2.12.0
D-2021-10-18
https://github.com/zaproxy/zaproxy/releases/download/w2021-10-18/ZAP_WEEKLY_D-2021-10-18.zip
ZAP_WEEKLY_D-2021-10-18.zip
SHA-256:9d4bcb12e47293f3cbc4c32285b8469e620f092bb2519e65e12e5e528a25a8ad
188556676
https://github.com/zaproxy/zaproxy/releases/download/v2.12.0/ZAP_2_12_0_windows-x32.exe
ZAP_2_12_0_windows-x32.exe
SHA-256:fa741469190fd7d29ed870682a614535082a0c403450707c1359e79fe0cd0813
250469376
https://github.com/zaproxy/zaproxy/releases/download/v2.12.0/ZAP_2_12_0_windows.exe
ZAP_2_12_0_windows.exe
SHA-256:2dc7236c076dff9d35782fb85dbcfea1c57a63eca26ded15807ef2f62a0dcfd5
250598912
https://github.com/zaproxy/zaproxy/releases/download/v2.12.0/ZAP_2.12.0_Linux.tar.gz
ZAP_2.12.0_Linux.tar.gz
SHA-256:9c4493c991cb9347063864d2436a3795cf3b69760625e7b3db401cd342d3fc55
248228711
https://github.com/zaproxy/zaproxy/releases/download/v2.12.0/ZAP_2.12.0.dmg
ZAP_2.12.0.dmg
SHA-256:ca9ca8b8923a451d92372a37aa848d742836cf6a7ee94990bda701f2caa648fc
372161778
Bug fix and enhancement release.
https://www.zaproxy.org/docs/desktop/releases/2.12.0/
accessControl
Access Control Testing
Adds a set of tools for testing access control in web applications.
ZAP Dev Team
8
accessControl-alpha-8.zap
alpha
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/accessControl-v8/accessControl-alpha-8.zap
SHA-256:b46903f948e9cc57f9bd2be5402ad64858da6fb39359fa4b459d5e0836492d67
https://www.zaproxy.org/docs/desktop/addons/access-control-testing/
https://github.com/zaproxy/zap-extensions/
2022-10-28
596436
2.12.0
alertFilters
Alert Filters
Allows you to automate the changing of alert risk levels.
ZAP Dev Team
15
alertFilters-release-15.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevent exception if no display (Issue 3978).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/alertFilters-v15/alertFilters-release-15.zap
SHA-256:dd16791ffc3912ec6463da3a2e3b922eacb83ef60bee2098d4beca2d923c7cce
https://www.zaproxy.org/docs/desktop/addons/alert-filters/
https://github.com/zaproxy/zap-extensions/
2023-01-03
535740
2.12.0
allinonenotes
All In One Notes
A simple extension to view all notes in one pane.
David Vassallo
2
allinonenotes-alpha-2.zap
alpha
<h3>Added</h3>
<ul>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Update link to repository.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/allinonenotes-v2/allinonenotes-alpha-2.zap
SHA-256:9e70d6e76b72692e9c0cb64002a692b710710e688ea2d8834818086300632d2a
https://www.zaproxy.org/docs/desktop/addons/all-in-one-notes/
https://github.com/zaproxy/zap-extensions/
2021-10-07
249532
2.11.0
amf
AMF Support
Adds support for AMF messages
ZAP Dev Team
3
amf-alpha-3.zap
alpha
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/amf-v3/amf-alpha-3.zap
SHA-256:01345ea00a6623d794753a3210f4e3e2b50a8c4ce2bfa6ea57324f0ff01ad7e3
https://www.zaproxy.org/docs/desktop/addons/amf-support/
https://github.com/zaproxy/zap-extensions/
2021-10-07
911943
2.11.0
ascanrules
Active scanner rules
The release status Active Scanner rules
ZAP Dev Team
53
ascanrules-release-53.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>The SQL Injection Scan Rule filters reflected payload containing escaped characters like '&' and '"' before response content comparison to reduce false negatives.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/ascanrules-v53/ascanrules-release-53.zap
SHA-256:6658fd1b616a582c84909bd8c07cf6339f61d354da660983136e73a6286730c2
https://www.zaproxy.org/docs/desktop/addons/active-scan-rules/
https://github.com/zaproxy/zap-extensions/
2023-03-03
3129569
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
network
>= 0.3.0
oast
>= 0.7.0
ascanrulesAlpha
Active scanner rules (alpha)
The alpha status Active Scanner rules
ZAP Dev Team
42
ascanrulesAlpha-alpha-42.zap
alpha
<h3>Added</h3>
<ul>
<li>LDAP protocol technology support.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Preserve the HTTP version in Web Cache Deception scan rule.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Server Side Request Forgery Scan Rule.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesAlpha-v42/ascanrulesAlpha-alpha-42.zap
SHA-256:a75486ff0fae911e34e2e7b1504d0fb8bdcc9b35c887cc9681aafb4539041a47
https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-alpha/
https://github.com/zaproxy/zap-extensions/
2022-12-13
417060
2.12.0
commonlib
>= 1.9.0 & < 2.0.0
oast
>= 0.14.0
ascanrulesBeta
Active scanner rules (beta)
The beta status Active Scanner rules
ZAP Dev Team
45
ascanrulesBeta-beta-45.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>The Log4Shell scan rule alerts now include Alert References and Tags.</li>
<li>The Spring4Shell scan rule now includes a CVE Alert Tag and reference link.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Use same non-default port in the HTTP Only Site scan rule.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/ascanrulesBeta-v45/ascanrulesBeta-beta-45.zap
SHA-256:1360181ecefd77ddae76a0c1c9cbd7a4c8b725e090d3753675950ac463464f26
https://www.zaproxy.org/docs/desktop/addons/active-scan-rules-beta/
https://github.com/zaproxy/zap-extensions/
2023-03-03
1825186
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
database
>= 0.1.0
network
>= 0.3.0
oast
>= 0.7.0
attacksurfacedetector
Attack Surface Detector
The Attack Surface Detector analyzes web application source code to generate endpoints that can be used for penetration testing.
Secure Decisions (Matthew DeLetto)
1.1.4
attacksurfacedetector-alpha-1.1.4.zap
alpha
Various incremental changes (see https://github.com/secdec/attack-surface-detector-zap/releases)<br>
Fix un-handled exception when target unavailable & address various "house keeping" tasks.<br>
https://github.com/zaproxy/zap-extensions/releases/download/2.7/attacksurfacedetector-alpha-1.1.4.zap
SHA1:e21758c2cdcbc7806f44cc986a88360457eff82e
https://github.com/secdec/attack-surface-detector-zap/wiki
https://github.com/secdec/attack-surface-detector-zap/
2019-03-07
15604948
2.7.0
authhelper
Authentication Helper
Authentication Helper
ZAP Dev Team
0.3.0
authhelper-alpha-0.3.0.zap
alpha
<h3>Added</h3>
<ul>
<li>Support for browser based authentication.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/authhelper-v0.3.0/authhelper-alpha-0.3.0.zap
SHA-256:4ef594e28962982c1ab0a618e627e850fba64b55b2a8e3b8e45f20af38734bb5
https://www.zaproxy.org/docs/desktop/addons/authentication-helper/
https://github.com/zaproxy/zap-extensions/
2023-03-13
78423
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
network
>=0.6.0
selenium
15.*
authstats
Authentication Statistics
Records logged in/out statistics for all contexts in scope.
ZAP Dev Team
2
authstats-alpha-2.zap
alpha
<h3>Added</h3>
<ul>
<li>Add repo URL.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Dynamically unload the add-on.</li>
<li>Change info URL to link to the site.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/authstats-v2/authstats-alpha-2.zap
SHA-256:cfb604c27f3a7a58e7b5aa55fe9f19a9ce5561fab3ef7d3f6c72845671fb5dcf
https://www.zaproxy.org/docs/desktop/addons/authentication-statistics/
https://github.com/zaproxy/zap-extensions/
2021-10-07
247499
2.11.0
automation
Automation Framework
Automation Framework.
