2.14.0 D-2021-10-18 https://github.com/zaproxy/zaproxy/releases/download/w2021-10-18/ZAP_WEEKLY_D-2021-10-18.zip ZAP_WEEKLY_D-2021-10-18.zip SHA-256:9d4bcb12e47293f3cbc4c32285b8469e620f092bb2519e65e12e5e528a25a8ad 188556676 https://github.com/zaproxy/zaproxy/releases/download/v2.14.0/ZAP_2_14_0_windows-x32.exe ZAP_2_14_0_windows-x32.exe SHA-256:5dae52e27da12fba5115e40ebc0cd2da24f6d9ba91608a7b0b7b254984a0b798 220967424 https://github.com/zaproxy/zaproxy/releases/download/v2.14.0/ZAP_2_14_0_windows.exe ZAP_2_14_0_windows.exe SHA-256:df49ffbd14cf82cde5ac06902615e40cbfce1576f866436366708c0845eb9ec6 221097472 https://github.com/zaproxy/zaproxy/releases/download/v2.14.0/ZAP_2.14.0_Linux.tar.gz ZAP_2.14.0_Linux.tar.gz SHA-256:219d7f25bbe25247713805ab02cc12279898c870743c1aae3c2b0b1882191960 215142045 https://github.com/zaproxy/zaproxy/releases/download/v2.14.0/ZAP_2.14.0.dmg ZAP_2.14.0.dmg SHA-256:3b9862a647b1c5c26d6917f2316113dfaceac06bdb79ad3f2c96e0cbd73861f7 244671708 Bug fix and enhancement release. https://www.zaproxy.org/docs/desktop/releases/2.14.0/ accessControl Access Control Testing Adds a set of tools for testing access control in web applications. ZAP Dev Team 8 accessControl-alpha-8.zap alpha <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/accessControl-v8/accessControl-alpha-8.zap SHA-256:b46903f948e9cc57f9bd2be5402ad64858da6fb39359fa4b459d5e0836492d67 https://www.zaproxy.org/docs/desktop/addons/access-control-testing/ https://github.com/zaproxy/zap-extensions/ 2022-10-28 596436 2.12.0 alertFilters Alert Filters Allows you to automate the changing of alert risk levels. ZAP Dev Team 16 alertFilters-release-16.zap release <h3>Added</h3> <ul> <li>Allow to specify the HTTP method when filtering the alerts (Issue 5967).</li> </ul> <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/alertFilters-v16/alertFilters-release-16.zap SHA-256:7c2f8f47bb727fa5c03d6ebfbc78a821baa88946f27fce91daa074491dfce606 https://www.zaproxy.org/docs/desktop/addons/alert-filters/ https://github.com/zaproxy/zap-extensions/ 2023-06-12 548251 2.12.0 allinonenotes All In One Notes A simple extension to view all notes in one pane. David Vassallo 2 allinonenotes-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Update link to repository.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/allinonenotes-v2/allinonenotes-alpha-2.zap SHA-256:9e70d6e76b72692e9c0cb64002a692b710710e688ea2d8834818086300632d2a https://www.zaproxy.org/docs/desktop/addons/all-in-one-notes/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 249532 2.11.0 amf AMF Support Adds support for AMF messages ZAP Dev Team 3 amf-alpha-3.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/amf-v3/amf-alpha-3.zap SHA-256:01345ea00a6623d794753a3210f4e3e2b50a8c4ce2bfa6ea57324f0ff01ad7e3 https://www.zaproxy.org/docs/desktop/addons/amf-support/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 911943 2.11.0 ascanrules Active scanner rules The release status Active Scanner rules ZAP Dev Team 55 ascanrules-release-55.zap release <h3>Changed</h3> <ul> <li>The Parameter Tamper Scan rule now includes example alert functionality for documentation generation purposes (Issue 6119)</li> </ul> <h3>Fixed</h3> <ul> <li>Fix typo in ASP payload of Server Side Code Injection scan rule.</li> <li>Include complete solution of Server Side Include scan rule.</li> <li>Ensure Custom Payloads support can be properly unloaded.</li> </ul> <h3>Added</h3> <ul> <li>The Hidden File Finder scan rule now check for Blazor WASM config files.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrules-v55/ascanrules-release-55.zap SHA-256:e405d6d1046cf05a4666543c14a5546e32fa0f6d9f00bf80f8469a98f9b5da66 https://www.zaproxy.org/docs/desktop/addons/active-scan-rules/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 3127859 2.12.0 commonlib >= 1.13.0 & < 2.0.0 network >= 0.3.0 oast >= 0.7.0 ascanrulesAlpha Active scanner rules (alpha) The alpha status Active Scanner rules ZAP Dev Team 42 ascanrulesAlpha-alpha-42.zap alpha <h3>Added</h3> <ul> <li>LDAP protocol technology support.</li> </ul> <h3>Fixed</h3> <ul> <li>Preserve the HTTP version in Web Cache Deception scan rule.</li> </ul> <h3>Added</h3> <ul> <li>Server Side Request Forgery Scan Rule.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesAlpha-v42/ascanrulesAlpha-alpha-42.zap SHA-256:a75486ff0fae911e34e2e7b1504d0fb8bdcc9b35c887cc9681aafb4539041a47 https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-alpha/ https://github.com/zaproxy/zap-extensions/ 2022-12-13 417060 2.12.0 commonlib >= 1.9.0 & < 2.0.0 oast >= 0.14.0 ascanrulesBeta Active scanner rules (beta) The beta status Active Scanner rules ZAP Dev Team 46 ascanrulesBeta-beta-46.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>The Insecure HTTP Method Scan rule now allows PUT/PATCH methods, if they return JSON or XML data in response (Issue 7772).</li> <li>The Source Code Disclosure - Git scan rule now includes example alert functionality for documentation generation purposes (Issue 6119).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v46/ascanrulesBeta-beta-46.zap SHA-256:00bb290ef196005c4ed05c4b3da1537cb29ae3fa1a844bb50c66feaf6ac2b926 https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-beta/ https://github.com/zaproxy/zap-extensions/ 2023-05-03 1824345 2.12.0 commonlib >= 1.13.0 & < 2.0.0 database >= 0.1.0 network >= 0.3.0 oast >= 0.7.0 attacksurfacedetector Attack Surface Detector The Attack Surface Detector analyzes web application source code to generate endpoints that can be used for penetration testing. Secure Decisions (Matthew DeLetto) 1.1.4 attacksurfacedetector-alpha-1.1.4.zap alpha Various incremental changes (see https://github.com/secdec/attack-surface-detector-zap/releases)<br> Fix un-handled exception when target unavailable & address various "house keeping" tasks.<br> https://github.com/zaproxy/zap-extensions/releases/download/2.7/attacksurfacedetector-alpha-1.1.4.zap SHA1:e21758c2cdcbc7806f44cc986a88360457eff82e https://github.com/secdec/attack-surface-detector-zap/wiki https://github.com/secdec/attack-surface-detector-zap/ 2019-03-07 15604948 2.7.0 authhelper Authentication Helper Authentication Helper ZAP Dev Team 0.8.0 authhelper-beta-0.8.0.zap beta <h3>Changed</h3> <ul> <li>Prefer username fields with known id/name strings.</li> </ul> <h3>Fixed</h3> <ul> <li>Correct example alert of Session Management Response Identified scan rule.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.8.0/authhelper-beta-0.8.0.zap SHA-256:ad41bfaed26b229bfeb0775e146d1c11d1a088c9990bdb038dc04c9dd673ca29 https://www.zaproxy.org/docs/desktop/addons/authentication-helper/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 810737 2.12.0 commonlib >= 1.13.0 & < 2.0.0 network >=0.6.0 selenium 15.* authstats Authentication Statistics Records logged in/out statistics for all contexts in scope. ZAP Dev Team 2 authstats-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Dynamically unload the add-on.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/authstats-v2/authstats-alpha-2.zap SHA-256:cfb604c27f3a7a58e7b5aa55fe9f19a9ce5561fab3ef7d3f6c72845671fb5dcf https://www.zaproxy.org/docs/desktop/addons/authentication-statistics/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 247499 2.11.0 automation Automation Framework Automation Framework. ZAP Dev Team 0.29.0 automation-beta-0.29.0.zap beta <h3>Added</h3> <ul> <li>Statistic name to test summary.