Dynamic web application scanning¶
Features of the two main web application scanners (community versions):
Feature |
Burp Suite |
OWASP ZAP |
Burp Suite Pro |
---|---|---|---|
Web Application Scanning |
Not Available |
Available with |
Available with |
Intercepting Feature |
Available |
Available |
Available |
Fuzzing Capabilities |
Available |
Available |
Available |
Encoder and Decoder |
Available |
Not Available |
Available |
Cost |
Free |
Free |
Paid Subscription |
Documentation |
Extensive |
Little |
Extensive |
Spider |
Available |
Available |
Available |
Updates |
Available |
Available |
Available |
Extensions |
Less Options |
No provision |
Available |
Coverage |
Medium coverage |
Less coverage |
Extensive Coverage |
False Positive |
Less |
More |
Less |
Session Token |
Available |
Not Available |
Available |
Comparison Feature |
Available |
Not Available |
Available |