ZAP Dev Team
0.26.0
automation-beta-0.26.0.zap
beta
<h3>Added</h3>
<ul>
<li>Support for dynamically added browser based authentication.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/automation-v0.26.0/automation-beta-0.26.0.zap
SHA-256:0b8a36ffb0375beb4710f77bb224bf37427ffa609d295fa0f52e08fc5e3cadc6
https://www.zaproxy.org/docs/desktop/addons/automation-framework/
https://github.com/zaproxy/zap-extensions/
2023-03-18
4320485
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
beanshell
BeanShell Console
Provides a BeanShell Console
ZAP Dev Team
7
beanshell-beta-7.zap
beta
<h3>Added</h3>
<ul>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Maintenance changes.</li>
<li>Improve permissions and space handling when saving.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/beanshell-v7/beanshell-beta-7.zap
SHA-256:0a83cb7d0369ccef50768ccbda1e6c6d82b9f4e3bd9372b38fd32cc21f6a30fb
https://www.zaproxy.org/docs/desktop/addons/bean-shell/
https://github.com/zaproxy/zap-extensions/
2021-10-07
577838
2.11.0
browserView
Browser View
Adds an option to render HTML responses like a browser
ZAP Dev Team
6
browserView-alpha-6.zap
alpha
<h3>Added</h3>
<ul>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Maintenance changes.</li>
<li>Make missing JavaFX logging less verbose in regular use.</li>
<li>Update help with the requirements to use the add-on.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/browserView-v6/browserView-alpha-6.zap
SHA-256:e53cfde3a009a4be2e40c84ac02e05114505160bd2bab6cbb42416ab9a65b16c
https://www.zaproxy.org/docs/desktop/addons/browser-view/
https://github.com/zaproxy/zap-extensions/
2023-03-13
197667
2.12.0
bruteforce
Forced Browse
Forced browsing of files and directories using code from the OWASP DirBuster tool
ZAP Dev Team
12
bruteforce-beta-12.zap
beta
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/bruteforce-v12/bruteforce-beta-12.zap
SHA-256:4f1f59a27ee31994cb8fddf41059df5c5759f9e7e52a123cdbfee1a438533ab1
https://www.zaproxy.org/docs/desktop/addons/forced-browse/
https://github.com/zaproxy/zap-extensions/
2022-10-27
554080
2.12.0
bugtracker
Bug Tracker
Bug Tracker extension.
ZAP Dev Team
4
bugtracker-alpha-4.zap
alpha
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.1.</li>
<li>Dependency updates.</li>
<li>Maintenance changes.</li>
<li>Updated to use PAT not password (https://github.blog/changelog/2021-08-12-git-password-authentication-is-shutting-down/).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/bugtracker-v4/bugtracker-alpha-4.zap
SHA-256:37c57f8e7f4a1608500527ac1831f8b078427f804ea04ad5790a2970e3e1b722
https://www.zaproxy.org/docs/desktop/addons/bug-tracker/
https://github.com/zaproxy/zap-extensions/
2022-09-23
3707425
2.11.1
callgraph
Call Graph
Allows the user to view a call graph of the selected resources
Colm O'Flaherty
5
callgraph-alpha-5.zap
alpha
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/callgraph-v5/callgraph-alpha-5.zap
SHA-256:0874ce5aad0c4bbf28f72627a4940759d328396e12b7d6a5596f2e41bf24dc4e
https://www.zaproxy.org/docs/desktop/addons/call-graph/
https://github.com/zaproxy/zap-extensions/
2021-10-07
925930
2.11.0
callhome
Call Home
Handles all of the calls to ZAP services.
ZAP Dev Team
0.6.0
callhome-release-0.6.0.zap
release
<h3>Fixed</h3>
<ul>
<li>Include container field for CFUs.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/callhome-v0.6.0/callhome-release-0.6.0.zap
SHA-256:030facef0471ce4c63a40aedd2bd2eaa6768dff2bc61d66c68d9534a376edf47
https://www.zaproxy.org/docs/desktop/addons/call-home/
https://github.com/zaproxy/zap-extensions/
2022-12-02
320946
2.12.0
codedx
Code Dx Extension
Includes request and response data in XML reports and provides the ability to upload reports directly to a Code Dx server
Code Dx, Inc.
9
codedx-alpha-9.zap
alpha
<h3>Added</h3>
<ul>
<li>Add repo URL.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Change info URL to link to the site.</li>
<li>Maintenance changes.</li>
<li>Change to no longer rely on core report classes, which are going to be deleted.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/codedx-v9/codedx-alpha-9.zap
SHA-256:767e0a098de281f0bc880b036a5192f26fe0bb014b81227b385a0b63ca570428
https://www.zaproxy.org/docs/desktop/addons/code-dx/
https://github.com/zaproxy/zap-extensions/
2021-10-07
1769797
2.11.0
commonlib
Common Library
A common library, for use by other add-ons.
ZAP Dev Team
1.14.0
commonlib-release-1.14.0.zap
release
<h3>Fixed</h3>
<ul>
<li>Comparable Response functionality is now more robust and doesn't fail when processing types other than JSON Object (Issue 7736).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/commonlib-v1.14.0/commonlib-release-1.14.0.zap
SHA-256:3a658fd3bc9b3def39ad9efb90eecd8f661fa5ef7e7994c23420837efa3a6df1
https://www.zaproxy.org/docs/desktop/addons/common-library/
https://github.com/zaproxy/zap-extensions/
2023-02-24
4084762
2.12.0
communityScripts
Community Scripts
Useful ZAP scripts written by the ZAP community.
ZAP Community
15
communityScripts-alpha-15.zap
alpha
<h3>Added</h3>
<ul>
<li>active/RCE.py</li>
<li>active/SSTI.py</li>
<li>active/SSTI.js - An active scan script to check for SSTI in 14 different template engines.</li>
<li>httpfuzzerprocessor/addCacheBusting.js - Fuzzing with cache busting.</li>
<li>encode-decode
<ul>
<li>README.md - Summary of the script type.</li>
<li>double-spacer.js - A script that inserts a space after every character in a string.</li>
</ul>
</li>
<li>standalone/SecurityCrawlMazeScore.js</li>
<li>scan-hooks/LogMessagesHook.py and httpsender/LogMessages.js to help debugging, especially in docker.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>standalone/enableDebugLogging.js > Updated for more recent logging funtionality.</li>
<li>Update JS scripts to use passed singleton variables (control, model, view) if available (>= ZAP 2.12.0).</li>
<li>passive/Server Header Disclosure.js > Updated to check that the Server Header contains something that looks like a semantic version component.</li>
</ul>
https://github.com/zaproxy/community-scripts/releases/download/v15/communityScripts-alpha-15.zap
SHA-256:df178cb433864303dd9670fc4c66303db2ee88ee55e72621009f4d68d5bcec96
https://www.zaproxy.org/docs/desktop/addons/community-scripts/
https://github.com/zaproxy/community-scripts/
2022-10-02
459421
2.11.0
coreLang
Core Language Files
Translations of the core language files
ZAP Dev Team
15
coreLang-release-15.zap
release
<h3>Changed</h3>
<ul>
<li>Update the languages files from Crowdin.</li>
<li>Update minimum ZAP version to 2.11.1.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/coreLang-v15/coreLang-release-15.zap
SHA-256:d8258b914ffc95820dd045acf56677668a8cbbfc759290f72e30210056dfb88c
https://crowdin.com/project/owasp-zap
https://github.com/zaproxy/zap-extensions/
2022-02-14
4616009
2.11.1
custompayloads
Custom Payloads
Ability to add, edit or remove payloads that are used i.e. by active scanners
ZAP Dev Team
0.12.0
custompayloads-alpha-0.12.0.zap
alpha
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.11.1.</li>
<li>Add help content linking to the Scan Rules which support Custom Payloads.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/custompayloads-v0.12.0/custompayloads-alpha-0.12.0.zap
SHA-256:8e31acafdc1e2246e25953d8ccb87efa189a3fdadc596331feabeccc99dece65
https://www.zaproxy.org/docs/desktop/addons/custom-payloads/
https://github.com/zaproxy/zap-extensions/
2022-09-23
236404
2.11.1
database
Database
Provides database engines and related infrastructure.