</li> </ul> <h3>Fixed</h3> <ul> <li>Test taking into account previous statistic values.</li> <li>Clear Output tab on new plan.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.29.0/automation-beta-0.29.0.zap SHA-256:7224d2cc088f994d7ea7041548389fae7071b5d77ee7a8cae70c7c881cf2d54b https://www.zaproxy.org/docs/desktop/addons/automation-framework/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 4349656 2.12.0 commonlib >= 1.13.0 & < 2.0.0 beanshell BeanShell Console Provides a BeanShell Console ZAP Dev Team 7 beanshell-beta-7.zap beta <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> <li>Improve permissions and space handling when saving.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/beanshell-v7/beanshell-beta-7.zap SHA-256:0a83cb7d0369ccef50768ccbda1e6c6d82b9f4e3bd9372b38fd32cc21f6a30fb https://www.zaproxy.org/docs/desktop/addons/bean-shell/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 577838 2.11.0 browserView Browser View Adds an option to render HTML responses like a browser ZAP Dev Team 6 browserView-alpha-6.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> <li>Make missing JavaFX logging less verbose in regular use.</li> <li>Update help with the requirements to use the add-on.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/browserView-v6/browserView-alpha-6.zap SHA-256:e53cfde3a009a4be2e40c84ac02e05114505160bd2bab6cbb42416ab9a65b16c https://www.zaproxy.org/docs/desktop/addons/browser-view/ https://github.com/zaproxy/zap-extensions/ 2023-03-13 197667 2.12.0 bruteforce Forced Browse Forced browsing of files and directories using code from the OWASP DirBuster tool ZAP Dev Team 13 bruteforce-beta-13.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Default number of threads to 2 * processor count.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/bruteforce-v13/bruteforce-beta-13.zap SHA-256:c03333528aff28bec89c22d8e83ca582bd6939cbd44ec7c024fbcaa8b488eecc https://www.zaproxy.org/docs/desktop/addons/forced-browse/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 554319 2.12.0 commonlib >= 1.13.0 & < 2.0.0 bugtracker Bug Tracker Bug Tracker extension. ZAP Dev Team 4 bugtracker-alpha-4.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.1.</li> <li>Dependency updates.</li> <li>Maintenance changes.</li> <li>Updated to use PAT not password (https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/bugtracker-v4/bugtracker-alpha-4.zap SHA-256:37c57f8e7f4a1608500527ac1831f8b078427f804ea04ad5790a2970e3e1b722 https://www.zaproxy.org/docs/desktop/addons/bug-tracker/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 3707425 2.11.1 callgraph Call Graph Allows the user to view a call graph of the selected resources Colm O'Flaherty 5 callgraph-alpha-5.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/callgraph-v5/callgraph-alpha-5.zap SHA-256:0874ce5aad0c4bbf28f72627a4940759d328396e12b7d6a5596f2e41bf24dc4e https://www.zaproxy.org/docs/desktop/addons/call-graph/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 925930 2.11.0 callhome Call Home Handles all of the calls to ZAP services. ZAP Dev Team 0.6.0 callhome-release-0.6.0.zap release <h3>Fixed</h3> <ul> <li>Include container field for CFUs.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/callhome-v0.6.0/callhome-release-0.6.0.zap SHA-256:030facef0471ce4c63a40aedd2bd2eaa6768dff2bc61d66c68d9534a376edf47 https://www.zaproxy.org/docs/desktop/addons/call-home/ https://github.com/zaproxy/zap-extensions/ 2022-12-02 320946 2.12.0 codedx Code Dx Extension Includes request and response data in XML reports and provides the ability to upload reports directly to a Code Dx server Code Dx, Inc. 9 codedx-alpha-9.zap alpha <h3>Added</h3> <ul> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Change info URL to link to the site.</li> <li>Maintenance changes.</li> <li>Change to no longer rely on core report classes, which are going to be deleted.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/codedx-v9/codedx-alpha-9.zap SHA-256:767e0a098de281f0bc880b036a5192f26fe0bb014b81227b385a0b63ca570428 https://www.zaproxy.org/docs/desktop/addons/code-dx/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 1769797 2.11.0 commonlib Common Library A common library, for use by other add-ons. ZAP Dev Team 1.14.0 commonlib-release-1.14.0.zap release <h3>Fixed</h3> <ul> <li>Comparable Response functionality is now more robust and doesn't fail when processing types other than JSON Object (Issue 7736).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.14.0/commonlib-release-1.14.0.zap SHA-256:3a658fd3bc9b3def39ad9efb90eecd8f661fa5ef7e7994c23420837efa3a6df1 https://www.zaproxy.org/docs/desktop/addons/common-library/ https://github.com/zaproxy/zap-extensions/ 2023-02-24 4084762 2.12.0 communityScripts Community Scripts Useful ZAP scripts written by the ZAP community. ZAP Community 17 communityScripts-alpha-17.zap alpha <h3>Added</h3> <ul> <li>targeted/SQLMapCommandGenerator.js - it will generate and copy sqlmap command based on the request</li> <li>encode-decode/JwtDecode.js - Decodes JWTs</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0: <ul> <li>Remove compatibility code that provided the singletons (<code>control</code> and <code>model</code>) in JavaScript scripts, they can now be accessed directly always.</li> <li>Use provided singletons (<code>control</code> and <code>model</code>) in Python scripts.</li> <li>Use non-deprecated <code>HttpSender</code> constructor.</li> <li>extender/Simple Reverse Proxy.js - replace usage of deprecated core classes.</li> </ul> </li> <li>Remove statements that return the message in HTTP Sender scripts, the message passed as parameter is used/sent always.</li> </ul> https://github.com/zaproxy/community-scripts/releases/download/v17/communityScripts-alpha-17.zap SHA-256:58110bdd68defdb3610886e37d4a4e46e99cbe60370d5299f5ee398762ef524d https://www.zaproxy.org/docs/desktop/addons/community-scripts/ https://github.com/zaproxy/community-scripts/ 2023-06-28 460543 2.12.0 coreLang Core Language Files Translations of the core language files ZAP Dev Team 15 coreLang-release-15.zap release <h3>Changed</h3> <ul> <li>Update the languages files from Crowdin.</li> <li>Update minimum ZAP version to 2.11.1.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/coreLang-v15/coreLang-release-15.zap SHA-256:d8258b914ffc95820dd045acf56677668a8cbbfc759290f72e30210056dfb88c https://crowdin.com/project/zaproxy https://github.com/zaproxy/zap-extensions/ 2022-02-14 4616009 2.11.1 custompayloads Custom Payloads Ability to add, edit or remove payloads that are used i.e. by active scanners ZAP Dev Team 0.12.0 custompayloads-alpha-0.12.0.zap alpha <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.1.</li> <li>Add help content linking to the Scan Rules which support Custom Payloads.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.12.0/custompayloads-alpha-0.12.0.zap SHA-256:8e31acafdc1e2246e25953d8ccb87efa189a3fdadc596331feabeccc99dece65 https://www.zaproxy.org/docs/desktop/addons/custom-payloads/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 236404 2.11.1 database Database Provides database engines and related infrastructure. ZAP Dev Team 0.1.0 database-alpha-0.1.0.zap alpha <h3>Added</h3> <ul> <li>Provides the SQLite database engine for other add-ons to use.</li> <li>Support for the ZAP permanent database.