FAQ: What does ZAP test for?

ZAP supports both active and passive scanning.

By default ZAP comes with the following 'release' quality rules:

But you can also download and install:

from the ZAP Marketplace.

And there are also these scripts in the community scripts repo:

The full list of reserved scan ids is maintained in