ZAP Dev Team
0.1.0
database-alpha-0.1.0.zap
alpha
<h3>Added</h3>
<ul>
<li>Provides the SQLite database engine for other add-ons to use.</li>
<li>Support for the ZAP permanent database.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/database-v0.1.0/database-alpha-0.1.0.zap
SHA-256:587f1b2e2cac30c132a6c19092d2dc69c6c0472da4fea9a2048694a0aa239981
https://www.zaproxy.org/docs/desktop/addons/database/
https://github.com/zaproxy/zap-extensions/
2022-10-27
19560894
2.12.0
diff
Diff
Displays a dialog showing the differences between 2 requests or responses. It uses diffutils and diff_match_patch
ZAP Dev Team
12
diff-beta-12.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/diff-v12/diff-beta-12.zap
SHA-256:3367a087f6d14d990764cc8fd395424d81da2bb57e0020a819153ccf7cbeca35
https://www.zaproxy.org/docs/desktop/addons/diff/
https://github.com/zaproxy/zap-extensions/
2022-10-27
283039
2.12.0
directorylistv1
Directory List v1.0
List of directory names to be used with Forced Browse or Fuzzer add-on.
ZAP Dev Team
5
directorylistv1-release-5.zap
release
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/directorylistv1-v5/directorylistv1-release-5.zap
SHA-256:c1c0e14aac2ce203bdfd3a038f9b9dcf0b498f404936c3ff96e5a4614f611b9f
https://www.zaproxy.org/docs/desktop/addons/directory-list-v1.0/
https://github.com/zaproxy/zap-extensions/
2021-10-06
960428
2.11.0
directorylistv2_3
Directory List v2.3
Lists of directory names to be used with Forced Browse or Fuzzer add-on.
ZAP Dev Team
4
directorylistv2_3-release-4.zap
release
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add repo URL.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Change info URL to link to the site.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3-v4/directorylistv2_3-release-4.zap
SHA-256:3a8b04b9363b57acd9cf8cd67abce4c630f986e2b492a1ebd01eaa9587a0a199
https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3/
https://github.com/zaproxy/zap-extensions/
2021-10-07
8722229
2.11.0
directorylistv2_3_lc
Directory List v2.3 LC
Lists of lower case directory names to be used with Forced Browse or Fuzzer add-on.
ZAP Dev Team
4
directorylistv2_3_lc-release-4.zap
release
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add repo URL.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Change info URL to link to the site.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/directorylistv2_3_lc-v4/directorylistv2_3_lc-release-4.zap
SHA-256:2603580ba53673c31800ef7373e7cc09de759369b6f8fb43cc9e5024ad5d9af4
https://www.zaproxy.org/docs/desktop/addons/directory-list-v2.3-lc/
https://github.com/zaproxy/zap-extensions/
2021-10-07
7569974
2.11.0
domxss
DOM XSS Active scanner rule
DOM XSS Active scanner rule
Aabha Biyani, ZAP Dev Team
14
domxss-release-14.zap
release
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Promoted to Release status.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/domxss-v14/domxss-release-14.zap
SHA-256:6822a710a70d0ff2cfcfe3b2e7f07c776078fac17d4c6a8ad25126069611ffa1
https://www.zaproxy.org/docs/desktop/addons/dom-xss-active-scan-rule/
https://github.com/zaproxy/zap-extensions/
2022-10-27
271147
2.12.0
commonlib
>= 1.6.0 & < 2.0.0
network
>=0.1.0
selenium
15.*
encoder
Encoder
Adds encode/decode/hash dialog and support for scripted processors as well
ZAP Dev Team
1.1.0
encoder-release-1.1.0.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Added</h3>
<ul>
<li>A context menu active on the output text areas facilitating the replacement of input text.</li>
<li>PowerShell encoder (hat tip to hackvertor/hackvertor#71 for the idea and details).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/encoder-v1.1.0/encoder-release-1.1.0.zap
SHA-256:95243e1ea557a7e96d56f16e77a8cac6f71c8b6437ddbf4600e52470504577c2
https://www.zaproxy.org/docs/desktop/addons/encode-decode-hash/
https://github.com/zaproxy/zap-extensions/
2023-03-13
445128
2.12.0
evalvillain
Eval Villain
Adds the Eval Villain extension to Firefox when launched from ZAP.
Dennis Goodlett and the ZAP Dev Team
0.1.1
evalvillain-alpha-0.1.1.zap
alpha
<h3>Fixed</h3>
<ul>
<li>Fix the downloaded version of the Eval Villain Firefox extension.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/evalvillain-v0.1.1/evalvillain-alpha-0.1.1.zap
SHA-256:b0932f4f8fec19bf0dfae1dbe3668bbdadc6092707ea360216e37fdc8ae457cd
https://www.zaproxy.org/docs/desktop/addons/eval-villain/
https://github.com/zaproxy/zap-extensions/
2022-02-15
4943171
2.11.1
selenium
>=15.5.0
exim
Import/Export
Import and Export functionality
ZAP Dev Team & thatsn0tmysite
0.4.0
exim-beta-0.4.0.zap
beta
<h3>Added</h3>
<ul>
<li>Support for relative file paths and ones including vars in the Automation Framework job.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Show missing API endpoints' descriptions.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/exim-v0.4.0/exim-beta-0.4.0.zap
SHA-256:df4289fa691471fae1f49d3141ee67fc679191beb4f9581f39098871a9761dad
https://www.zaproxy.org/docs/desktop/addons/import-export/
https://github.com/zaproxy/zap-extensions/
2023-02-09
476728
2.12.0
commonlib
>= 1.8.0 & < 2.0.0
fileupload
FileUpload
Detect File upload requests and scan them to find related vulnerabilities
KSASAN preetkaran20@gmail.com
1.1.0
fileupload-alpha-1.1.0.zap
alpha
https://github.com/zaproxy/zap-extensions/releases/download/2.7/fileupload-alpha-1.1.0.zap
SHA-256:47f2d93c6a53c55983056af282ebef09e80d27c0980517a73347778ad9e47932
https://github.com/SasanLabs/owasp-zap-fileupload-addon/
2021-09-17
77520
2.11.0
formhandler
Form Handler
This Form Handler Add-on allows a user to define field names and values to be used in a form's fields. Fields can be added, modified, enabled, and deleted for use in form fields.
ZAP Dev Team
6.1.0
formhandler-beta-6.1.0.zap
beta
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>No longer provide the value generator through the core spider (Related to Issue 3113).</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/formhandler-v6.1.0/formhandler-beta-6.1.0.zap
SHA-256:c991b33bae9a4f2ebadbc81d216434a0d97da0434c44af1b70677ac0878fb34a
https://www.zaproxy.org/docs/desktop/addons/form-handler/
https://github.com/zaproxy/zap-extensions/
2022-10-27
2202857
2.12.0
fuzz
Fuzzer
Advanced fuzzer for manual testing
ZAP Dev Team
13.9.0
fuzz-beta-13.9.0.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevent exception if no display (Issue 3978).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/fuzz-v13.9.0/fuzz-beta-13.9.0.zap
SHA-256:5fae24e3586db435bd1a3156e1aebea36616e5a03571cfa86089546a581e525b
https://www.zaproxy.org/docs/desktop/addons/fuzzer/
https://github.com/zaproxy/zap-extensions/
2023-01-03
2001020
2.12.0
fuzzdb
FuzzDB Files
FuzzDB files which can be used with the ZAP fuzzer
ZAP Dev Team
9
fuzzdb-release-9.zap
release
<h3>Changed</h3>
<ul>
<li>Updated RAFT lists based on more recent SecLists contributions</li>
<li>Update minimum ZAP version to 2.11.1.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/fuzzdb-v9/fuzzdb-release-9.zap
SHA-256:c79537362cd6b383f447359685e3bd51795600b97ca0c1fadc4ba74828a7d4f4
https://www.zaproxy.org/docs/desktop/addons/fuzzdb-files/
https://github.com/zaproxy/zap-extensions/
2022-09-23
6167205
2.11.1
fuzzdboffensive
FuzzDB Offensive
FuzzDB web backdoors and attack files which can be used with the ZAP fuzzer or for manual penetration testing
ZAP Dev Team
4
fuzzdboffensive-release-4.zap
release
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.10.0.</li>
</ul>
https://github.com/zaproxy/fuzzdb-offensive/releases/download/v4/fuzzdboffensive-release-4.zap
SHA-256:06bf75d2745c8f6e9a861597a31bab2d3f96058a3c497539a3ba234c687e796a
https://www.zaproxy.org/docs/desktop/addons/fuzzdb-offensive/
https://github.com/zaproxy/fuzzdb-offensive/
2021-06-11
414373
2.10.0
gettingStarted
Getting Started with ZAP Guide
A short Getting Started with ZAP Guide
ZAP Dev Team
14
gettingStarted-release-14.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Added note about Firefox's Enhanced Tracking Protection.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/gettingStarted-v14/gettingStarted-release-14.zap
SHA-256:83a8aca931746122bdd89c651f0bd70f695b609167d94b9194de3b7f9ec1a841
https://www.zaproxy.org/docs/desktop/addons/getting-started-guide/
https://github.com/zaproxy/zap-extensions/
2022-10-27
796000
2.12.0
graaljs
GraalVM JavaScript
Provides the GraalVM JavaScript engine for ZAP scripting.