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/database-v0.1.0/database-alpha-0.1.0.zap SHA-256:587f1b2e2cac30c132a6c19092d2dc69c6c0472da4fea9a2048694a0aa239981 https://www.zaproxy.org/docs/desktop/addons/database/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 19560894 2.12.0 dev Dev Add-on An add-on to help with development of ZAP. ZAP Dev Team 0.2.0 dev-alpha-0.2.0.zap alpha <h3>Added</h3> <ul> <li>Auth pages where the password field is not accessible until the username is filled in.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/dev-v0.2.0/dev-alpha-0.2.0.zap SHA-256:5766843a40411ece9ec7cecaa2c0d08562046023a66baaac4751ebf455107819 https://www.zaproxy.org/docs/desktop/addons/dev-add-on/ https://github.com/zaproxy/zap-extensions/ 2023-05-09 70614 2.12.0 network >=0.7.0 diff Diff Displays a dialog showing the differences between 2 requests or responses. It uses diffutils and diff_match_patch ZAP Dev Team 12 diff-beta-12.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/diff-v12/diff-beta-12.zap SHA-256:3367a087f6d14d990764cc8fd395424d81da2bb57e0020a819153ccf7cbeca35 https://www.zaproxy.org/docs/desktop/addons/diff/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 283039 2.12.0 directorylistv1 Directory List v1.0 List of directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 5 directorylistv1-release-5.zap release <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv1-v5/directorylistv1-release-5.zap SHA-256:c1c0e14aac2ce203bdfd3a038f9b9dcf0b498f404936c3ff96e5a4614f611b9f https://www.zaproxy.org/docs/desktop/addons/directory-list-v1.0/ https://github.com/zaproxy/zap-extensions/ 2021-10-06 960428 2.11.0 directorylistv2_3 Directory List v2.3 Lists of directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 4 directorylistv2_3-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3-v4/directorylistv2_3-release-4.zap SHA-256:3a8b04b9363b57acd9cf8cd67abce4c630f986e2b492a1ebd01eaa9587a0a199 https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 8722229 2.11.0 directorylistv2_3_lc Directory List v2.3 LC Lists of lower case directory names to be used with Forced Browse or Fuzzer add-on. ZAP Dev Team 4 directorylistv2_3_lc-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3_lc-v4/directorylistv2_3_lc-release-4.zap SHA-256:2603580ba53673c31800ef7373e7cc09de759369b6f8fb43cc9e5024ad5d9af4 https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3-lc/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 7569974 2.11.0 domxss DOM XSS Active scanner rule DOM XSS Active scanner rule Aabha Biyani, ZAP Dev Team 15 domxss-release-15.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Disable JSON view in Firefox to prevent hangs when the &quot;Save As&quot; option is invoked.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/domxss-v15/domxss-release-15.zap SHA-256:76653c39791ee3090bad573b2f383709b837034025299fd6e41069e5d3a8e6bb https://www.zaproxy.org/docs/desktop/addons/dom-xss-active-scan-rule/ https://github.com/zaproxy/zap-extensions/ 2023-05-23 271332 2.12.0 commonlib >= 1.6.0 & < 2.0.0 network >=0.1.0 selenium >= 15.12.0 encoder Encoder Adds encode/decode/hash dialog and support for scripted processors as well ZAP Dev Team 1.1.0 encoder-release-1.1.0.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Added</h3> <ul> <li>A context menu active on the output text areas facilitating the replacement of input text.</li> <li>PowerShell encoder (hat tip to hackvertor/hackvertor#71 for the idea and details).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/encoder-v1.1.0/encoder-release-1.1.0.zap SHA-256:95243e1ea557a7e96d56f16e77a8cac6f71c8b6437ddbf4600e52470504577c2 https://www.zaproxy.org/docs/desktop/addons/encode-decode-hash/ https://github.com/zaproxy/zap-extensions/ 2023-03-13 445128 2.12.0 evalvillain Eval Villain Adds the Eval Villain extension to Firefox when launched from ZAP. Dennis Goodlett and the ZAP Dev Team 0.2.0 evalvillain-alpha-0.2.0.zap alpha <h3>Changed</h3> <ul> <li>Updated with new version of Eval Villain.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/evalvillain-v0.2.0/evalvillain-alpha-0.2.0.zap SHA-256:7eea4ad7c86f17b5daff5d1c59ed63c278c0833e6358503799ee9e19b7f0645e https://www.zaproxy.org/docs/desktop/addons/eval-villain/ https://github.com/zaproxy/zap-extensions/ 2023-04-04 4943217 2.12.0 selenium >=15.5.0 exim Import/Export Import and Export functionality ZAP Dev Team & thatsn0tmysite 0.5.0 exim-beta-0.5.0.zap beta <h3>Changed</h3> <ul> <li>Log cause of error when failed to import the HAR file.</li> </ul> <h3>Fixed</h3> <ul> <li>Ensure the 'ZAP messages' Export delimiters are consistent with the Import expectation.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/exim-v0.5.0/exim-beta-0.5.0.zap SHA-256:c419cb4a27b580e75935b557e2fda721ed8b48c6c55eeee8d8a25c9c22c180e6 https://www.zaproxy.org/docs/desktop/addons/import-export/ https://github.com/zaproxy/zap-extensions/ 2023-04-04 477696 2.12.0 commonlib >= 1.8.0 & < 2.0.0 fileupload FileUpload Detect File upload requests and scan them to find related vulnerabilities KSASAN preetkaran20@gmail.com 1.1.0 fileupload-alpha-1.1.0.zap alpha https://github.com/zaproxy/zap-extensions/releases/download/2.7/fileupload-alpha-1.1.0.zap SHA-256:47f2d93c6a53c55983056af282ebef09e80d27c0980517a73347778ad9e47932 https://github.com/SasanLabs/owasp-zap-fileupload-addon/ 2021-09-17 77520 2.11.0 formhandler Value Generator This Value Generator Add-on allows a user to define field names and values to be used when submitting values to an app. Fields can be added, modified, enabled/disabled, and deleted. ZAP Dev Team 6.3.0 formhandler-beta-6.3.0.zap beta <h3>Changed</h3> <ul> <li>Renamed to &quot;Value Generator&quot; to more clearly identify to users what the add-on does.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/formhandler-v6.3.0/formhandler-beta-6.3.0.zap SHA-256:09370682b4a3b5f1444ea3fb40d2251b5847deefee02251614c3c2e3a5654115 https://www.zaproxy.org/docs/desktop/addons/value-generator/ https://github.com/zaproxy/zap-extensions/ 2023-06-02 2213174 2.12.0 fuzz Fuzzer Advanced fuzzer for manual testing ZAP Dev Team 13.9.0 fuzz-beta-13.9.0.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Prevent exception if no display (Issue 3978).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/fuzz-v13.9.0/fuzz-beta-13.9.0.zap SHA-256:5fae24e3586db435bd1a3156e1aebea36616e5a03571cfa86089546a581e525b https://www.zaproxy.org/docs/desktop/addons/fuzzer/ https://github.com/zaproxy/zap-extensions/ 2023-01-03 2001020 2.12.0 fuzzdb FuzzDB Files FuzzDB files which can be used with the ZAP fuzzer ZAP Dev Team 9 fuzzdb-release-9.zap release <h3>Changed</h3> <ul> <li>Updated RAFT lists based on more recent SecLists contributions</li> <li>Update minimum ZAP version to 2.11.1.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/fuzzdb-v9/fuzzdb-release-9.zap SHA-256:c79537362cd6b383f447359685e3bd51795600b97ca0c1fadc4ba74828a7d4f4 https://www.zaproxy.org/docs/desktop/addons/fuzzdb-files/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 6167205 2.11.1 fuzzdboffensive FuzzDB Offensive FuzzDB web backdoors and attack files which can be used with the ZAP fuzzer or for manual penetration testing ZAP Dev Team 4 fuzzdboffensive-release-4.zap release <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.10.0.