0.4.0.zap SHA-256:dedb6245cee2383b13eb4c0c58301ee2518c6e0af36359559f2e1638a8a076e3 https://www.zaproxy.org/docs/desktop/addons/eval-villain/ https://github.com/zaproxy/zap-extensions/ 2024-11-25 4957040 2.15.0 selenium >=15.5.0 exim Import/Export Import and Export functionality ZAP Dev Team & thatsn0tmysite 0.15.0 exim-beta-0.15.0.zap beta <h3>Changed</h3> <ul> <li>Update dependency.</li> <li>Use always the same newlines (LF) when exporting HAR files.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/exim-v0.15.0/exim-beta-0.15.0.zap SHA-256:0ddc3a5fd14b55359c9430b0fdaffbac19b78d717c242b2e645c6e50695ebb36 https://www.zaproxy.org/docs/desktop/addons/import-export/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 1109146 2.16.0 commonlib >= 1.28.0 & < 2.0.0 fileupload FileUpload Detect File upload requests and scan them to find related vulnerabilities KSASAN preetkaran20@gmail.com 1.2.1 fileupload-alpha-1.2.1.zap alpha https://github.com/zaproxy/zap-extensions/releases/download/2.7/fileupload-alpha-1.2.1.zap SHA-256:84734320ed04f6e287cc0458897e99e80fe16d632d071e73187e446448b5fa7f https://www.zaproxy.org/blog/2021-08-20-zap-fileupload-addon/ https://github.com/SasanLabs/owasp-zap-fileupload-addon/ 2023-10-23 78272 2.11.0 formhandler Value Generator This Value Generator Add-on allows a user to define field names and values to be used when submitting values to an app. Fields can be added, modified, enabled/disabled, and deleted. ZAP Dev Team 6.7.0 formhandler-beta-6.7.0.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> <li>Depend on Common Library add-on, to provide the default/custom values to the other add-ons (Issue 8016).</li> </ul> <h3>Fixed</h3> <ul> <li>Fixed an issue in the help which may cause images to be displayed inline impacting the flow of the text.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/formhandler-v6.7.0/formhandler-beta-6.7.0.zap SHA-256:2adb0a7f60f7c43861cdeac14d0d72cde139abcaf12fdd6cb82cf4739e52bd81 https://www.zaproxy.org/docs/desktop/addons/value-generator/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 2128203 2.16.0 commonlib >= 1.29.0 & < 2.0.0 fuzz Fuzzer Advanced fuzzer for manual testing ZAP Dev Team 13.16.0 fuzz-beta-13.16.0.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Use a scrollbar in the Default Category combo box instead of making the options panel larger (Issue 8923).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/fuzz-v13.16.0/fuzz-beta-13.16.0.zap SHA-256:c39125db01a774b19b5f224d504a301a0f25a213e87a3ce58d90306a79a70701 https://www.zaproxy.org/docs/desktop/addons/fuzzer/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 2014901 2.16.0 commonlib >= 1.23.0 & < 2.0.0 fuzzai FuzzAI Files FuzzAI files which can be used with the ZAP fuzzer ZAP Dev Team 0.0.1 fuzzai-release-0.0.1.zap release <h3>Added</h3> <ul> <li>First version</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/fuzzai-v0.0.1/fuzzai-release-0.0.1.zap SHA-256:7d60565b5814b8523514c5d8001d0bdf1f30f6d96cae9b4ac0abb45ee7abcaea https://www.zaproxy.org/docs/desktop/addons/fuzzai-files/ https://github.com/zaproxy/zap-extensions/ 2024-09-24 50063 2.15.0 fuzzdb FuzzDB Files FuzzDB files which can be used with the ZAP fuzzer ZAP Dev Team 9 fuzzdb-release-9.zap release <h3>Changed</h3> <ul> <li>Updated RAFT lists based on more recent SecLists contributions</li> <li>Update minimum ZAP version to 2.11.1.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/fuzzdb-v9/fuzzdb-release-9.zap SHA-256:c79537362cd6b383f447359685e3bd51795600b97ca0c1fadc4ba74828a7d4f4 https://www.zaproxy.org/docs/desktop/addons/fuzzdb-files/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 6167205 2.11.1 fuzzdboffensive FuzzDB Offensive FuzzDB web backdoors and attack files which can be used with the ZAP fuzzer or for manual penetration testing - contains files that may well be flagged by anti-virus tools ZAP Dev Team 5 fuzzdboffensive-release-5.zap release <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.14.0.</li> <li>Updated help and description to say this may cause problems with anti-virus tools (Issue 8297).</li> </ul> https://github.com/zaproxy/fuzzdb-offensive/releases/download/v5/fuzzdboffensive-release-5.zap SHA-256:9d7bf6f8df62e5ee56e72b47785e6027674127ae70604d9c4f6dc0cea1f536dc https://www.zaproxy.org/docs/desktop/addons/fuzzdb-offensive/ https://github.com/zaproxy/fuzzdb-offensive/ 2024-01-11 523693 2.14.0 gettingStarted Getting Started with ZAP Guide A short Getting Started with ZAP Guide ZAP Dev Team 19 gettingStarted-release-19.zap release <h3>Changed</h3> <ul> <li>Update Getting Started Guide for 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/gettingStarted-v19/gettingStarted-release-19.zap SHA-256:74ca76fbe518917005828d3b4f4392d8d91b5e11d1d6517a1ae9fc19f16bfd9b https://www.zaproxy.org/docs/desktop/addons/getting-started-guide/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 968572 2.16.0 graaljs GraalVM JavaScript Provides the GraalVM JavaScript engine for ZAP scripting. ZAP Dev Team 0.9.0 graaljs-alpha-0.9.0.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/graaljs-v0.9.0/graaljs-alpha-0.9.0.zap SHA-256:8abec96df1ff90177953d5fffd4dfd57228c1a8d8e140a521e81ea80a256ca19 https://www.zaproxy.org/docs/desktop/addons/graalvm-javascript/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 24540532 2.16.0 commonlib >=1.24.0 scripts >=45.2.0 graphql GraphQL Support Inspect and attack GraphQL endpoints. ZAP Dev Team 0.28.0 graphql-alpha-0.28.0.zap alpha <h3>Fixed</h3> <ul> <li>A Null Pointer Exception which occurred when installing the add-on when Tech Detection (Wappalyzer) add-on was already installed (Issue 8902).