ZAP Dev Team
0.3.0
graaljs-alpha-0.3.0.zap
alpha
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Declare the engine is single threaded (Issue 6992).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/graaljs-v0.3.0/graaljs-alpha-0.3.0.zap
SHA-256:c16a2c0b94192ed929b9b38d81f4b06a00286a0fbefd8b575be352c3e42f68be
https://github.com/zaproxy/zap-extensions/
2022-10-27
20440986
2.12.0
graphql
GraphQL Support
Inspect and attack GraphQL endpoints.
ZAP Dev Team
0.13.0
graphql-alpha-0.13.0.zap
alpha
<h3>Added</h3>
<ul>
<li>Support for relative file paths in the Automation Framework job.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Dependency updates and maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Fixed exception in the variant when POST message has empty body and no content-type (Issue 7689).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/graphql-v0.13.0/graphql-alpha-0.13.0.zap
SHA-256:6dbed7b91247ff626042187294e2cb9a62c3b0fb25454eeabe12a1b763d7f417
https://www.zaproxy.org/docs/desktop/addons/graphql-support/
https://github.com/zaproxy/zap-extensions/
2023-02-09
5494716
2.12.0
groovy
Groovy Support
Adds Groovy support to ZAP
ZAP Dev Team
3.1.0
groovy-beta-3.1.0.zap
beta
<h3>Added</h3>
<ul>
<li>encode-decode default template.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update links to zaproxy and zap-extensions repos.</li>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/groovy-v3.1.0/groovy-beta-3.1.0.zap
SHA-256:ee208309c6b9619f6527a05f48949e38e1476f2b3fa7c6e32fbd1111f4bdac58
https://www.zaproxy.org/docs/desktop/addons/groovy-support/
https://github.com/zaproxy/zap-extensions/
2021-10-07
19006812
2.11.0
help
Help - English
English version of the ZAP help file.
ZAP Crowdin Team
15
help-release-15.zap
release
<h3>Changed</h3>
<ul>
<li>Updated for 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help-v15/help-release-15.zap
SHA-256:8db85b4f0fedb8b2fa56578222f1a76b2b48029e2d2e360a9659826241ebfaa6
https://www.zaproxy.org/docs/desktop/
https://github.com/zaproxy/zap-core-help/
2022-10-27
611954
2.10.0
help_ar_SA
Help - Arabic
Arabic version of the ZAP help file.
ZAP Crowdin Team
1
help_ar_SA-alpha-1.zap
alpha
<ul>
<li>First version.</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_ar_SA-v1/help_ar_SA-alpha-1.zap
SHA-256:8208b0c788d5e29a2bb34f3c44c07db613faefb17d8d9cfb60adc02629c2b3f1
https://github.com/zaproxy/zap-core-help/
2022-01-18
649333
2.11.0
help_bs_BA
Help - Bosnian
Bosnian version of the ZAP help file.
ZAP Crowdin Team
9
help_bs_BA-alpha-9.zap
alpha
Updated with the latest files from crowdin
https://github.com/zaproxy/zap-extensions/releases/download/2.7/help_bs_BA-alpha-9.zap
SHA1:d33a3277e877da4734e6bf9c911c61c4e6ce2f3f
2018-02-08
747536
2.7.0
help_es_ES
Help - Spanish
Spanish version of the ZAP help file.
ZAP Crowdin Team
10
help_es_ES-release-10.zap
release
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_es_ES-v10/help_es_ES-release-10.zap
SHA-256:63cc24e180374cf038d6aefe31b3f62e170437958ad61d2d3e65d2722fbedc1a
https://github.com/zaproxy/zap-core-help/
2022-01-18
697066
2.11.0
help_fil_PH
Help - Filipino
Filipino version of the ZAP help file.
ZAP Crowdin Team
3
help_fil_PH-alpha-3.zap
alpha
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_fil_PH-v3/help_fil_PH-alpha-3.zap
SHA-256:64bbeb0f9404b70c0d49e9fd5da789b8d3902a20f518c7305eb412242831a180
https://github.com/zaproxy/zap-core-help/
2022-01-18
710027
2.11.0
help_fr_FR
Help - French
French version of the ZAP help file.
ZAP Crowdin Team
10
help_fr_FR-alpha-10.zap
alpha
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_fr_FR-v10/help_fr_FR-alpha-10.zap
SHA-256:f1ede9441e5de48170fdef598eb543ef6ad0813eed2e838d2c4803ea114fcb1a
https://github.com/zaproxy/zap-core-help/
2022-01-18
646717
2.11.0
help_id_ID
Help - Indonesian
Indonesian version of the ZAP help file.
ZAP Crowdin Team
3
help_id_ID-beta-3.zap
beta
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_id_ID-v3/help_id_ID-beta-3.zap
SHA-256:ef50363872d783c3c49417bc821b28256cf35d8390004c48f6d4e030ceb8a7c5
https://github.com/zaproxy/zap-core-help/
2022-01-18
671009
2.11.0
help_ja_JP
Help - Japanese
Japanese version of the ZAP help file.
ZAP Crowdin Team
10
help_ja_JP-beta-10.zap
beta
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_ja_JP-v10/help_ja_JP-beta-10.zap
SHA-256:11d310352e8719fe50587c5b97dd5eeb3a2e2ab23e450a7c1d0fad013d003536
https://github.com/zaproxy/zap-core-help/
2022-01-18
661964
2.11.0
help_ms_MY
Help - Malay
Malay version of the ZAP help file.
ZAP Crowdin Team
1
help_ms_MY-alpha-1.zap
alpha
<ul>
<li>First version.</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_ms_MY-v1/help_ms_MY-alpha-1.zap
SHA-256:6407990b8ebaa2e401c3addc47081c742ab7fce25cec107ef49b4e627ad3ceae
https://github.com/zaproxy/zap-core-help/
2022-01-18
636908
2.11.0
help_pt_BR
Help - Portuguese, Brazilian
Portuguese, Brazilian version of the ZAP help file.
ZAP Crowdin Team
11
help_pt_BR-release-11.zap
release
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_pt_BR-v11/help_pt_BR-release-11.zap
SHA-256:3fdf92763c1c851848df6b3588c97bbeb22837002351fd00c8208d8ab01ff710
https://github.com/zaproxy/zap-core-help/
2022-01-18
682092
2.11.0
help_ru_RU
Help - Russian
Russian version of the ZAP help file.
ZAP Crowdin Team
2
help_ru_RU-release-2.zap
release
<h3>Changed</h3>
<ul>
<li>Promote to Release</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_ru_RU-v2/help_ru_RU-release-2.zap
SHA-256:3fd5d8e6af7453a3a16e7c38a19ec941a330d0fd050f562ecebdc4638ae52c80
https://github.com/zaproxy/zap-core-help/
2022-02-24
779171
2.11.0
help_tr_TR
Help - Turkish
Turkish version of the ZAP help file.
ZAP Crowdin Team
2
help_tr_TR-release-2.zap
release
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_tr_TR-v2/help_tr_TR-release-2.zap
SHA-256:a92b43beab5e196341d8ddf40d594f1596c225c74f0f5b9280e223acc9a8535c
https://github.com/zaproxy/zap-core-help/
2022-01-18
710766
2.11.0
help_zh_CN
Help - Chinese Simplified
Chinese Simplified version of the ZAP help file.