</li> </ul> https://github.com/zaproxy/fuzzdb-offensive/releases/download/v4/fuzzdboffensive-release-4.zap SHA-256:06bf75d2745c8f6e9a861597a31bab2d3f96058a3c497539a3ba234c687e796a https://www.zaproxy.org/docs/desktop/addons/fuzzdb-offensive/ https://github.com/zaproxy/fuzzdb-offensive/ 2021-06-11 414373 2.10.0 gettingStarted Getting Started with ZAP Guide A short Getting Started with ZAP Guide ZAP Dev Team 14 gettingStarted-release-14.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> <li>Added note about Firefox's Enhanced Tracking Protection.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/gettingStarted-v14/gettingStarted-release-14.zap SHA-256:83a8aca931746122bdd89c651f0bd70f695b609167d94b9194de3b7f9ec1a841 https://www.zaproxy.org/docs/desktop/addons/getting-started-guide/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 796000 2.12.0 graaljs GraalVM JavaScript Provides the GraalVM JavaScript engine for ZAP scripting. ZAP Dev Team 0.3.0 graaljs-alpha-0.3.0.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> </ul> <h3>Fixed</h3> <ul> <li>Declare the engine is single threaded (Issue 6992).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/graaljs-v0.3.0/graaljs-alpha-0.3.0.zap SHA-256:c16a2c0b94192ed929b9b38d81f4b06a00286a0fbefd8b575be352c3e42f68be https://github.com/zaproxy/zap-extensions/ 2022-10-27 20440986 2.12.0 graphql GraphQL Support Inspect and attack GraphQL endpoints. ZAP Dev Team 0.17.0 graphql-alpha-0.17.0.zap alpha <h3>Added</h3> <ul> <li>It is now possible to disable the query generator completely.</li> </ul> <h3>Changed</h3> <ul> <li>Dependency updates.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/graphql-v0.17.0/graphql-alpha-0.17.0.zap SHA-256:aefbd274ca78bb9a66f02330137363dfe69df5ea30765e47b87795c0836f6e44 https://www.zaproxy.org/docs/desktop/addons/graphql-support/ https://github.com/zaproxy/zap-extensions/ 2023-06-19 5650675 2.12.0 commonlib >= 1.14.0 & < 2.0.0 groovy Groovy Support Adds Groovy support to ZAP ZAP Dev Team 3.1.0 groovy-beta-3.1.0.zap beta <h3>Added</h3> <ul> <li>encode-decode default template.</li> </ul> <h3>Changed</h3> <ul> <li>Update links to zaproxy and zap-extensions repos.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/groovy-v3.1.0/groovy-beta-3.1.0.zap SHA-256:ee208309c6b9619f6527a05f48949e38e1476f2b3fa7c6e32fbd1111f4bdac58 https://www.zaproxy.org/docs/desktop/addons/groovy-support/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 19006812 2.11.0 help Help - English English version of the ZAP help file. ZAP Crowdin Team 15 help-release-15.zap release <h3>Changed</h3> <ul> <li>Updated for 2.12.0.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help-v15/help-release-15.zap SHA-256:8db85b4f0fedb8b2fa56578222f1a76b2b48029e2d2e360a9659826241ebfaa6 https://www.zaproxy.org/docs/desktop/ https://github.com/zaproxy/zap-core-help/ 2022-10-27 611954 2.10.0 help_ar_SA Help - Arabic Arabic version of the ZAP help file. ZAP Crowdin Team 1 help_ar_SA-alpha-1.zap alpha <ul> <li>First version.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ar_SA-v1/help_ar_SA-alpha-1.zap SHA-256:8208b0c788d5e29a2bb34f3c44c07db613faefb17d8d9cfb60adc02629c2b3f1 https://github.com/zaproxy/zap-core-help/ 2022-01-18 649333 2.11.0 help_bs_BA Help - Bosnian Bosnian version of the ZAP help file. ZAP Crowdin Team 9 help_bs_BA-alpha-9.zap alpha Updated with the latest files from crowdin https://github.com/zaproxy/zap-extensions/releases/download/2.7/help_bs_BA-alpha-9.zap SHA1:d33a3277e877da4734e6bf9c911c61c4e6ce2f3f 2018-02-08 747536 2.7.0 help_es_ES Help - Spanish Spanish version of the ZAP help file. ZAP Crowdin Team 10 help_es_ES-release-10.zap release <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_es_ES-v10/help_es_ES-release-10.zap SHA-256:63cc24e180374cf038d6aefe31b3f62e170437958ad61d2d3e65d2722fbedc1a https://github.com/zaproxy/zap-core-help/ 2022-01-18 697066 2.11.0 help_fil_PH Help - Filipino Filipino version of the ZAP help file. ZAP Crowdin Team 3 help_fil_PH-alpha-3.zap alpha <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_fil_PH-v3/help_fil_PH-alpha-3.zap SHA-256:64bbeb0f9404b70c0d49e9fd5da789b8d3902a20f518c7305eb412242831a180 https://github.com/zaproxy/zap-core-help/ 2022-01-18 710027 2.11.0 help_fr_FR Help - French French version of the ZAP help file. ZAP Crowdin Team 10 help_fr_FR-alpha-10.zap alpha <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_fr_FR-v10/help_fr_FR-alpha-10.zap SHA-256:f1ede9441e5de48170fdef598eb543ef6ad0813eed2e838d2c4803ea114fcb1a https://github.com/zaproxy/zap-core-help/ 2022-01-18 646717 2.11.0 help_id_ID Help - Indonesian Indonesian version of the ZAP help file. ZAP Crowdin Team 3 help_id_ID-beta-3.zap beta <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_id_ID-v3/help_id_ID-beta-3.zap SHA-256:ef50363872d783c3c49417bc821b28256cf35d8390004c48f6d4e030ceb8a7c5 https://github.com/zaproxy/zap-core-help/ 2022-01-18 671009 2.11.0 help_ja_JP Help - Japanese Japanese version of the ZAP help file. ZAP Crowdin Team 10 help_ja_JP-beta-10.zap beta <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ja_JP-v10/help_ja_JP-beta-10.zap SHA-256:11d310352e8719fe50587c5b97dd5eeb3a2e2ab23e450a7c1d0fad013d003536 https://github.com/zaproxy/zap-core-help/ 2022-01-18 661964 2.11.0 help_ms_MY Help - Malay Malay version of the ZAP help file. ZAP Crowdin Team 1 help_ms_MY-alpha-1.zap alpha <ul> <li>First version.</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ms_MY-v1/help_ms_MY-alpha-1.zap SHA-256:6407990b8ebaa2e401c3addc47081c742ab7fce25cec107ef49b4e627ad3ceae https://github.com/zaproxy/zap-core-help/ 2022-01-18 636908 2.11.0 help_pt_BR Help - Portuguese, Brazilian Portuguese, Brazilian version of the ZAP help file. ZAP Crowdin Team 11 help_pt_BR-release-11.zap release <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_pt_BR-v11/help_pt_BR-release-11.zap SHA-256:3fdf92763c1c851848df6b3588c97bbeb22837002351fd00c8208d8ab01ff710 https://github.com/zaproxy/zap-core-help/ 2022-01-18 682092 2.11.0 help_ru_RU Help - Russian Russian version of the ZAP help file. ZAP Crowdin Team 2 help_ru_RU-release-2.zap release <h3>Changed</h3> <ul> <li>Promote to Release</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_ru_RU-v2/help_ru_RU-release-2.zap SHA-256:3fd5d8e6af7453a3a16e7c38a19ec941a330d0fd050f562ecebdc4638ae52c80 https://github.com/zaproxy/zap-core-help/ 2022-02-24 779171 2.11.0 help_tr_TR Help - Turkish Turkish version of the ZAP help file. ZAP Crowdin Team 2 help_tr_TR-release-2.zap release <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_tr_TR-v2/help_tr_TR-release-2.zap SHA-256:a92b43beab5e196341d8ddf40d594f1596c225c74f0f5b9280e223acc9a8535c https://github.com/zaproxy/zap-core-help/ 2022-01-18 710766 2.11.0 help_zh_CN Help - Chinese Simplified Chinese Simplified version of the ZAP help file. ZAP Crowdin Team 3 help_zh_CN-beta-3.zap beta <h3>Changed</h3> <ul> <li>Updated with the latest files from crowdin</li> </ul> https://github.com/zaproxy/zap-core-help/releases/download/help_zh_CN-v3/help_zh_CN-beta-3.zap SHA-256:959b718a307ca32c7807c0d327533765eeb6a0a799b9bc98a2a1e22b3b47bc5a https://github.com/zaproxy/zap-core-help/ 2022-01-18 656718 2.11.0 highlighter Highlighter Allows you to highlight strings in the request and response tabs. ZAP Dev Team 8 highlighter-alpha-8.