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/graphql-v0.28.0/graphql-alpha-0.28.0.zap SHA-256:f71725838a911988ce76cc2f188fa27b6e899e1fae900f5e75996a9ccf605db9 https://www.zaproxy.org/docs/desktop/addons/graphql-support/ https://github.com/zaproxy/zap-extensions/ 2025-03-26 5524748 2.16.0 commonlib >= 1.29.0 & < 2.0.0 groovy Groovy Support Adds Groovy support to ZAP ZAP Dev Team 3.2.0 groovy-beta-3.2.0.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.14.0.</li> <li>Maintenance changes.</li> <li>Replace usage of singletons with injected variables (e.g. <code>model</code>, <code>control</code>) in scripts.</li> <li>Dependency updates.</li> <li>Update Active and Passive Script Templates to include a <code>getMetadata</code> function. This will allow them to be used as regular scan rules.</li> <li>Depend on the <code>commonlib</code> and <code>scripts</code> add-ons for scan rule scripts.</li> </ul> <h3>Fixed</h3> <ul> <li>Updated encode-decode script template to conform to the latest method signatures.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/groovy-v3.2.0/groovy-beta-3.2.0.zap SHA-256:2603bcff3728308c6dab09135def96a1209ce8219b0d1f9d861c59b5a8fc522e https://www.zaproxy.org/docs/desktop/addons/groovy-support/ https://github.com/zaproxy/zap-extensions/ 2024-04-11 20168743 2.14.0 commonlib >=1.24.0 scripts >=45.2.0 grpc gRPC Support Inspect, attack gRPC endpoints, and decode protobuf messages. ZAP Dev Team 0.2.0 grpc-alpha-0.2.0.zap alpha <h3>Added</h3> <ul> <li>gRPC WebSocket Support Added</li> </ul> <h3>Fixed</h3> <ul> <li>Do not try to decode non-gRPC responses when active scanning, which would lead to unnecessary warnings.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/grpc-v0.2.0/grpc-alpha-0.2.0.zap SHA-256:028464ebc6c80f36fd32088c7aede870f68940dcbb2064a0ed6bfe2bb93f37e1 https://www.zaproxy.org/docs/desktop/addons/grpc-support/ https://github.com/zaproxy/zap-extensions/ 2024-07-02 8202269 2.15.0 help Help - English English version of the ZAP help file. ZAP Crowdin Team 21 help-release-21.zap release <h3>Changed</h3> <ul> <li>Update available JavaScript engine and links.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help-v21/help-release-21.zap SHA-256:6a86b3f60a5d3d46988674840b04b996d79160fd39772604557bc64b23a3e66b https://www.zaproxy.org/docs/desktop/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 640142 2.16.0 help_ar_SA Help - Arabic Arabic version of the ZAP help file. ZAP Crowdin Team 2 help_ar_SA-alpha-2.zap alpha <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ar_SA-v2/help_ar_SA-alpha-2.zap SHA-256:938663e7a1ff6a36bb7336bc80eec07366af3ff36acf817b472c2e959f8eb0fe https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 700495 2.16.0 help_bs_BA Help - Bosnian Bosnian version of the ZAP help file. ZAP Crowdin Team 10 help_bs_BA-alpha-10.zap alpha <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_bs_BA-v10/help_bs_BA-alpha-10.zap SHA-256:f61b6df64dfaf669942899843f8f8eedd6d02fa4f980883276bfaca22ffefadd https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 688882 2.16.0 help_es_ES Help - Spanish Spanish version of the ZAP help file. ZAP Crowdin Team 11 help_es_ES-release-11.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_es_ES-v11/help_es_ES-release-11.zap SHA-256:d85348dd51a2110ef9be994d2df39af675666f13682114d5161895ecbbaff7d5 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 750150 2.16.0 help_fil_PH Help - Filipino Filipino version of the ZAP help file. ZAP Crowdin Team 4 help_fil_PH-release-4.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_fil_PH-v4/help_fil_PH-release-4.zap SHA-256:e19ef5a3645e528a44c4508e682b1d1d2b9bda104518e2c765a0586797f384d0 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 756582 2.16.0 help_fr_FR Help - French French version of the ZAP help file. ZAP Crowdin Team 11 help_fr_FR-alpha-11.zap alpha <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_fr_FR-v11/help_fr_FR-alpha-11.zap SHA-256:49b144d2fb7a31d55b69df0834f82efb24c1ac541da1fe271aa7c896c4b02c63 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 695730 2.16.0 help_id_ID Help - Indonesian Indonesian version of the ZAP help file. ZAP Crowdin Team 4 help_id_ID-release-4.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_id_ID-v4/help_id_ID-release-4.zap SHA-256:636f1bf1a6c8c344243a99dc45010060da1a343ee67312901a9a76e2c9dea129 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 721864 2.16.0 help_ja_JP Help - Japanese Japanese version of the ZAP help file. ZAP Crowdin Team 11 help_ja_JP-beta-11.zap beta <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ja_JP-v11/help_ja_JP-beta-11.zap SHA-256:16bbeabe913f66105c1a7de32aa670e20a76d3bec6d20d28c6175043c068c7bd https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 712619 2.16.0 help_ms_MY Help - Malay Malay version of the ZAP help file. ZAP Crowdin Team 2 help_ms_MY-alpha-2.zap alpha <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ms_MY-v2/help_ms_MY-alpha-2.zap SHA-256:f640cb80be1859aef002e6717e9549f1d08e89f8614a9c53db049b06baa74164 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 687911 2.16.0 help_pt_BR Help - Portuguese, Brazilian Portuguese, Brazilian version of the ZAP help file. ZAP Crowdin Team 12 help_pt_BR-release-12.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_pt_BR-v12/help_pt_BR-release-12.zap SHA-256:98e5d9911bb25718a373ecd9c37388224e8b59ecb203c2ec3d91b84eaf8c1e5c https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 732259 2.16.0 help_ru_RU Help - Russian Russian version of the ZAP help file. ZAP Crowdin Team 3 help_ru_RU-release-3.