ZAP Crowdin Team
3
help_zh_CN-beta-3.zap
beta
<h3>Changed</h3>
<ul>
<li>Updated with the latest files from crowdin</li>
</ul>
https://github.com/zaproxy/zap-core-help/releases/download/help_zh_CN-v3/help_zh_CN-beta-3.zap
SHA-256:959b718a307ca32c7807c0d327533765eeb6a0a799b9bc98a2a1e22b3b47bc5a
https://github.com/zaproxy/zap-core-help/
2022-01-18
656718
2.11.0
highlighter
Highlighter
Allows you to highlight strings in the request and response tabs.
ZAP Dev Team
8
highlighter-alpha-8.zap
alpha
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/highlighter-v8/highlighter-alpha-8.zap
SHA-256:4c4852bb2f42eb20dbe19a091e9025667947c73967a65770658333bedd01fccf
https://www.zaproxy.org/docs/desktop/addons/highlighter/
https://github.com/zaproxy/zap-extensions/
2021-10-07
115527
2.11.0
hud
HUD - Heads Up Display
Display information from ZAP in browser.
ZAP Dev Team
0.16.0
hud-beta-0.16.0.zap
beta
<h3>Added</h3>
<ul>
<li>Added Clear Button to History and WebSockets Tab (Issue 411).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevent exception if no display (Issue 3978).</li>
</ul>
https://github.com/zaproxy/zap-hud/releases/download/v0.16.0/hud-beta-0.16.0.zap
SHA-256:a4c61217077abfc4ad162f7b3908454f88284c0f57706cc63c2bc1611b9883e2
https://www.zaproxy.org/docs/desktop/addons/hud/
https://github.com/zaproxy/zap-hud/
2023-01-25
1368604
2.12.0
network
>= 0.1.0
websocket
imagelocationscanner
Image Location and Privacy Scanner
Image Location and Privacy Passive Scanner
Jay Ball (veggiespam) and the ZAP Dev Team
4
imagelocationscanner-beta-4.zap
beta
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.1.</li>
<li>Maintenance changes.</li>
</ul>
<h3>Added</h3>
<ul>
<li>OWASP Web Security Testing Guide v4.2 mappings.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/imagelocationscanner-v4/imagelocationscanner-beta-4.zap
SHA-256:6d168e4d156335a0544619011b742e47e6dc1d492a2d63a0e8f787b28796b2c9
https://www.zaproxy.org/docs/desktop/addons/image-location-and-privacy-scanner/
https://github.com/zaproxy/zap-extensions/
2022-09-23
1138093
2.11.1
commonlib
>= 1.6.0 & < 2.0.0
invoke
Invoke Applications
Invoke external applications passing context related information such as URLs and parameters
ZAP Dev Team
12
invoke-beta-12.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/invoke-v12/invoke-beta-12.zap
SHA-256:ee1461a3f2f82165bcc2c4050c99daf22ead9f28506ecfa190a10e14f7f3c9c3
https://www.zaproxy.org/docs/desktop/addons/invoke-applications/
https://github.com/zaproxy/zap-extensions/
2022-10-27
325970
2.12.0
jruby
Ruby Scripting
Allows Ruby to be used for ZAP scripting - templates included
ZAP Dev Team
8
jruby-beta-8.zap
beta
<h3>Changed</h3>
<ul>
<li>Update links to zaproxy repo.</li>
<li>Rename reliability to confidence in active/passive templates.</li>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/jruby-v8/jruby-beta-8.zap
SHA-256:f5bb450a165f6c407b8d24f7b2776bdc7a2edb0b4b42aea385f8a6ad1ae605ca
https://www.zaproxy.org/docs/desktop/addons/ruby-scripting/
https://github.com/zaproxy/zap-extensions/
2021-10-07
21968128
2.11.0
jsonview
JSON View
Adds a view that shows JSON messages nicely formatted
Juha Kivekäs
2
jsonview-alpha-2.zap
alpha
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add the main context menu to the JSON view.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Capitalize the view dropdown menu entry (related to Issue 2000).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/jsonview-v2/jsonview-alpha-2.zap
SHA-256:49fd8995eac7724e5a60f7b6d7f10cfb617f3f083b6f23406075631ba23c7ebc
https://www.zaproxy.org/docs/desktop/addons/json-view/
https://github.com/zaproxy/zap-extensions/
2021-10-07
119886
2.11.0
jwt
JWT Support
Detect JWT requests and scan them to find related vulnerabilities
KSASAN preetkaran20@gmail.com
1.0.3
jwt-alpha-1.0.3.zap
alpha
<ul>
<li>First version of JWT Support.
<ul>
<li>Contains scanning rules for basic JWT related vulnerabilities.</li>
<li>Contains JWT Fuzzer for fuzzing the JWT's present in the request.</li>
</ul>
</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/2.7/jwt-alpha-1.0.3.zap
SHA-256:d3df8480010ad2df230cbdb99619aafdb869861349455c3da0129a99b132d204
https://github.com/SasanLabs/owasp-zap-jwt-addon/
2023-01-02
751748
2.11.1
commonlib
fuzz
13.*
jython
Python Scripting
Allows Python to be used for ZAP scripting - templates included
ZAP Dev Team
12
jython-beta-12.zap
beta
<h3>Added</h3>
<ul>
<li>encode-decode default and rot13 templates.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update links to zaproxy repo.</li>
<li>Rename reliability to confidence in active/passive templates.</li>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/jython-v12/jython-beta-12.zap
SHA-256:4519b862edf8f006c429c86b0152ade561b660ae6f74cfce684b272f4fe28ef1
https://www.zaproxy.org/docs/desktop/addons/python-scripting/
https://github.com/zaproxy/zap-extensions/
2021-10-07
43312397
2.11.0
kotlin
Kotlin Support
Allows Kotlin to be used for ZAP scripting
StackHawk Engineering
1.1.0
kotlin-alpha-1.1.0.zap
alpha
<h3>Changed</h3>
<ul>
<li>Use appropriate syntax style for highlighting of code.</li>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/kotlin-v1.1.0/kotlin-alpha-1.1.0.zap
SHA-256:85a47ea7199b77cfb09081302c277de2ba5e2102ef79907573ebcfa6425302e9
https://www.zaproxy.org/docs/desktop/addons/kotlin-support/
https://github.com/zaproxy/zap-extensions/
2021-10-07
48865539
2.11.0
levoai
Levo.ai
Build OpenAPI Specs with ZAP traffic using Levo.ai.
Levo.ai
0.2.0
levoai-zap-addon-alpha-0.2.0.zap
alpha
<h3>Added</h3>
<ul>
<li>Validate the Satellite URL structure when it is modified.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>URLs with '/' as the path were not being handled correctly.</li>
</ul>
https://github.com/levoai/levoai-zap-addon/releases/download/v0.2.0/levoai-zap-addon-alpha-0.2.0.zap
SHA-256:28777022d50fa8ff29ef21ab94d01786d4936dcf6ddc9303e64f52983203311d
https://docs.levo.ai/api-observability/quickstart/quickstart-zap-addon
https://github.com/levoai/levoai-zap-addon
2022-12-26
2459871
2.12.0
neonmarker
Neonmarker
Colors history table items based on tags
Juha Kivekäs, Kingthorin
1.5.0
neonmarker-alpha-1.5.0.zap
alpha
<h3>Added</h3>
<ul>
<li>A right-click context menu is now available in the History tab in order to Select/Set a color for arbitrary messages.</li>
</ul>
https://github.com/kingthorin/neonmarker/releases/download/v1.5.0/neonmarker-alpha-1.5.0.zap
SHA-256:0b888612670e66712001d0bd3cb990d7b34f88b7b6339aed2734083b8a5fe5c5
https://www.zaproxy.org/docs/desktop/addons/neonmarker/
https://github.com/kingthorin/neonmarker
2022-07-11
35903
2.10.0
network
Network
Provides core networking capabilities.