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/highlighter-v8/highlighter-alpha-8.zap SHA-256:4c4852bb2f42eb20dbe19a091e9025667947c73967a65770658333bedd01fccf https://www.zaproxy.org/docs/desktop/addons/highlighter/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 115527 2.11.0 hud HUD - Heads Up Display Display information from ZAP in browser. ZAP Dev Team 0.16.0 hud-beta-0.16.0.zap beta <h3>Added</h3> <ul> <li>Added Clear Button to History and WebSockets Tab (Issue 411).</li> </ul> <h3>Fixed</h3> <ul> <li>Prevent exception if no display (Issue 3978).</li> </ul> https://github.com/zaproxy/zap-hud/releases/download/v0.16.0/hud-beta-0.16.0.zap SHA-256:a4c61217077abfc4ad162f7b3908454f88284c0f57706cc63c2bc1611b9883e2 https://www.zaproxy.org/docs/desktop/addons/hud/ https://github.com/zaproxy/zap-hud/ 2023-01-25 1368604 2.12.0 network >= 0.1.0 websocket imagelocationscanner Image Location and Privacy Scanner Image Location and Privacy Passive Scanner Jay Ball (veggiespam) and the ZAP Dev Team 4 imagelocationscanner-beta-4.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.1.</li> <li>Maintenance changes.</li> </ul> <h3>Added</h3> <ul> <li>OWASP Web Security Testing Guide v4.2 mappings.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/imagelocationscanner-v4/imagelocationscanner-beta-4.zap SHA-256:6d168e4d156335a0544619011b742e47e6dc1d492a2d63a0e8f787b28796b2c9 https://www.zaproxy.org/docs/desktop/addons/image-location-and-privacy-scanner/ https://github.com/zaproxy/zap-extensions/ 2022-09-23 1138093 2.11.1 commonlib >= 1.6.0 & < 2.0.0 invoke Invoke Applications Invoke external applications passing context related information such as URLs and parameters ZAP Dev Team 12 invoke-beta-12.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/invoke-v12/invoke-beta-12.zap SHA-256:ee1461a3f2f82165bcc2c4050c99daf22ead9f28506ecfa190a10e14f7f3c9c3 https://www.zaproxy.org/docs/desktop/addons/invoke-applications/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 325970 2.12.0 jruby Ruby Scripting Allows Ruby to be used for ZAP scripting - templates included ZAP Dev Team 8 jruby-beta-8.zap beta <h3>Changed</h3> <ul> <li>Update links to zaproxy repo.</li> <li>Rename reliability to confidence in active/passive templates.</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jruby-v8/jruby-beta-8.zap SHA-256:f5bb450a165f6c407b8d24f7b2776bdc7a2edb0b4b42aea385f8a6ad1ae605ca https://www.zaproxy.org/docs/desktop/addons/ruby-scripting/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 21968128 2.11.0 jsonview JSON View Adds a view that shows JSON messages nicely formatted Juha Kivekäs 2 jsonview-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add the main context menu to the JSON view.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Capitalize the view dropdown menu entry (related to Issue 2000).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jsonview-v2/jsonview-alpha-2.zap SHA-256:49fd8995eac7724e5a60f7b6d7f10cfb617f3f083b6f23406075631ba23c7ebc https://www.zaproxy.org/docs/desktop/addons/json-view/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 119886 2.11.0 jwt JWT Support Detect JWT requests and scan them to find related vulnerabilities KSASAN preetkaran20@gmail.com 1.0.3 jwt-alpha-1.0.3.zap alpha <ul> <li>First version of JWT Support. <ul> <li>Contains scanning rules for basic JWT related vulnerabilities.</li> <li>Contains JWT Fuzzer for fuzzing the JWT's present in the request.</li> </ul> </li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/2.7/jwt-alpha-1.0.3.zap SHA-256:d3df8480010ad2df230cbdb99619aafdb869861349455c3da0129a99b132d204 https://github.com/SasanLabs/owasp-zap-jwt-addon/ 2023-01-02 751748 2.11.1 commonlib fuzz 13.* jython Python Scripting Allows Python to be used for ZAP scripting - templates included ZAP Dev Team 12 jython-beta-12.zap beta <h3>Added</h3> <ul> <li>encode-decode default and rot13 templates.</li> </ul> <h3>Changed</h3> <ul> <li>Update links to zaproxy repo.</li> <li>Rename reliability to confidence in active/passive templates.</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/jython-v12/jython-beta-12.zap SHA-256:4519b862edf8f006c429c86b0152ade561b660ae6f74cfce684b272f4fe28ef1 https://www.zaproxy.org/docs/desktop/addons/python-scripting/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 43312397 2.11.0 kotlin Kotlin Support Allows Kotlin to be used for ZAP scripting StackHawk Engineering 1.1.0 kotlin-alpha-1.1.0.zap alpha <h3>Changed</h3> <ul> <li>Use appropriate syntax style for highlighting of code.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/kotlin-v1.1.0/kotlin-alpha-1.1.0.zap SHA-256:85a47ea7199b77cfb09081302c277de2ba5e2102ef79907573ebcfa6425302e9 https://www.zaproxy.org/docs/desktop/addons/kotlin-support/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 48865539 2.11.0 levoai Levo.ai Build OpenAPI Specs with ZAP traffic using Levo.ai. Levo.ai 0.2.0 levoai-zap-addon-alpha-0.2.0.zap alpha <h3>Added</h3> <ul> <li>Validate the Satellite URL structure when it is modified.</li> </ul> <h3>Fixed</h3> <ul> <li>URLs with '/' as the path were not being handled correctly.</li> </ul> https://github.com/levoai/levoai-zap-addon/releases/download/v0.2.0/levoai-zap-addon-alpha-0.2.0.zap SHA-256:28777022d50fa8ff29ef21ab94d01786d4936dcf6ddc9303e64f52983203311d https://docs.levo.ai/api-observability/quickstart/quickstart-zap-addon https://github.com/levoai/levoai-zap-addon 2022-12-26 2459871 2.12.0 neonmarker Neonmarker Colors history table items based on tags Juha Kivekäs, Kingthorin 1.5.0 neonmarker-alpha-1.5.0.zap alpha <h3>Added</h3> <ul> <li>A right-click context menu is now available in the History tab in order to Select/Set a color for arbitrary messages.</li> </ul> https://github.com/kingthorin/neonmarker/releases/download/v1.5.0/neonmarker-alpha-1.5.0.zap SHA-256:0b888612670e66712001d0bd3cb990d7b34f88b7b6339aed2734083b8a5fe5c5 https://www.zaproxy.org/docs/desktop/addons/neonmarker/ https://github.com/kingthorin/neonmarker 2022-07-11 35903 2.10.0 network Network Provides core networking capabilities. ZAP Dev Team 0.9.0 network-beta-0.9.0.zap beta <h3>Changed</h3> <ul> <li>Use <code>TRACE</code> level (instead of <code>DEBUG</code>) to log client side HTTP traffic to avoid accidentally enabling it when debugging other add-ons.</li> </ul> <h3>Fixed</h3> <ul> <li>Do not close the client connection when the server closes it, if not required, to keep the client connection in good state and be used longer.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/network-v0.9.0/network-beta-0.9.0.zap SHA-256:aab240ca0bc82077830b96273b2f770d163eea017a04e9ed6c70217581ed7a99 https://www.zaproxy.org/docs/desktop/addons/network/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 27356770 2.12.0 oast OAST Support Allows you to exploit out-of-band vulnerabilities ZAP Dev Team 0.15.0 oast-beta-0.15.0.zap beta <h3>Added</h3> <ul> <li>A context menu to paste payloads from all the supported OAST services (Issue 7665).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/oast-v0.15.0/oast-beta-0.15.0.zap SHA-256:472c4e387057d88365885345e2e254b930928e84f2eae12fe725e0cfcc9590c8 https://www.zaproxy.org/docs/desktop/addons/oast-support/ https://github.com/zaproxy/zap-extensions/ 2023-03-13 806224 2.12.0 database >= 0.1.0 network >= 0.1.0 onlineMenu Online menus ZAP Online menu items ZAP Dev Team 10 onlineMenu-release-10.