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ru_RU-v3/help_ru_RU-release-3.zap SHA-256:ec0e82c2e805b028f1fd38963b88aa82126c3f1fc95d5c0562e0e0bc026f4207 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 829148 2.16.0 help_tr_TR Help - Turkish Turkish version of the ZAP help file. ZAP Crowdin Team 3 help_tr_TR-release-3.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_tr_TR-v3/help_tr_TR-release-3.zap SHA-256:7623354df0309798953860fbf4650d7a771d5beb8355a287da58b5c51371080f https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 759564 2.16.0 help_zh_CN Help - Chinese Simplified Chinese Simplified version of the ZAP help file. ZAP Crowdin Team 4 help_zh_CN-release-4.zap release <h3>Changed</h3> <ul> <li>Updated for 2.16.1.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_zh_CN-v4/help_zh_CN-release-4.zap SHA-256:18937e5678c949ff15f55e213cf9b0da8da03ed61774308d2fc5257fecad77b2 https://www.zaproxy.org/docs/contribute/translate/ https://github.com/zaproxy/zap-core-help/ 2025-08-21 708657 2.16.0 highlighter Highlighter Allows you to highlight strings in the request and response tabs. ZAP Dev Team 8 highlighter-alpha-8.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/highlighter-v8/highlighter-alpha-8.zap SHA-256:4c4852bb2f42eb20dbe19a091e9025667947c73967a65770658333bedd01fccf https://www.zaproxy.org/docs/desktop/addons/highlighter/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 115527 2.11.0 hud HUD - Heads Up Display Display information from ZAP in browser. ZAP Dev Team 0.19.0 hud-beta-0.19.0.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.15.0.</li> <li>Disable the HUD by default - it still works but its flaky, and currently not a focus for us.</li> </ul> https://github.com/zaproxy/zap-hud/releases/download/v0.19.0/hud-beta-0.19.0.zap SHA-256:737239ce1b765ff32f9351a647594f22d725d319b94f7a2ef2cb153aadf832df https://www.zaproxy.org/docs/desktop/addons/hud/ https://github.com/zaproxy/zap-hud/ 2024-05-07 1382692 2.15.0 network >= 0.1.0 websocket imagelocationscanner Image Location and Privacy Scanner Image Location and Privacy Passive Scanner Jay Ball (@veggiespam) and the ZAP Dev Team 7 imagelocationscanner-beta-7.zap beta <h3>Changed</h3> <ul> <li>Update alert reference and help link to latest location.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/imagelocationscanner-v7/imagelocationscanner-beta-7.zap SHA-256:97bc21190702e26f5c4546450a41a94f020459a1d32a5818f9456ed2d2bd797f https://www.zaproxy.org/docs/desktop/addons/image-location-and-privacy-scanner/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 1437825 2.16.0 commonlib >= 1.32.0 & < 2.0.0 invoke Invoke Applications Invoke external applications passing context related information such as URLs and parameters ZAP Dev Team 16 invoke-beta-16.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/invoke-v16/invoke-beta-16.zap SHA-256:439fd2ff1d090779bc9f874696286d1685dffa7b83624254c2b92a2daa943464 https://www.zaproxy.org/docs/desktop/addons/invoke-applications/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 323503 2.16.0 commonlib >=1.23.0 jruby Ruby Scripting Allows Ruby to be used for ZAP scripting - templates included ZAP Dev Team 8 jruby-beta-8.zap beta <h3>Changed</h3> <ul> <li>Update links to zaproxy repo.</li> <li>Rename reliability to confidence in active/passive templates.</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jruby-v8/jruby-beta-8.zap SHA-256:f5bb450a165f6c407b8d24f7b2776bdc7a2edb0b4b42aea385f8a6ad1ae605ca https://www.zaproxy.org/docs/desktop/addons/ruby-scripting/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 21968128 2.11.0 jsonview JSON View Adds a view that shows JSON messages nicely formatted Juha Kivekäs 3 jsonview-alpha-3.zap alpha <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.13.0.</li> <li>Depend on Common Library add-on to reuse libraries (Issue 7961).</li> </ul> <h3>Fixed</h3> <ul> <li>Use other library to format the JSON bodies (Issue 7798).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jsonview-v3/jsonview-alpha-3.zap SHA-256:ddafbbced033cc937ef37182e3650119dee3c7e5f1ac4ded73ea42125467184d https://www.zaproxy.org/docs/desktop/addons/json-view/ https://github.com/zaproxy/zap-extensions/ 2023-09-07 120558 2.13.0 commonlib >= 1.16.0 & < 2.0.0 jwt JWT Support Detect JWT requests and scan them to find related vulnerabilities KSASAN preetkaran20@gmail.com 1.0.3 jwt-alpha-1.0.3.zap alpha <ul> <li>First version of JWT Support. <ul> <li>Contains scanning rules for basic JWT related vulnerabilities.</li> <li>Contains JWT Fuzzer for fuzzing the JWT's present in the request.</li> </ul> </li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/2.7/jwt-alpha-1.0.3.zap SHA-256:d3df8480010ad2df230cbdb99619aafdb869861349455c3da0129a99b132d204 https://github.com/SasanLabs/owasp-zap-jwt-addon/ 2023-01-02 751748 2.11.1 commonlib fuzz 13.* jython Python Scripting Allows Python to be used for ZAP scripting - templates included ZAP Dev Team 15 jython-beta-15.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update Active and Passive Script Templates to include a <code>getMetadata</code> function. This will allow them to be used as regular scan rules.</li> <li>Depend on the <code>commonlib</code> add-on for scan rule scripts.</li> <li>Update minimum <code>scripts</code> add-on version to 45.1.