ZAP Dev Team
0.6.0
network-beta-0.6.0.zap
beta
<h3>Changed</h3>
<ul>
<li>Allow access to the ZAP API when running in command line mode.</li>
<li>Fallback to HTTP/1.1 in internal local servers/proxies if the client does not negotiate a protocol (ALPN).</li>
<li>Dynamically unload the add-on on newer core versions.</li>
<li>Update dependencies.</li>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Use always a plain connection to the outgoing HTTP proxy (Issue 7594).</li>
<li>Do not change the case of the Content-Length header.</li>
<li>Use the available response content when the Content-Length is more than what is available.</li>
<li>Properly persist proxy error responses.</li>
<li>Correctly manage cookies with domain and path attributes (Issue 7631).</li>
<li>Do not prevent serving internal requests to the local servers/proxies.</li>
<li>Consume the response body even when none expected (e.g. 204, HEAD), otherwise the previous body
would not be cleared when reusing the same message.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/network-v0.6.0/network-beta-0.6.0.zap
SHA-256:e3f36060c37d086d04dd2d0884e80c37b7a30555ee48c19dd89e42846d8a92b8
https://www.zaproxy.org/docs/desktop/addons/network/
https://github.com/zaproxy/zap-extensions/
2023-01-03
27350988
2.12.0
oast
OAST Support
Allows you to exploit out-of-band vulnerabilities
ZAP Dev Team
0.15.0
oast-beta-0.15.0.zap
beta
<h3>Added</h3>
<ul>
<li>A context menu to paste payloads from all the supported OAST services (Issue 7665).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/oast-v0.15.0/oast-beta-0.15.0.zap
SHA-256:472c4e387057d88365885345e2e254b930928e84f2eae12fe725e0cfcc9590c8
https://www.zaproxy.org/docs/desktop/addons/oast-support/
https://github.com/zaproxy/zap-extensions/
2023-03-13
806224
2.12.0
database
>= 0.1.0
network
>= 0.1.0
onlineMenu
Online menus
ZAP Online menu items
ZAP Dev Team
10
onlineMenu-release-10.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/onlineMenu-v10/onlineMenu-release-10.zap
SHA-256:e621aadb1d686243e1463344b128573cb9857c4118cf41ddb7be7c584fdd0ed9
https://www.zaproxy.org/docs/desktop/addons/online-menu/
https://github.com/zaproxy/zap-extensions/
2022-10-27
209008
2.12.0
openapi
OpenAPI Support
Imports and spiders OpenAPI definitions.
ZAP Dev Team plus Joanna Bona, Nathalie Bouchahine, Artur Grzesica, Mohammad Kamar, Markus Kiss, Michal Materniak, Marcin Spiewak, and SDA SE Open Industry Solutions
32
openapi-beta-32.zap
beta
<h3>Added</h3>
<ul>
<li>Support for relative file paths and ones including vars in the Automation Framework job.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/openapi-v32/openapi-beta-32.zap
SHA-256:e1e6c5181e89726a248c1b3fa51c9a2cc4e7964bbf2730c171e7c90a53cda954
https://www.zaproxy.org/docs/desktop/addons/openapi-support/
https://github.com/zaproxy/zap-extensions/
2023-02-09
12827393
2.12.0
commonlib
>= 1.8.0 & < 2.0.0
packpentester
Collection: Pentester Pack
A collection of add-ons ideal for pentesters
ZAP Dev Team
0.1.0
packpentester-alpha-0.1.0.zap
alpha
<h3>Fixed</h3>
<ul>
<li>Corrected fuzz add-on name</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/packpentester-v0.1.0/packpentester-alpha-0.1.0.zap
SHA-256:0b8e7e4ddffdcacf46fdf9793bf84217738e281cbd5ccac732788c4b768d069c
https://www.zaproxy.org/docs/desktop/addons/collection-pentester-pack/
https://github.com/zaproxy/zap-extensions/
2022-05-12
6792
2.11.1
accessControl
attacksurfacedetector
custompayloads
evalvillain
fileupload
fuzz
fuzzdb
jsonview
jwt
requester
viewstate
wappalyzer
packscanrules
Collection: Scan Rules Pack
All of the add-ons just containing release, beta and alpha status scan rules
ZAP Dev Team
0.0.1
packscanrules-alpha-0.0.1.zap
alpha
<p>First version.</p>
https://github.com/zaproxy/zap-extensions/releases/download/packscanrules-v0.0.1/packscanrules-alpha-0.0.1.zap
SHA-256:5ad68f153379bd96f36a7bead61e884cc42e1409cdd262dffc682b5f7bf92da4
https://www.zaproxy.org/docs/desktop/addons/collection-scan-rules-pack/
https://github.com/zaproxy/zap-extensions/
2022-05-13
9244
2.11.1
ascanrules
ascanrulesAlpha
ascanrulesBeta
domxss
pscanrules
pscanrulesAlpha
pscanrulesBeta
retire
paramdigger
Parameter Digger
Identify hidden, unlinked parameters. Useful for finding web cache poisoning vulnerabilities.
ZAP Dev Team and Arkaprabha Chakraborty
0.1.0
paramdigger-alpha-0.1.0.zap
alpha
<h3>Changed</h3>
<ul>
<li>Rename multiple options in GUI and documentation.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/paramdigger-v0.1.0/paramdigger-alpha-0.1.0.zap
SHA-256:29ab753e092b42a546fb83fefcb8d952af745e6ba98d647099c7d0185af13eee
https://www.zaproxy.org/docs/desktop/addons/parameter-digger/
https://github.com/zaproxy/zap-extensions/
2022-08-22
522848
2.11.1
commonlib
>= 1.9.0 & < 2.0.0
plugnhack
Plug-n-Hack Configuration
Supports the Mozilla Plug-n-Hack standard: https://developer.mozilla.org/en-US/docs/Plug-n-Hack.
ZAP Dev Team
13
plugnhack-beta-13.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Use Network add-on to obtain main proxy address/port.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/plugnhack-v13/plugnhack-beta-13.zap
SHA-256:8d74b572bb7e08d09ebcfd10da9f2f65f7970f9452feadb8bbe69c8037b80ee2
https://www.zaproxy.org/docs/desktop/addons/plug-n-hack/
https://github.com/zaproxy/zap-extensions/
2022-10-27
736005
2.12.0
network
>= 0.2.0
portscan
Port Scanner
Allows to port scan a target server
ZAP Dev Team
10
portscan-beta-10.zap
beta
<h3>Changed</h3>
<ul>
<li>Use the Network add-on to obtain the outgoing proxy.</li>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/portscan-v10/portscan-beta-10.zap
SHA-256:6cf0432e1c329499649b219d2f00e7ec7bc2079d7160396fecb9a8ad3446b963
https://www.zaproxy.org/docs/desktop/addons/port-scan/
https://github.com/zaproxy/zap-extensions/
2022-10-27
724563
2.12.0
network
>=0.3.0
pscanrules
Passive scanner rules
The release status Passive Scanner rules
ZAP Dev Team
46
pscanrules-release-46.zap
release
<h3>Changed</h3>
<ul>
<li>The PII Disclosure scan rule:
<ul>
<li>Now includes a solution statement.</li>
<li>Now more specifically portrays alert Evidence.</li>
<li>Now includes example alert functionality for documentation generation purposes (Issue 6119).</li>
<li>Will now only consider PDFs at Low threshold.</li>
</ul>
</li>
<li>Maintenance changes.</li>
<li>The HeartBleed scan rule alert now includes a CVE tag.</li>
<li>Timestamp Disclosure scan rule now excludes values in "RateLimit-Reset", "X-RateLimit-Reset", and "X-Rate-Limit-Reset" headers (Issue 7747).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>The CSP Missing scan rule now alerts when the Content-Security-Policy header is missing, and when the obsolete X-Content-Security-Policy or X-WebKit-CSP are found (Issue 7653).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/pscanrules-v46/pscanrules-release-46.zap
SHA-256:a4c24491dfee9b6b929335ba52992845fe5589d466755d810c268a7ea5cec6ff
https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules/
https://github.com/zaproxy/zap-extensions/
2023-03-03
1842272
2.12.0
commonlib
>= 1.10.0 & < 2.0.0
pscanrulesAlpha
Passive scanner rules (alpha)
The alpha status Passive Scanner rules
ZAP Dev Team
38
pscanrulesAlpha-alpha-38.zap
alpha
<h3>Fixed</h3>
<ul>
<li>Use case insensitive HTTP field name check in Insufficient Site Isolation Against Spectre Vulnerability scan rule.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesAlpha-v38/pscanrulesAlpha-alpha-38.zap