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/onlineMenu-v10/onlineMenu-release-10.zap SHA-256:e621aadb1d686243e1463344b128573cb9857c4118cf41ddb7be7c584fdd0ed9 https://www.zaproxy.org/docs/desktop/addons/online-menu/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 209008 2.12.0 openapi OpenAPI Support Imports and spiders OpenAPI definitions. ZAP Dev Team plus Joanna Bona, Nathalie Bouchahine, Artur Grzesica, Mohammad Kamar, Markus Kiss, Michal Materniak, Marcin Spiewak, and SDA SE Open Industry Solutions 34 openapi-beta-34.zap beta <h3>Changed</h3> <ul> <li>Dependency updates.</li> </ul> <h3>Fixed</h3> <ul> <li>Fix exception when generating data for parameters without schema.</li> <li>An exception which might occur on large definition imports (Issue 7876).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/openapi-v34/openapi-beta-34.zap SHA-256:63206207b32f403f53f6dd01bf7f9521a0a8fc60582a5f142395f3d58fff2579 https://www.zaproxy.org/docs/desktop/addons/openapi-support/ https://github.com/zaproxy/zap-extensions/ 2023-06-27 13114271 2.12.0 commonlib >= 1.8.0 & < 2.0.0 packpentester Collection: Pentester Pack A collection of add-ons ideal for pentesters ZAP Dev Team 0.1.0 packpentester-alpha-0.1.0.zap alpha <h3>Fixed</h3> <ul> <li>Corrected fuzz add-on name</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/packpentester-v0.1.0/packpentester-alpha-0.1.0.zap SHA-256:0b8e7e4ddffdcacf46fdf9793bf84217738e281cbd5ccac732788c4b768d069c https://www.zaproxy.org/docs/desktop/addons/collection-pentester-pack/ https://github.com/zaproxy/zap-extensions/ 2022-05-12 6792 2.11.1 accessControl attacksurfacedetector custompayloads evalvillain fileupload fuzz fuzzdb jsonview jwt requester viewstate wappalyzer packscanrules Collection: Scan Rules Pack All of the add-ons just containing release, beta and alpha status scan rules ZAP Dev Team 0.0.1 packscanrules-alpha-0.0.1.zap alpha <p>First version.</p> https://github.com/zaproxy/zap-extensions/releases/download/packscanrules-v0.0.1/packscanrules-alpha-0.0.1.zap SHA-256:5ad68f153379bd96f36a7bead61e884cc42e1409cdd262dffc682b5f7bf92da4 https://www.zaproxy.org/docs/desktop/addons/collection-scan-rules-pack/ https://github.com/zaproxy/zap-extensions/ 2022-05-13 9244 2.11.1 ascanrules ascanrulesAlpha ascanrulesBeta domxss pscanrules pscanrulesAlpha pscanrulesBeta retire paramdigger Parameter Digger Identify hidden, unlinked parameters. Useful for finding web cache poisoning vulnerabilities. ZAP Dev Team and Arkaprabha Chakraborty 0.2.0 paramdigger-alpha-0.2.0.zap alpha <h3>Fixed</h3> <ul> <li>NullPointerException which could occur with header guesser.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> <li>Default number of threads to 2 * processor count.</li> <li>Change panel designs to allow message selection.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/paramdigger-v0.2.0/paramdigger-alpha-0.2.0.zap SHA-256:a6741d85e9d9b9a01107e176f8530c3386fc4671fde4c0a38b94cd6d953a35d6 https://www.zaproxy.org/docs/desktop/addons/parameter-digger/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 553729 2.12.0 commonlib >= 1.13.0 & < 2.0.0 plugnhack Plug-n-Hack Configuration Supports the Mozilla Plug-n-Hack standard: https://developer.mozilla.org/en-US/docs/Plug-n-Hack. ZAP Dev Team 13 plugnhack-beta-13.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> <li>Use Network add-on to obtain main proxy address/port.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/plugnhack-v13/plugnhack-beta-13.zap SHA-256:8d74b572bb7e08d09ebcfd10da9f2f65f7970f9452feadb8bbe69c8037b80ee2 https://www.zaproxy.org/docs/desktop/addons/plug-n-hack/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 736005 2.12.0 network >= 0.2.0 portscan Port Scanner Allows to port scan a target server ZAP Dev Team 10 portscan-beta-10.zap beta <h3>Changed</h3> <ul> <li>Use the Network add-on to obtain the outgoing proxy.</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/portscan-v10/portscan-beta-10.zap SHA-256:6cf0432e1c329499649b219d2f00e7ec7bc2079d7160396fecb9a8ad3446b963 https://www.zaproxy.org/docs/desktop/addons/port-scan/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 724563 2.12.0 network >=0.3.0 pscanrules Passive scanner rules The release status Passive Scanner rules ZAP Dev Team 49 pscanrules-release-49.zap release <h3>Changed</h3> <ul> <li>The X-AspNet-Version Response Header Scan Rule now includes example alert functionality for documentation generation purposes (Issue 6119).</li> <li>The Information Disclosure Suspicious Comments scan rule: <ul> <li>Now includes example alert functionality for documentation generation purposes (Issue 6119).</li> <li>Now has a Alert Tag with a OWASP WSTG reference.</li> <li>Added 'DEBUG' to list of suspicious comments.</li> <li>Added custom payload support (via Custom Payloads add-on).</li> <li>Removed suspicious-comments.txt file in favor of payload editing via Custom Payloads add-on.</li> </ul> </li> </ul> <h3>Fixed</h3> <ul> <li>Ensure Custom Payloads support can be properly unloaded.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v49/pscanrules-release-49.zap SHA-256:9388d27b7274f6d4bcd2d27e0522e74297921eb31e3abd50df027f32b4c2c82d https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 1841359 2.12.0 commonlib >= 1.13.0 & < 2.0.0 pscanrulesAlpha Passive scanner rules (alpha) The alpha status Passive Scanner rules ZAP Dev Team 39 pscanrulesAlpha-alpha-39.zap alpha <h3>Added</h3> <ul> <li>Base64, Example, Site Isolation, and Source Code Disclosure scan rules now all provide example alerts for documentation purposes. As well as Alert Refs where applicable (Issues 6119 &amp; 7100).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesAlpha-v39/pscanrulesAlpha-alpha-39.zap SHA-256:100190abe7d70a4b0315ee5465c90fc2c72bbb7be3db4ef259c93b873d147224 https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-alpha/ https://github.com/zaproxy/zap-extensions/ 2023-05-03 445880 2.12.0 commonlib >= 1.10.0 & < 2.0.0 pscanrulesBeta Passive scanner rules (beta) The beta status Passive Scanner rules ZAP Dev Team 33 pscanrulesBeta-beta-33.zap beta <h3>Changed</h3> <ul> <li>The following scan rules now have functionality to generate example alerts for documentation purposes (Issue 6119). <ul> <li>In Page Banner Information Leak</li> <li>Java Serialization Object</li> <li>HTTP Parameter Override</li> <li>Sub Resource Integrity Attribute Missing</li> </ul> </li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v33/pscanrulesBeta-beta-33.zap SHA-256:33c8abaa98fa3e6aeea5d32316a106bbc5addf4fd0a111a7bd0edf322f499493 https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-beta/ https://github.com/zaproxy/zap-extensions/ 2023-05-03 575914 2.12.0 commonlib >= 1.10.0 & < 2.0.0 quickstart Quick Start Provides a tab which allows you to quickly test a target application ZAP Dev Team 37 quickstart-release-37.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Show correct error message when unable to access the provided URL, also, add the scheme if none provided.</li> <li>Ensure the add-on is not in use before uninstalling.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/quickstart-v37/quickstart-release-37.zap SHA-256:c3c13c5d128a30d73e029818b304f51deb87d634ea73dd1ad13481eb58b9f800 https://www.zaproxy.org/docs/desktop/addons/quick-start/ https://github.com/zaproxy/zap-extensions/ 2023-03-13 632915 2.12.0 callhome >= 0.0.1 network >= 0.3.0 reports >= 0.4.0 reflect Reflect Finds reflected parameters Caleb Kinney 0.0.11 reflect-alpha-0.0.11.zap alpha https://github.com/zaproxy/zap-extensions/releases/download/2.7/reflect-alpha-0.0.11.zap SHA-256:c45307037042e4079546a5fcb17d1165475e5cdd5ba7e8abc0d2cf0a14866466 2021-02-19 1780219 2.9.0 regextester Regular Expression Tester Allows to test Regular Expressions ZAP Dev Team 2 regextester-alpha-2.zap alpha <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> </ul> <h3>Fixed</h3> <ul> <li>Close dialogues when the add-on is uninstalled.