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jython-v15/jython-beta-15.zap SHA-256:019a64ba85cc9021a841e7253ae14f619129b603ab2048bec9593f5d59c1da02 https://www.zaproxy.org/docs/desktop/addons/python-scripting/ https://github.com/zaproxy/zap-extensions/ 2024-04-11 43315501 2.14.0 commonlib >=1.24.0 scripts >=45.2.0 kotlin Kotlin Support Allows Kotlin to be used for ZAP scripting StackHawk Engineering 1.1.0 kotlin-alpha-1.1.0.zap alpha <h3>Changed</h3> <ul> <li>Use appropriate syntax style for highlighting of code.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/kotlin-v1.1.0/kotlin-alpha-1.1.0.zap SHA-256:85a47ea7199b77cfb09081302c277de2ba5e2102ef79907573ebcfa6425302e9 https://www.zaproxy.org/docs/desktop/addons/kotlin-support/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 48865539 2.11.0 levoai Levo.ai Build OpenAPI Specs with ZAP traffic using Levo.ai. Levo.ai 0.3.0 levoai-zap-addon-alpha-0.3.0.zap alpha <h3>Added</h3> <ul> <li>Option to configure an organization ID that is added as a header in the requests made to the Satellite.</li> <li>Option to specify the environment under which the discovered apps will be shown in the Levo dashboard.</li> <li>Set the sensor type in the requests made to the Satellite.</li> </ul> https://github.com/levoai/levoai-zap-addon/releases/download/v0.3.0/levoai-zap-addon-alpha-0.3.0.zap SHA-256:1a86d7c288bf4284e83f54203f4ed8dd7d40b2bd47fbb8f8f853da67676269d2 https://levo.ai https://github.com/levoai/levoai-zap-addon 2024-07-10 2465951 2.12.0 maplocal Map Local Allows mapping of responses to content of a chosen local file. Keindel (Andrey Maksimov) 0.0.1 maplocal-alpha-0.0.1.zap alpha <ul> <li>First version of Map Local extension. Provides feature to map Response Body to a content of chosen local file. <ul> <li>Has status panel in UI with 3 columns: Enabled / URL / Local Path.</li> <li>Has add / edit dialog with browse button to choose file.</li> <li>Has file choice verification check.</li> <li>Popup menus in sites and history, edit / remove - popups in status panel.</li> <li>Persists to session DB.</li> </ul> </li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/2.7/maplocal-alpha-0.0.1.zap SHA-256:d3ecd2a6e23b06ffed8646ee2314d921a1c1925c3ab08070a624a090734ebdca https://github.com/Keindel/owasp-zap-maplocal-addon 2023-10-05 49040 2.12.0 neonmarker Neonmarker Colors history table items based on tags Juha Kivekäs, Kingthorin 1.8.0 neonmarker-alpha-1.8.0.zap alpha <h3>Changed</h3> <ul> <li>Adjust initialization of the Tags list</li> </ul> https://github.com/kingthorin/neonmarker/releases/download/v1.8.0/neonmarker-alpha-1.8.0.zap SHA-256:b4a52ab49d887fa1772b4b371d9ec9e48f2bb5dd0add25f21130b9e58e053e0b https://www.zaproxy.org/docs/desktop/addons/neonmarker/ https://github.com/kingthorin/neonmarker 2025-02-14 35958 2.16.0 pscan >=0.2.0 network Network Provides core networking capabilities. ZAP Dev Team 0.23.0 network-beta-0.23.0.zap beta <h3>Added</h3> <ul> <li>NetworkUtils class.</li> </ul> <h3>Changed</h3> <ul> <li>Use only positive serial numbers for the Root CA certificate (Issue 8984).</li> </ul> <h3>Fixed</h3> <ul> <li>Correctly inform about unknown proxy host on all OSes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/network-v0.23.0/network-beta-0.23.0.zap SHA-256:91ee5f75d6462049f063f22a41961f7ec349040139a3029034eddb14a6c73f5e https://www.zaproxy.org/docs/desktop/addons/network/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 28133037 2.16.0 oast OAST Support Allows you to exploit out-of-band vulnerabilities ZAP Dev Team 0.22.0 oast-beta-0.22.0.zap beta <h3>Changed</h3> <ul> <li>Link to repositories/documentation instead of service URLs in the help content.</li> <li>No longer provide a default server URL for Interactsh due to (random) unavailability.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/oast-v0.22.0/oast-beta-0.22.0.zap SHA-256:7ddbcda77b9f58a0b7b3f4db4bf3aaa7b7bf87c4ee578d343e748a5b8c077a0e https://www.zaproxy.org/docs/desktop/addons/oast-support/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 904262 2.16.0 database >= 0.6.0 network >= 0.1.0 onlineMenu Online menus ZAP Online menu items ZAP Dev Team 14 onlineMenu-release-14.zap release <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/onlineMenu-v14/onlineMenu-release-14.zap SHA-256:da47b95478c008545f403ffc20640c12c6215211e93727118f0854a2e40c5794 https://www.zaproxy.org/docs/desktop/addons/online-menu/ https://github.com/zaproxy/zap-extensions/ 2025-01-09 208647 2.16.0 openapi OpenAPI Support Imports and spiders OpenAPI definitions. ZAP Dev Team plus Joanna Bona, Nathalie Bouchahine, Artur Grzesica, Mohammad Kamar, Markus Kiss, Michal Materniak, Marcin Spiewak, and SDA SE Open Industry Solutions 46 openapi-beta-46.zap beta <h3>Fixed</h3> <ul> <li>Warn logs to always include stack trace.</li> <li>Correct generation of empty object.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/openapi-v46/openapi-beta-46.zap SHA-256:df24124ef26da2cafb027b4d3c81ec74668541b48b48e6139b3201070b9681fe https://www.zaproxy.org/docs/desktop/addons/openapi-support/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 11575438 2.16.0 commonlib >= 1.29.0 & < 2.0.0 packpentester Collection: Pentester Pack A collection of add-ons ideal for pentesters ZAP Dev Team 0.1.0 packpentester-alpha-0.1.0.zap alpha <h3>Fixed</h3> <ul> <li>Corrected fuzz add-on name</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/packpentester-v0.1.0/packpentester-alpha-0.1.0.zap SHA-256:0b8e7e4ddffdcacf46fdf9793bf84217738e281cbd5ccac732788c4b768d069c https://www.zaproxy.org/docs/desktop/addons/collection-pentester-pack/ https://github.com/zaproxy/zap-extensions/ 2022-05-12 6792 2.11.1 accessControl attacksurfacedetector custompayloads evalvillain fileupload fuzz fuzzdb jsonview jwt requester viewstate wappalyzer packscanrules Collection: Scan Rules Pack All of the add-ons just containing release, beta and alpha status scan rules ZAP Dev Team 0.0.1 packscanrules-alpha-0.0.1.zap alpha <p>First version.