SHA-256:d1f296411d7645c0e53fa3e843e3fb66d5b0e2a7f4ba383c3c9a8b8d5859fcec
https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-alpha/
https://github.com/zaproxy/zap-extensions/
2023-03-03
444740
2.12.0
commonlib
>= 1.10.0 & < 2.0.0
pscanrulesBeta
Passive scanner rules (beta)
The beta status Passive Scanner rules
ZAP Dev Team
32
pscanrulesBeta-beta-32.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>The Cacheable scan rule should now be more tolerant when parsing s-max-age values.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/pscanrulesBeta-v32/pscanrulesBeta-beta-32.zap
SHA-256:8445ae5653b895d2dfc31a0828f6d27db82558ccd916b96b0dec09a775df94dc
https://www.zaproxy.org/docs/desktop/addons/passive-scan-rules-beta/
https://github.com/zaproxy/zap-extensions/
2023-03-03
574875
2.12.0
commonlib
>= 1.10.0 & < 2.0.0
quickstart
Quick Start
Provides a tab which allows you to quickly test a target application
ZAP Dev Team
37
quickstart-release-37.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Show correct error message when unable to access the provided URL, also, add the scheme if none provided.</li>
<li>Ensure the add-on is not in use before uninstalling.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/quickstart-v37/quickstart-release-37.zap
SHA-256:c3c13c5d128a30d73e029818b304f51deb87d634ea73dd1ad13481eb58b9f800
https://www.zaproxy.org/docs/desktop/addons/quick-start/
https://github.com/zaproxy/zap-extensions/
2023-03-13
632915
2.12.0
callhome
>= 0.0.1
network
>= 0.3.0
reports
>= 0.4.0
reflect
Reflect
Finds reflected parameters
Caleb Kinney
0.0.11
reflect-alpha-0.0.11.zap
alpha
https://github.com/zaproxy/zap-extensions/releases/download/2.7/reflect-alpha-0.0.11.zap
SHA-256:c45307037042e4079546a5fcb17d1165475e5cdd5ba7e8abc0d2cf0a14866466
2021-02-19
1780219
2.9.0
regextester
Regular Expression Tester
Allows to test Regular Expressions
ZAP Dev Team
2
regextester-alpha-2.zap
alpha
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Close dialogues when the add-on is uninstalled.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/regextester-v2/regextester-alpha-2.zap
SHA-256:b4706709c16a45e8bedc0bd6f28dd09532d5dbf3f1fe2c2853e20dbf6160a584
https://www.zaproxy.org/docs/desktop/addons/regular-expression-tester/
https://github.com/zaproxy/zap-extensions/
2021-10-07
159441
2.11.0
replacer
Replacer
Easy way to replace strings in requests and responses.
ZAP Dev Team
12
replacer-release-12.zap
release
<h3>Added</h3>
<ul>
<li>Added special replacement string processing for:
<ul>
<li>Random Integer</li>
<li>UUID</li>
<li>Epoch Milliseconds</li>
</ul>
</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/replacer-v12/replacer-release-12.zap
SHA-256:101ecc9964cb4111cc082ec7c7260eaf2aadf7867aec22c2e88d5888447a855e
https://www.zaproxy.org/docs/desktop/addons/replacer/
https://github.com/zaproxy/zap-extensions/
2023-01-03
347818
2.12.0
reports
Report Generation
Official ZAP Reports.
ZAP Dev Team
0.19.0
reports-release-0.19.0.zap
release
<h3>Added</h3>
<ul>
<li>A description of riskdesc fields in the relevant report templates' help (Issue 7445).</li>
<li>Support for relative report file and directory names in the Automation Framework job.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/reports-v0.19.0/reports-release-0.19.0.zap
SHA-256:658d5e9e2291fe4ba6bdf287262c2864d8f54ce6ffeb10180001f7037621c6d3
https://www.zaproxy.org/docs/desktop/addons/report-generation/
https://github.com/zaproxy/zap-extensions/
2023-02-09
67262733
2.12.0
requester
Requester
Allows to manually edit and send messages.
Surikato and the ZAP Dev Team
7.1.0
requester-beta-7.1.0.zap
beta
<h3>Added</h3>
<ul>
<li>Find control in footer</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/requester-v7.1.0/requester-beta-7.1.0.zap
SHA-256:f30bd0ca2c85175e95fc6affaf0483a0a4d68567860936d737e87d5c8f8d95e8
https://www.zaproxy.org/docs/desktop/addons/requester/
https://github.com/zaproxy/zap-extensions/
2022-12-19
701190
2.12.0
retest
Retest
An add-on to retest for presence/absence of previously generated alerts.
ZAP Dev Team
0.5.0
retest-alpha-0.5.0.zap
alpha
<h3>Changed</h3>
<ul>
<li>Include the HTTP version of the alerts' message when creating the <code>requestor</code> job.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/retest-v0.5.0/retest-alpha-0.5.0.zap
SHA-256:ddba5597d583f28df5d908f0eae3a243a1697615d4c06846b94b125549342ae1
https://www.zaproxy.org/docs/desktop/addons/retest/
https://github.com/zaproxy/zap-extensions/
2023-01-03
258076
2.12.0
automation
>=0.20.0
retire
Retire.js
Retire.js
Nikita Mundhada and the ZAP Dev Team
0.20.0
retire-release-0.20.0.zap
release
<h3>Changed</h3>
<ul>
<li>Updated with upstream retire.js pattern changes.</li>
<li>Alert Tags for CVEs now include standardized links.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/retire-v0.20.0/retire-release-0.20.0.zap
SHA-256:cc23c55dd56a87a295d7a9e7cb3743c0590c828fb0e93844548d6cf4c7048b4c
https://www.zaproxy.org/docs/desktop/addons/retire.js/
https://github.com/zaproxy/zap-extensions/
2023-03-03
1215804
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
reveal
Reveal
Show hidden fields and enable disabled fields
ZAP Dev Team
5
reveal-release-5.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/reveal-v5/reveal-release-5.zap
SHA-256:6cf38bfb49427e6303a9cf7b674c24cf5f53ee8cc2e70bf3841cc0e373c18369
https://www.zaproxy.org/docs/desktop/addons/reveal/
https://github.com/zaproxy/zap-extensions/
2022-10-27
238237
2.12.0
revisit
Revisit
Revisit a site at any time in the past using the session history
ZAP Dev Team
4
revisit-alpha-4.zap
alpha
<h3>Added</h3>
<ul>
<li>Add info and repo URLs.</li>
<li>Maintenance changes.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/revisit-v4/revisit-alpha-4.zap
SHA-256:445bb2a98e06d4ecc945c35c2777dae1b1e5b6ea20de78b920c8004bc3615195
https://www.zaproxy.org/docs/desktop/addons/revisit/
https://github.com/zaproxy/zap-extensions/
2021-10-07
299864
2.11.0
saml
SAML Support
Detect, Show, Edit, Fuzz SAML requests
ZAP Dev Team
10
saml-alpha-10.zap
alpha
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/saml-v10/saml-alpha-10.zap
SHA-256:097492271c7ec1d85def81091ffe897f4809927043844d1f5f0c7c598a0ad164
https://www.zaproxy.org/docs/desktop/addons/saml-support/
https://github.com/zaproxy/zap-extensions/
2022-10-28
1811985
2.12.0
scripts
Script Console
Supports all JSR 223 scripting languages
ZAP Dev Team
37
scripts-release-37.zap
release
<h3>Fixed</h3>
<ul>
<li>Do not require a name if file provided when adding script with automation job.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/scripts-v37/scripts-release-37.zap
SHA-256:261df64f03e7951fc977d8700f985f981e28e717a10fd98ef8b664374130e3c9
https://www.zaproxy.org/docs/desktop/addons/script-console/
https://github.com/zaproxy/zap-extensions/
2023-03-18
792046
2.12.0
selenium
Selenium
WebDriver provider and includes HtmlUnit browser
ZAP Dev Team
15.11.0
selenium-release-15.11.0.zap
release
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/selenium-v15.11.0/selenium-release-15.11.0.zap
SHA-256:04e012121ba17d82ce65e8fcbf81fe69d66a557b44b0e1a60534f2917fd7990a
https://www.zaproxy.org/docs/desktop/addons/selenium/
https://github.com/zaproxy/zap-extensions/
2022-10-27
24911204
2.12.0
network
>=0.2.0
sequence
Sequence
Gives the possibility of defining a sequence of requests to be scanned.