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/regextester-v2/regextester-alpha-2.zap SHA-256:b4706709c16a45e8bedc0bd6f28dd09532d5dbf3f1fe2c2853e20dbf6160a584 https://www.zaproxy.org/docs/desktop/addons/regular-expression-tester/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 159441 2.11.0 replacer Replacer Easy way to replace strings in requests and responses. ZAP Dev Team 12 replacer-release-12.zap release <h3>Added</h3> <ul> <li>Added special replacement string processing for: <ul> <li>Random Integer</li> <li>UUID</li> <li>Epoch Milliseconds</li> </ul> </li> </ul> <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/replacer-v12/replacer-release-12.zap SHA-256:101ecc9964cb4111cc082ec7c7260eaf2aadf7867aec22c2e88d5888447a855e https://www.zaproxy.org/docs/desktop/addons/replacer/ https://github.com/zaproxy/zap-extensions/ 2023-01-03 347818 2.12.0 reports Report Generation Official ZAP Reports. ZAP Dev Team 0.22.0 reports-release-0.22.0.zap release <h3>Added</h3> <ul> <li>Automation job: support for sites (Issue 7858).</li> </ul> <h3>Fixed</h3> <ul> <li>Change SARIF's Base64 encoder to not rely on the default character encoding.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.22.0/reports-release-0.22.0.zap SHA-256:f3559d35696d552cfb5c1269826e91c9cb271b72c6698fae1febc72c69b5a31f https://www.zaproxy.org/docs/desktop/addons/report-generation/ https://github.com/zaproxy/zap-extensions/ 2023-06-12 67287477 2.12.0 requester Requester Allows to manually edit and send messages. Surikato and the ZAP Dev Team 7.2.0 requester-beta-7.2.0.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Allow to read HTTP/2 trailing headers.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/requester-v7.2.0/requester-beta-7.2.0.zap SHA-256:b5af96c6935f9ebbb93396ed0931b412a940728fe5ffd962115bd12022fef6e5 https://www.zaproxy.org/docs/desktop/addons/requester/ https://github.com/zaproxy/zap-extensions/ 2023-03-23 712182 2.12.0 retest Retest An add-on to retest for presence/absence of previously generated alerts. ZAP Dev Team 0.5.0 retest-alpha-0.5.0.zap alpha <h3>Changed</h3> <ul> <li>Include the HTTP version of the alerts' message when creating the <code>requestor</code> job.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/retest-v0.5.0/retest-alpha-0.5.0.zap SHA-256:ddba5597d583f28df5d908f0eae3a243a1697615d4c06846b94b125549342ae1 https://www.zaproxy.org/docs/desktop/addons/retest/ https://github.com/zaproxy/zap-extensions/ 2023-01-03 258076 2.12.0 automation >=0.20.0 retire Retire.js Retire.js Nikita Mundhada and the ZAP Dev Team 0.23.0 retire-release-0.23.0.zap release <h3>Changed</h3> <ul> <li>Updated with upstream retire.js pattern changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/retire-v0.23.0/retire-release-0.23.0.zap SHA-256:8e071e96498953c156b54c0213d5fdeb1973e6cbb7649c74abf8884fc8c50065 https://www.zaproxy.org/docs/desktop/addons/retire.js/ https://github.com/zaproxy/zap-extensions/ 2023-06-02 1218632 2.12.0 commonlib >= 1.13.0 & < 2.0.0 reveal Reveal Show hidden fields and enable disabled fields ZAP Dev Team 5 reveal-release-5.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/reveal-v5/reveal-release-5.zap SHA-256:6cf38bfb49427e6303a9cf7b674c24cf5f53ee8cc2e70bf3841cc0e373c18369 https://www.zaproxy.org/docs/desktop/addons/reveal/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 238237 2.12.0 revisit Revisit Revisit a site at any time in the past using the session history ZAP Dev Team 4 revisit-alpha-4.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> <li>Maintenance changes.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/revisit-v4/revisit-alpha-4.zap SHA-256:445bb2a98e06d4ecc945c35c2777dae1b1e5b6ea20de78b920c8004bc3615195 https://www.zaproxy.org/docs/desktop/addons/revisit/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 299864 2.11.0 saml SAML Support Detect, Show, Edit, Fuzz SAML requests ZAP Dev Team 10 saml-alpha-10.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/saml-v10/saml-alpha-10.zap SHA-256:097492271c7ec1d85def81091ffe897f4809927043844d1f5f0c7c598a0ad164 https://www.zaproxy.org/docs/desktop/addons/saml-support/ https://github.com/zaproxy/zap-extensions/ 2022-10-28 1811985 2.12.0 scripts Script Console Supports all JSR 223 scripting languages ZAP Dev Team 38 scripts-release-38.zap release <h3>Fixed</h3> <ul> <li>extender/Copy as curl command menu.js - prevent and warn on local file inclusion when generating the command. Thanks to James Kettle (@albinowax) for reporting.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/scripts-v38/scripts-release-38.zap SHA-256:140926287accfdab714b49c29a6a15c33783bc7bc38cd9ec4fd94ded76293ce6 https://www.zaproxy.org/docs/desktop/addons/script-console/ https://github.com/zaproxy/zap-extensions/ 2023-03-29 792337 2.12.0 selenium Selenium WebDriver provider and includes HtmlUnit browser ZAP Dev Team 15.12.1 selenium-release-15.12.1.zap release <h3>Fixed</h3> <ul> <li>Install Firefox extensions without using a profile (Issue 7878).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.12.1/selenium-release-15.12.1.zap SHA-256:f1506741fd69fc9749e4a03f629063f82fdac1bf4a7ff16f6823a21c2d8bb961 https://www.zaproxy.org/docs/desktop/addons/selenium/ https://github.com/zaproxy/zap-extensions/ 2023-05-26 24912992 2.12.0 network >=0.2.0 sequence Sequence Gives the possibility of defining a sequence of requests to be scanned. ZAP Dev Team 6 sequence-alpha-6.zap alpha <h3>Added</h3> <ul> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Issue 2000 - Updated strings shown in active scan dialog with title caps.</li> <li>Enable help button in Sequence tab of Active Scan dialog.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sequence-v6/sequence-alpha-6.zap SHA-256:2849204eab9ea1da50404ab9604e5ec69440c490453a24392c9a40bf95cdb164 https://www.zaproxy.org/docs/desktop/addons/sequence-scanner/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 1556476 2.11.0 zest soap SOAP Support Imports and scans WSDL files containing SOAP endpoints. Alberto (albertov91) + ZAP Dev Team 17 soap-beta-17.zap beta <h3>Added</h3> <ul> <li>Support for relative file paths and ones including vars in the Automation Framework job.</li> </ul> <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/soap-v17/soap-beta-17.zap SHA-256:7f9b12302368e2855aba909fdb6e65c757d4aef07bdf43e6f70a208ec1444baa https://www.zaproxy.org/docs/desktop/addons/soap-support/ https://github.com/zaproxy/zap-extensions/ 2023-02-09 12826438 2.12.0 commonlib >= 1.5.0 & < 2.0.0 spider Spider Spider used for automatically finding URIs on a site. ZAP Dev Team 0.4.0 spider-release-0.4.0.zap release <h3>Fixed</h3> <ul> <li>Set content-length even when body is empty, unless GET request.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/spider-v0.4.0/spider-release-0.4.0.zap SHA-256:7177a124f8064c8989817b9841e417dd236fc02533fe7ce2572fe770b4135195 https://www.zaproxy.org/docs/desktop/addons/spider/ https://github.com/zaproxy/zap-extensions/ 2023-05-03 1152803 2.12.0 commonlib >= 1.13.0 & < 2.0.0 database network >=0.3.0 spiderAjax Ajax Spider Allows you to spider sites that make heavy use of JavaScript using Crawljax ZAP Dev Team 23.14.1 spiderAjax-release-23.14.1.zap release <h3>Fixed</h3> <ul> <li>Handle job with no parameters when reading Excluded Elements (Issue 7889).