</p> https://github.com/zaproxy/zap-extensions/releases/download/packscanrules-v0.0.1/packscanrules-alpha-0.0.1.zap SHA-256:5ad68f153379bd96f36a7bead61e884cc42e1409cdd262dffc682b5f7bf92da4 https://www.zaproxy.org/docs/desktop/addons/collection-scan-rules-pack/ https://github.com/zaproxy/zap-extensions/ 2022-05-13 9244 2.11.1 ascanrules ascanrulesAlpha ascanrulesBeta domxss pscanrules pscanrulesAlpha pscanrulesBeta retire paramdigger Parameter Digger Identify hidden, unlinked parameters. Useful for finding web cache poisoning vulnerabilities. ZAP Dev Team and Arkaprabha Chakraborty 0.3.0 paramdigger-alpha-0.3.0.zap alpha <h3>Added</h3> <ul> <li>Support for menu weights (Issue 8369)</li> </ul> <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.15.0.</li> <li>The output panel is now properly reset on ZAP session change (part of Issue 7694).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/paramdigger-v0.3.0/paramdigger-alpha-0.3.0.zap SHA-256:585e4853c7cbc3c925ea4d5e1cfbcd6d8a3d4a20b00bdd49f582743cc6a9e281 https://www.zaproxy.org/docs/desktop/addons/parameter-digger/ https://github.com/zaproxy/zap-extensions/ 2024-07-15 561541 2.15.0 commonlib >= 1.23.0 & < 2.0.0 plugnhack Plug-n-Hack Configuration Supports the Mozilla Plug-n-Hack standard: https://developer.mozilla.org/en-US/docs/Plug-n-Hack. ZAP Dev Team 13 plugnhack-beta-13.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> <li>Use Network add-on to obtain main proxy address/port.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/plugnhack-v13/plugnhack-beta-13.zap SHA-256:8d74b572bb7e08d09ebcfd10da9f2f65f7970f9452feadb8bbe69c8037b80ee2 https://www.zaproxy.org/docs/desktop/addons/plug-n-hack/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 736005 2.12.0 network >= 0.2.0 postman Postman Support Imports and spiders Postman collections. ZAP Dev Team 0.7.0 postman-alpha-0.7.0.zap alpha <h3>Changed</h3> <ul> <li>Enable API functionality for imports.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/postman-v0.7.0/postman-alpha-0.7.0.zap SHA-256:8069006363a5808913f96069bd5980df219efc2d6c2dd4888c798eedd1412846 https://www.zaproxy.org/docs/desktop/addons/postman-support/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 283943 2.16.0 commonlib >= 1.16.0 & < 2.0.0 pscan Passive Scanner Provides core passive scanning capabilities. ZAP Dev Team 0.5.0 pscan-alpha-0.5.0.zap alpha <h3>Changed</h3> <ul> <li>Updated Automation Framework template plans and help content for passiveScan-* jobs to be more consistent.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscan-v0.5.0/pscan-alpha-0.5.0.zap SHA-256:354e64d7df7594b328b708bff1ecd7ef78abd31fa90abb2a5b79b88f3071ebef https://www.zaproxy.org/docs/desktop/addons/passive-scanner/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 684133 2.16.0 commonlib >= 1.32.0 & < 2.0.0 pscanrules Passive scanner rules The release status Passive Scanner rules ZAP Dev Team 67 pscanrules-release-67.zap release <h3>Changed</h3> <ul> <li>Add alert references to HTTP Server Response Header scan rule alerts (Issue 7100, 9050).</li> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v67/pscanrules-release-67.zap SHA-256:adccaad3a3d436ea2e711fe627d52da86cbc299ee4382246279a9984059bed70 https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 1975007 2.16.0 commonlib >= 1.32.0 & < 2.0.0 pscan pscanrulesAlpha Passive scanner rules (alpha) The alpha status Passive Scanner rules ZAP Dev Team 46 pscanrulesAlpha-alpha-46.zap alpha <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesAlpha-v46/pscanrulesAlpha-alpha-46.zap SHA-256:3cb08260bfc742f09b639b812bf7e728a6cf6f9da46375ff7cd008ef27801ada https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-alpha/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 562064 2.16.0 commonlib >= 1.32.0 & < 2.0.0 pscanrulesBeta Passive scanner rules (beta) The beta status Passive Scanner rules ZAP Dev Team 46 pscanrulesBeta-beta-46.zap beta <h3>Changed</h3> <ul> <li>Update alert references to latest locations to fix 404s and resolve redirections.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v46/pscanrulesBeta-beta-46.zap SHA-256:4723e8ceb4b80bb2a24c3aa0337dfb6c39d8b20b532c6d48728dd76ba72f2bfc https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-beta/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 682653 2.16.0 commonlib >= 1.32.0 & < 2.0.0 quickstart Quick Start Provides a tab which allows you to quickly test a target application ZAP Dev Team 52 quickstart-release-52.zap release <h3>Added</h3> <ul> <li>Add icon for Edge browser.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/quickstart-v52/quickstart-release-52.zap SHA-256:fc48c145e63143934c2ecdb0ad9b3c7e7e268d8dc3f09e0d81452363adb41a69 https://www.zaproxy.org/docs/desktop/addons/quick-start/ https://github.com/zaproxy/zap-extensions/ 2025-07-10 774747 2.16.0 callhome >= 0.0.1 network >= 0.3.0 pscan >= 0.1.0 & < 1.0.0 reports >= 0.4.0 reflect Reflect Finds reflected parameters Caleb Kinney 0.0.11 reflect-alpha-0.0.11.zap alpha https://github.com/zaproxy/zap-extensions/releases/download/2.7/reflect-alpha-0.0.11.zap SHA-256:c45307037042e4079546a5fcb17d1165475e5cdd5ba7e8abc0d2cf0a14866466 https://github.com/TypeError/reflect/ 2021-02-19 1780219 2.9.0 regextester Regular Expression Tester Allows to test Regular Expressions ZAP Dev Team 2 regextester-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> <h3>Fixed</h3> <ul> <li>Close dialogues when the add-on is uninstalled.