⚡
  • HOME
  • NEWS
  • SERVICES
  • ARCHITECTURE
  • TECH STACK
  • PORTFOLIO
  • ABOUT
  • CONTACT
HOMENEWSSERVICESARCHITECTURETECH STACKPORTFOLIOABOUTCONTACT
© 2026 Miodrag Gromilić. All rights reserved.
HOMENEWSSERVICESTECH STACKPORTFOLIOCONTACTABOUTFAQs
Back to Skills
OWASP ZAP

OWASP ZAP

Since 2010Web application security testing

Web application security testing — automated vulnerability scanning for XSS, SQL injection, and OWASP Top 10.

Overview

OWASP ZAP is my web application security testing tool. I run automated scans against staging environments to detect XSS, SQL injection, CSRF, and other OWASP Top 10 vulnerabilities. Integrated into CI/CD for automated security regression testing. I use both passive scanning during development and active scanning before releases.

Use Cases

  • Web app security scanning
  • OWASP Top 10 detection
  • penetration testing
  • CI/CD security gates
  • API security testing

Advantages

  • Free and open source
  • comprehensive vulnerability detection
  • CI/CD integration
  • active community
  • API scanning support

Considerations

  • Can be slow for full scans
  • false positives
  • requires tuning for accuracy
  • complex configuration for advanced use

Works Great With

CI/CDDockerJenkinsNginx

Related Technologies

SonarQube
Since 2007
Trivy
Since 2019
Snyk
Since 2015
Back to Skills CONTACT