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/spiderAjax-v23.14.1/spiderAjax-release-23.14.1.zap SHA-256:80da276b4942fb392e38c06d0c05060e006cfd1d91039692fa6f06b78947aafd https://www.zaproxy.org/docs/desktop/addons/ajax-spider/ https://github.com/zaproxy/zap-extensions/ 2023-06-02 5889470 2.12.0 commonlib >= 1.13.0 & < 2.0.0 network >=0.1.0 selenium 15.* sqliplugin Advanced SQLInjection Scanner An advanced active injection bundle for SQLi (derived by SQLMap) Andrea Pompili (Yhawke) 15 sqliplugin-beta-15.zap beta <h3>Fixed</h3> <ul> <li>Re-ordered variable initialization to prevent an NPE.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sqliplugin-v15/sqliplugin-beta-15.zap SHA-256:76e857bd2fea0b57b641862ea5bef46365ac1b03a19371c5e818a5401f7d9384 https://www.zaproxy.org/docs/desktop/addons/advanced-sqlinjection-scanner/ https://github.com/zaproxy/zap-extensions/ 2021-10-20 534349 2.11.0 commonlib >= 1.5.0 & < 2.0.0 sse Server-Sent Events Allows you to view Server-Sent Events (SSE) communication. ZAP Dev Team 12 sse-alpha-12.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/sse-v12/sse-alpha-12.zap SHA-256:c8805d497f71495e1d7fab7dfccf1955cc996ff514e6c0154e7937a72fdafc6c https://www.zaproxy.org/docs/desktop/addons/server-sent-events/ https://github.com/zaproxy/zap-extensions/ 2022-10-28 334645 2.12.0 svndigger SVN Digger Files SVN Digger files which can be used with ZAP forced browsing ZAP Dev Team 4 svndigger-release-4.zap release <h3>Added</h3> <ul> <li>Add help.</li> <li>Add repo URL.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Promote to release status.</li> <li>Change info URL to link to the site.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/svndigger-v4/svndigger-release-4.zap SHA-256:5556efdf3fdb84ebd6cf3e76ca31e3fb6fb57c002cf14b2cf2f05f67bf2b622a https://www.zaproxy.org/docs/desktop/addons/svn-digger-files/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 713963 2.11.0 tips Tips and Tricks Display ZAP Tips and Tricks ZAP Dev Team 10 tips-beta-10.zap beta <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.12.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/tips-v10/tips-beta-10.zap SHA-256:5fd165ff3384f31f070b34d5fd9f7c1dfe04a88298a340e418827aed923fc6f5 https://www.zaproxy.org/docs/desktop/addons/tips-and-tricks/ https://github.com/zaproxy/zap-extensions/ 2022-10-27 573495 2.12.0 tokengen Token Generation and Analysis Allows you to generate and analyze pseudo random tokens, such as those used for session handling or CSRF protection ZAP Dev Team 15 tokengen-beta-15.zap beta <h3>Changed</h3> <ul> <li>Now using 2.10 logging infrastructure (Log4j 2.x).</li> <li>Maintenance changes.</li> <li>Update minimum ZAP version to 2.11.0.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/tokengen-v15/tokengen-beta-15.zap SHA-256:daef1d13d44a76b8735a30ed9e1e50fa87a85d02728bd7ae575197d173f942f9 https://www.zaproxy.org/docs/desktop/addons/token-generator/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 525206 2.11.0 treetools TreeTools Tools to add functionality to the tree view. Carl Sampson 8 treetools-beta-8.zap beta <h3>Added</h3> <ul> <li>Add help.</li> <li>Add info and repo URLs.</li> </ul> <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/treetools-v8/treetools-beta-8.zap SHA-256:b7f61f8939937ebc120bce8deb72713d7676087056e88801df2573112e7642e4 https://www.zaproxy.org/docs/desktop/addons/treetools/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 128931 2.11.0 viewstate ViewState ASP/JSF ViewState Decoder and Editor Calum Hutton 3 viewstate-alpha-3.zap alpha <h3>Changed</h3> <ul> <li>Update minimum ZAP version to 2.11.0.</li> <li>Maintenance changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/viewstate-v3/viewstate-alpha-3.zap SHA-256:715caefd591415e79b32195361fea82aa8c6357b24e69530c22fde0a1b6dad17 https://www.zaproxy.org/docs/desktop/addons/viewstate/ https://github.com/zaproxy/zap-extensions/ 2021-10-07 148716 2.11.0 wappalyzer Wappalyzer - Technology Detection Technology detection using Wappalyzer: wappalyzer.com ZAP Dev Team 21.22.0 wappalyzer-release-21.22.0.zap release <h3>Changed</h3> <ul> <li>Updated with upstream Wappalyzer icon and pattern changes.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.22.0/wappalyzer-release-21.22.0.zap SHA-256:1cec5476c36edb18147dd2692912dbd7ef738e3d7e2569bbd38763b7f5ac6d59 https://www.zaproxy.org/docs/desktop/addons/technology-detection/ https://github.com/zaproxy/zap-extensions/ 2023-06-06 17970691 2.12.0 commonlib >= 1.7.0 & < 2.0.0 webdriverlinux Linux WebDrivers Linux WebDrivers for Firefox and Chrome. ZAP Dev Team 56 webdriverlinux-release-56.zap release <h3>Changed</h3> <ul> <li>Update ChromeDriver to 114.0.5735.90.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdriverlinux-v56/webdriverlinux-release-56.zap SHA-256:b0e35bb384bf38d8d954237e1b90cdaef68771e23f910d89d1dc13b03ea3d2d9 https://www.zaproxy.org/docs/desktop/addons/linux-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2023-06-01 16904847 2.12.0 webdrivermacos MacOS WebDrivers MacOS WebDrivers for Firefox and Chrome. ZAP Dev Team 56 webdrivermacos-release-56.zap release <h3>Changed</h3> <ul> <li>Update ChromeDriver to 114.0.5735.90.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdrivermacos-v56/webdrivermacos-release-56.zap SHA-256:9a17a55a6c75bf255b9ecaed9768c9895ddb1e650a970b5e7c8f37fff0d48b54 https://www.zaproxy.org/docs/desktop/addons/macos-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2023-06-01 20615638 2.12.0 webdriverwindows Windows WebDrivers Windows WebDrivers for Firefox and Chrome. ZAP Dev Team 55 webdriverwindows-release-55.zap release <h3>Changed</h3> <ul> <li>Update ChromeDriver to 114.0.5735.90.</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/webdriverwindows-v55/webdriverwindows-release-55.zap SHA-256:7db7f5eb4f11061bd81be220dc615299a82efa9999b54f23e06254a23e425842 https://www.zaproxy.org/docs/desktop/addons/windows-webdrivers/ https://github.com/zaproxy/zap-extensions/ 2023-06-01 10019996 2.12.0 websocket WebSockets Allows you to inspect WebSocket communication. ZAP Dev Team 28 websocket-release-28.zap release <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Prevent exception if no display (Issue 3978).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/websocket-v28/websocket-release-28.zap SHA-256:8d5eb20545f534a0631bb6c90a73c7ec75c19d4fe65741e275a2877383a89f61 https://www.zaproxy.org/docs/desktop/addons/websockets/ https://github.com/zaproxy/zap-extensions/ 2023-01-03 1403392 2.12.0 zest Zest - Graphical Security Scripting Language A graphical security scripting language, ZAPs macro language on steroids ZAP Dev Team 38 zest-beta-38.zap beta <h3>Changed</h3> <ul> <li>Maintenance changes.</li> </ul> <h3>Fixed</h3> <ul> <li>Prevent exception if no display (Issue 3978).</li> </ul> https://github.com/zaproxy/zap-extensions/releases/download/zest-v38/zest-beta-38.zap SHA-256:670c122b802fe548bc8a4f9d2c2b2a97f7ba5b7e607dc140d6d1b3917cc8d9b9 https://www.zaproxy.org/docs/desktop/addons/zest/ https://github.com/zaproxy/zap-extensions/ 2023-01-03 13582355 2.12.0 network >=0.2.0 scripts selenium 15.*