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/regextester-v2/regextester-alpha-2.zap SHA-256:b4706709c16a45e8bedc0bd6f28dd09532d5dbf3f1fe2c2853e20dbf6160a584 https://www.zaproxy.org/docs/desktop/addons/regular-expression-tester/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 159441 2.11.0 replacer Replacer Easy way to replace strings in requests and responses. ZAP Dev Team 20 replacer-release-20.zap release <h3>Fixed</h3> <ul> <li>Typo in automation job help.</li> <li>Address misleading warning <code>Unrecognised parameter</code> for <code>deleteAllRules</code> (Issue 8764).</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> <li>Fields with default or missing values are omitted for the <code>replacer</code> job in saved Automation Framework plans.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/replacer-v20/replacer-release-20.zap SHA-256:632ffa3e1a323b86c873a92285a308d052c7090b52721fdbc5a507e8baa001e0 https://www.zaproxy.org/docs/desktop/addons/replacer/ https://github.com/zaproxy/zap-extensions/ 2025-01-10 445124 2.16.0 reports Report Generation Official ZAP Reports. ZAP Dev Team 0.41.0 reports-release-0.41.0.zap release <h3>Changed</h3> <ul> <li>Corrected a minor typo and image alt tags in the help.</li> </ul> <h3>Added</h3> <ul> <li>An ISO 8601 date and time field (ex: &quot;created&quot;: &quot;2025-09-03T12:49:35.236211400Z&quot;) has been added to the Traditional JSON, Traditional JSON with Requests and Responses, Traditional XML, Traditional XML with Requests and Responses.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.41.0/reports-release-0.41.0.zap SHA-256:af44c18f994aabc87bcbe60d35f0b2786baddd15eacfa7f4bfdcbe41bb4c4d30 https://www.zaproxy.org/docs/desktop/addons/report-generation/ https://github.com/zaproxy/zap-extensions/ 2025-09-04 14940098 2.16.0 commonlib >= 1.17.0 & < 2.0.0 requester Requester Allows to manually edit and send messages. Surikato and the ZAP Dev Team 7.8.0 requester-beta-7.8.0.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/requester-v7.8.0/requester-beta-7.8.0.zap SHA-256:b18fdf0717b90407b770d9bcdae9898fe2365935c03e6a133520750b1dd3e9a7 https://www.zaproxy.org/docs/desktop/addons/requester/ https://github.com/zaproxy/zap-extensions/ 2025-01-10 763103 2.16.0 commonlib >=1.23.0 retest Retest An add-on to retest for presence/absence of previously generated alerts. ZAP Dev Team 0.11.0 retest-alpha-0.11.0.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> <li>To handle automation class changes.</li> <li>Depend on newer version of Passive Scanner add-on (Issue 7959).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/retest-v0.11.0/retest-alpha-0.11.0.zap SHA-256:26ad328ba5bcb144c20076949aacacf6c352121ee74f5bf4a813ccdd8945e35f https://www.zaproxy.org/docs/desktop/addons/retest/ https://github.com/zaproxy/zap-extensions/ 2025-01-10 259775 2.16.0 automation >=0.44.0 commonlib >= 1.17.0 & < 2.0.0 pscan >= 0.1.0 & < 1.0.0 retire Retire.js Use Retire.js to identify vulnerable or out-dated JavaScript packages. Nikita Mundhada and the ZAP Dev Team 0.49.0 retire-release-0.49.0.zap release <h3>Changed</h3> <ul> <li>Updated with upstream retire.js pattern changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/retire-v0.49.0/retire-release-0.49.0.zap SHA-256:249a628956a41e9cf6cbe4fe208cae460938c2c7fe987a318deb5cd22ea0fefd https://www.zaproxy.org/docs/desktop/addons/retire.js/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 1009324 2.16.0 commonlib >= 1.32.0 & < 2.0.0 reveal Reveal Show hidden fields and enable disabled fields ZAP Dev Team 10 reveal-release-10.zap release <h3>Fixed</h3> <ul> <li>The content length is now properly set on responses which have been modified (Issue 8947).</li> </ul> <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/reveal-v10/reveal-release-10.zap SHA-256:18368c13aa8a31a6470a465e9aef7c93d9a45b2c34cfe90f4200cbd04637fd0e https://www.zaproxy.org/docs/desktop/addons/reveal/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 239142 2.16.0 revisit Revisit Revisit a site at any time in the past using the session history ZAP Dev Team 6 revisit-alpha-6.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> <li>Maintenance changes.</li> <li>Minor fix in help content.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/revisit-v6/revisit-alpha-6.zap SHA-256:3f265ea36923b0a7870fb1d24db7c82261ad2616e3b1ad0e5bac5a6b7b8e8230 https://www.zaproxy.org/docs/desktop/addons/revisit/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 302331 2.16.0 saml SAML Support Detect, Show, Edit, Fuzz SAML requests ZAP Dev Team 10 saml-alpha-10.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/saml-v10/saml-alpha-10.zap SHA-256:097492271c7ec1d85def81091ffe897f4809927043844d1f5f0c7c598a0ad164 https://www.zaproxy.org/docs/desktop/addons/saml-support/ https://github.com/zaproxy/zap-extensions/ 2022-10-28 1811985 2.12.0 scanpolicies Scan Policies A set of standard scan policies. ZAP Dev Team 0.5.0 scanpolicies-alpha-0.5.0.zap alpha <h3>Changed</h3> <ul> <li>Updated based on Rules' Policy Tag assignments.</li> </ul> <h3>Added</h3> <ul> <li>QA CI/CD scan policy help.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/scanpolicies-v0.5.0/scanpolicies-alpha-0.5.0.zap SHA-256:1b18f47fdee70e39892c506344c71577996d40e1c2a23eed58a510b2a9edfe13 https://www.zaproxy.org/docs/desktop/addons/scan-policies/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 298823 2.16.0 scripts Script Console Supports all JSR 223 scripting languages ZAP Dev Team 45.13.0 scripts-release-45.13.0.zap release <h3>Changed</h3> <ul> <li>Update help with newer JavaScript engine and links.</li> </ul> <h3>Fixed</h3> <ul> <li>Error logs to always include stack trace.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/scripts-v45.13.0/scripts-release-45.13.0.zap SHA-256:cbf088ecd08a5318815d9460d9af1fad1f7cbe19499f1425e9c84f9fa3002825 https://www.zaproxy.org/docs/desktop/addons/script-console/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 5191053 2.16.0 commonlib >=1.32.0 pscan >= 0.1.0 & < 1.0.0 selenium Selenium WebDriver provider and includes HtmlUnit browser ZAP Dev Team 15.40.0 selenium-release-15.40.0.zap release <h3>Changed</h3> <ul> <li>Update Selenium to version 4.35.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.40.0/selenium-release-15.40.0.zap SHA-256:e8965b7558fb8286dfd9413c543188e77e8c32b66dc1fff44ba0218e584b4c47 https://www.zaproxy.org/docs/desktop/addons/selenium/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 34575132 2.16.0 commonlib >=1.23.0 network >=0.2.0 sequence Sequence Gives the possibility of defining a sequence of requests to be scanned. ZAP Dev Team 8 sequence-beta-8.zap beta <h3>Added</h3> <ul> <li>Add Automation Framework jobs: <ul> <li><code>sequence-import</code> to import HARs as sequences.</li> <li><code>sequence-activeScan</code> to active scan sequences.</li> </ul> </li> <li>Data for reporting.</li> <li>Stats for import automation and active scan.</li> <li>Sequence active scan policy which will be used if neither a policy nor policyDefinition are set.</li> <li>Add Import top level menu item to import HAR as sequence.</li> <li>Active Scan Sequence dialog.</li> </ul> <h3>Changed</h3> <ul> <li>Depend on Import/Export add-on to allow to import HARs as sequences.</li> <li>Update minimum ZAP version to 2.16.0.</li> <li>Maintenance changes.</li> <li>Sequence scan implementation.</li> <li>Promoted to beta.</li> </ul> <h3>Removed</h3> <ul> <li>Sequence panel from the Active Scan dialog.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sequence-v8/sequence-beta-8.zap SHA-256:8419a137caf10cf117523db84f886142116f1e694ca1da44b4481567915e1d6d https://www.zaproxy.org/docs/desktop/addons/sequence-scanner/ https://github.com/zaproxy/zap-extensions/ 2025-01-10 1609867 2.16.0 exim >= 0.13 network zest 48.* soap SOAP Support Imports and scans WSDL files containing SOAP endpoints. Alberto (albertov91) + ZAP Dev Team 28 soap-beta-28.zap beta <h3>Added</h3> <ul> <li>QA CICD policy tag to active scan rules.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/soap-v28/soap-beta-28.zap SHA-256:d91f231b8a7317a1be2d0f03c5ce64896f30fa3ffbd1f7f9d38931b98ddcd98a https://www.zaproxy.org/docs/desktop/addons/soap-support/ https://github.com/zaproxy/zap-extensions/ 2025-09-18 12910718 2.16.0 commonlib >= 1.36.0 & < 2.0.0 spider Spider Spider used for automatically finding URIs on a site. ZAP Dev Team 0.16.0 spider-release-0.16.0.zap release <h3>Added</h3> <ul> <li>Support for stopping the spider automation job.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/spider-v0.16.0/spider-release-0.16.0.zap SHA-256:d6c2551ea52449ea43b4f9f72aecde2faea5cf7ecba8a2230538dc74351e1c59 https://www.zaproxy.org/docs/desktop/addons/spider/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 1190785 2.16.0 commonlib >= 1.29.0 & < 2.0.0 database network >=0.3.0 spiderAjax Ajax Spider Allows you to spider sites that make heavy use of JavaScript using Crawljax ZAP Dev Team 23.26.0 spiderAjax-release-23.26.0.zap release <h3>Added</h3> <ul> <li>Support for stopping the spiderAjax automation job.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/spiderAjax-v23.26.0/spiderAjax-release-23.26.0.zap SHA-256:938cddd402fba0ed93d8bab37a8ae238d44ac1c8a3846e94d37c433631247f64 https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 7608416 2.16.0 commonlib >= 1.23.0 & < 2.0.0 network >=0.11.0 selenium 15.* sqliplugin Advanced SQLInjection Scanner An advanced active injection bundle for SQLi (derived by SQLMap) Andrea Pompili (Yhawke) 16 sqliplugin-beta-16.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.16.0.</li> <li>Maintenance changes.</li> <li>The included active scan rule has been tagged of interest to Penetration Testers.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sqliplugin-v16/sqliplugin-beta-16.zap SHA-256:7c04881f9a3c9c6b4e1ca37099e247886073f15945e479fbdcd58144b2e5a8be https://www.zaproxy.org/docs/desktop/addons/advanced-sqlinjection-scanner/ https://github.com/zaproxy/zap-extensions/ 2025-04-30 541003 2.16.0 commonlib >= 1.32.0 & < 2.0.0 sse Server-Sent Events Allows you to view Server-Sent Events (SSE) communication. ZAP Dev Team 13 sse-alpha-13.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.15.0.</li> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>More gracefully handle missing value for &quot;id&quot; field (Issue 8320)</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sse-v13/sse-alpha-13.zap SHA-256:38cf84e00664287e691606f473343ba0c0db0711c4f895312d0d482c3354731b https://www.zaproxy.org/docs/desktop/addons/server-sent-events/ https://github.com/zaproxy/zap-extensions/ 2024-05-21 330079 2.15.0 svndigger SVN Digger Files SVN Digger files which can be used with ZAP forced browsing ZAP Dev Team 4 svndigger-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Promote to release status.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/svndigger-v4/svndigger-release-4.zap SHA-256:5556efdf3fdb84ebd6cf3e76ca31e3fb6fb57c002cf14b2cf2f05f67bf2b622a https://www.zaproxy.org/docs/desktop/addons/svn-digger-files/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 713963 2.11.0 tips Tips and Tricks Display ZAP Tips and Tricks ZAP Dev Team 15 tips-beta-15.zap beta <h3>Changed</h3> <ul> <li>Change IRC tip to reference Slack.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/tips-v15/tips-beta-15.zap SHA-256:39b4a8e7bfcf86f8c09baa846b837d5045020f80350b73dccae6c03f1a57fe27 https://www.zaproxy.org/docs/desktop/addons/tips-and-tricks/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 572756 2.16.0 tokengen Token Generation and Analysis Allows you to generate and analyze pseudo random tokens, such as those used for session handling or CSRF protection ZAP Dev Team 15 tokengen-beta-15.zap beta <h3>Changed</h3> <ul> <li>Now using 2.10 logging infrastructure (Log4j 2.x).</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/tokengen-v15/tokengen-beta-15.zap SHA-256:daef1d13d44a76b8735a30ed9e1e50fa87a85d02728bd7ae575197d173f942f9 https://www.zaproxy.org/docs/desktop/addons/token-generator/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 525206 2.11.0 treetools TreeTools Tools to add functionality to the tree view. Carl Sampson 8 treetools-beta-8.zap beta <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/treetools-v8/treetools-beta-8.zap SHA-256:b7f61f8939937ebc120bce8deb72713d7676087056e88801df2573112e7642e4 https://www.zaproxy.org/docs/desktop/addons/treetools/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 128931 2.11.0 viewstate ViewState ASP/JSF ViewState Decoder and Editor Calum Hutton 3 viewstate-alpha-3.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/viewstate-v3/viewstate-alpha-3.zap SHA-256:715caefd591415e79b32195361fea82aa8c6357b24e69530c22fde0a1b6dad17 https://www.zaproxy.org/docs/desktop/addons/viewstate/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 148716 2.11.0 wappalyzer Technology Detection Technology detection using various fingerprints and identifiers. ZAP Dev Team 21.48.0 wappalyzer-release-21.48.0.zap release <h3>Changed</h3> <ul> <li>Updated with enthec upstream icon and pattern changes.</li> <li>During load the time taken to process the data files will be shown in human readable format (generally seconds), as well as milliseconds (ms).</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.48.0/wappalyzer-release-21.48.0.zap SHA-256:2b35448c12ba405ce1ce42456acc2594f3041a8e49caa9b77bf54c328d8fb319 https://www.zaproxy.org/docs/desktop/addons/technology-detection/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 25206100 2.16.0 commonlib >= 1.17.0 & < 2.0.0 pscan >= 0.1.0 & < 1.0.0 webdriverlinux Linux WebDrivers Linux WebDrivers for Firefox and Chrome. ZAP Dev Team 156 webdriverlinux-release-156.zap release <h3>Changed</h3> <ul> <li>Update ChromeDriver to 140.0.7339.82.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdriverlinux-v156/webdriverlinux-release-156.zap SHA-256:b133e4a6ab950a041692cee36a86b3bbfe18e5b20ce30d220f4974bc94b58df8 https://www.zaproxy.org/docs/desktop/addons/linux-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 16008361 2.16.0 webdrivermacos MacOS WebDrivers MacOS WebDrivers for Firefox and Chrome. ZAP Dev Team 156 webdrivermacos-release-156.zap release <h3>Changed</h3> <ul> <li>Update ChromeDriver to 140.0.7339.82.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdrivermacos-v156/webdrivermacos-release-156.zap SHA-256:44a4a0355ef81410dde4dfe4d298c2cbbd9bf08b0ac66151210532b006630fbe https://www.zaproxy.org/docs/desktop/addons/macos-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 21645486 2.16.0 webdriverwindows Windows WebDrivers Windows WebDrivers for Firefox and Chrome. ZAP Dev Team 157 webdriverwindows-release-157.zap release <h3>Fixed</h3> <ul> <li>Re-release because of accidental binary deletion of version 156.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdriverwindows-v157/webdriverwindows-release-157.zap SHA-256:a8fa9663fc6401ea578f3918eb168650d8b39b2742f62a10d1ac53716849fa84 https://www.zaproxy.org/docs/desktop/addons/windows-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2025-09-10 22188980 2.16.0 websocket WebSockets Allows you to inspect WebSocket communication. ZAP Dev Team 33 websocket-release-33.zap release <h3>Changed</h3> <ul> <li>Add website alert links to the help page (Issue 8189).</li> <li>Replace usage of CWE-200 for the following rules (Issue 8712): <ul> <li>Email Disclosure.</li> <li>Debug Error Disclosure.</li> </ul> </li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/websocket-v33/websocket-release-33.zap SHA-256:b34ee5374065661de46f329cea8a098713feac4b0f15cb97c96a59f837aad476 https://www.zaproxy.org/docs/desktop/addons/websockets/ https://github.com/zaproxy/zap-extensions/ 2025-06-20 1403130 2.16.0 commonlib >=1.23.0 zest Zest - Graphical Security Scripting Language A graphical security scripting language, ZAPs macro language on steroids ZAP Dev Team 48.9.0 zest-beta-48.9.0.zap beta <h3>Changed</h3> <ul> <li>Allow to keep auhtenticator's proxy running after the authentication.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/zest-v48.9.0/zest-beta-48.9.0.zap SHA-256:238ca3e5f6ce682da7ad178bd450a26354f6cb782dc8d09d72128e2821b56fc5 https://www.zaproxy.org/docs/desktop/addons/zest/ https://github.com/zaproxy/zap-extensions/ 2025-09-02 3045438 2.16.0 commonlib >=1.31.0 network >=0.2.0 pscan >= 0.1.0 & < 1.0.0 scripts >=45.2.0 selenium >= 15.13.0