ZAP Dev Team
6
sequence-alpha-6.zap
alpha
<h3>Added</h3>
<ul>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Issue 2000 - Updated strings shown in active scan dialog with title caps.</li>
<li>Enable help button in Sequence tab of Active Scan dialog.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/sequence-v6/sequence-alpha-6.zap
SHA-256:2849204eab9ea1da50404ab9604e5ec69440c490453a24392c9a40bf95cdb164
https://www.zaproxy.org/docs/desktop/addons/sequence-scanner/
https://github.com/zaproxy/zap-extensions/
2021-10-07
1556476
2.11.0
zest
soap
SOAP Support
Imports and scans WSDL files containing SOAP endpoints.
Alberto (albertov91) + ZAP Dev Team
17
soap-beta-17.zap
beta
<h3>Added</h3>
<ul>
<li>Support for relative file paths and ones including vars in the Automation Framework job.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/soap-v17/soap-beta-17.zap
SHA-256:7f9b12302368e2855aba909fdb6e65c757d4aef07bdf43e6f70a208ec1444baa
https://www.zaproxy.org/docs/desktop/addons/soap-support/
https://github.com/zaproxy/zap-extensions/
2023-02-09
12826438
2.12.0
commonlib
>= 1.5.0 & < 2.0.0
spider
Spider
Spider used for automatically finding URIs on a site.
ZAP Dev Team
0.3.0
spider-release-0.3.0.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
<li>Default number of threads to 2 * processor count.</li>
</ul>
<h3>Added</h3>
<ul>
<li>Support for parsing .DS_Store files to find paths to try (Issue 30).</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Spurious error message on setting user in AF job.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/spider-v0.3.0/spider-release-0.3.0.zap
SHA-256:bea5a510fd37c0bdfd76d3a93a5ad6d0638399a59dd8a13aee7c68ee49eab509
https://www.zaproxy.org/docs/desktop/addons/spider/
https://github.com/zaproxy/zap-extensions/
2023-02-23
1147689
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
database
network
>=0.3.0
spiderAjax
Ajax Spider
Allows you to spider sites that make heavy use of JavaScript using Crawljax
ZAP Dev Team
23.13.0
spiderAjax-release-23.13.0.zap
release
<h3>Added</h3>
<ul>
<li>Automation Framework - HTML elements to click support</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Close the AJAX Spider dialogue when uninstalling the add-on.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/spiderAjax-v23.13.0/spiderAjax-release-23.13.0.zap
SHA-256:dc96dce0da244995c181fe8073953e06c4f419ba7ee8fff51c50fbfc58b10602
https://www.zaproxy.org/docs/desktop/addons/ajax-spider/
https://github.com/zaproxy/zap-extensions/
2023-03-15
5841704
2.12.0
commonlib
>= 1.13.0 & < 2.0.0
network
>=0.1.0
selenium
15.*
sqliplugin
Advanced SQLInjection Scanner
An advanced active injection bundle for SQLi (derived by SQLMap)
Andrea Pompili (Yhawke)
15
sqliplugin-beta-15.zap
beta
<h3>Fixed</h3>
<ul>
<li>Re-ordered variable initialization to prevent an NPE.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/sqliplugin-v15/sqliplugin-beta-15.zap
SHA-256:76e857bd2fea0b57b641862ea5bef46365ac1b03a19371c5e818a5401f7d9384
https://www.zaproxy.org/docs/desktop/addons/advanced-sqlinjection-scanner/
https://github.com/zaproxy/zap-extensions/
2021-10-20
534349
2.11.0
commonlib
>= 1.5.0 & < 2.0.0
sse
Server-Sent Events
Allows you to view Server-Sent Events (SSE) communication.
ZAP Dev Team
12
sse-alpha-12.zap
alpha
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/sse-v12/sse-alpha-12.zap
SHA-256:c8805d497f71495e1d7fab7dfccf1955cc996ff514e6c0154e7937a72fdafc6c
https://www.zaproxy.org/docs/desktop/addons/server-sent-events/
https://github.com/zaproxy/zap-extensions/
2022-10-28
334645
2.12.0
svndigger
SVN Digger Files
SVN Digger files which can be used with ZAP forced browsing
ZAP Dev Team
4
svndigger-release-4.zap
release
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add repo URL.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Promote to release status.</li>
<li>Change info URL to link to the site.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/svndigger-v4/svndigger-release-4.zap
SHA-256:5556efdf3fdb84ebd6cf3e76ca31e3fb6fb57c002cf14b2cf2f05f67bf2b622a
https://www.zaproxy.org/docs/desktop/addons/svn-digger-files/
https://github.com/zaproxy/zap-extensions/
2021-10-07
713963
2.11.0
tips
Tips and Tricks
Display ZAP Tips and Tricks
ZAP Dev Team
10
tips-beta-10.zap
beta
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.12.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/tips-v10/tips-beta-10.zap
SHA-256:5fd165ff3384f31f070b34d5fd9f7c1dfe04a88298a340e418827aed923fc6f5
https://www.zaproxy.org/docs/desktop/addons/tips-and-tricks/
https://github.com/zaproxy/zap-extensions/
2022-10-27
573495
2.12.0
tokengen
Token Generation and Analysis
Allows you to generate and analyze pseudo random tokens, such as those used for session handling or CSRF protection
ZAP Dev Team
15
tokengen-beta-15.zap
beta
<h3>Changed</h3>
<ul>
<li>Now using 2.10 logging infrastructure (Log4j 2.x).</li>
<li>Maintenance changes.</li>
<li>Update minimum ZAP version to 2.11.0.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/tokengen-v15/tokengen-beta-15.zap
SHA-256:daef1d13d44a76b8735a30ed9e1e50fa87a85d02728bd7ae575197d173f942f9
https://www.zaproxy.org/docs/desktop/addons/token-generator/
https://github.com/zaproxy/zap-extensions/
2021-10-07
525206
2.11.0
treetools
TreeTools
Tools to add functionality to the tree view.
Carl Sampson
8
treetools-beta-8.zap
beta
<h3>Added</h3>
<ul>
<li>Add help.</li>
<li>Add info and repo URLs.</li>
</ul>
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/treetools-v8/treetools-beta-8.zap
SHA-256:b7f61f8939937ebc120bce8deb72713d7676087056e88801df2573112e7642e4
https://www.zaproxy.org/docs/desktop/addons/treetools/
https://github.com/zaproxy/zap-extensions/
2021-10-07
128931
2.11.0
viewstate
ViewState
ASP/JSF ViewState Decoder and Editor
Calum Hutton
3
viewstate-alpha-3.zap
alpha
<h3>Changed</h3>
<ul>
<li>Update minimum ZAP version to 2.11.0.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/viewstate-v3/viewstate-alpha-3.zap
SHA-256:715caefd591415e79b32195361fea82aa8c6357b24e69530c22fde0a1b6dad17
https://www.zaproxy.org/docs/desktop/addons/viewstate/
https://github.com/zaproxy/zap-extensions/
2021-10-07
148716
2.11.0
wappalyzer
Wappalyzer - Technology Detection
Technology detection using Wappalyzer: wappalyzer.com
ZAP Dev Team
21.19.0
wappalyzer-release-21.19.0.zap
release
<h3>Changed</h3>
<ul>
<li>Updated with upstream Wappalyzer icon and pattern changes.</li>
<li>Maintenance changes.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/wappalyzer-v21.19.0/wappalyzer-release-21.19.0.zap
SHA-256:5c553b6112fdcc7c9150d6b637c454c89560f8d146903f075e9186f4a151ebad
https://www.zaproxy.org/docs/desktop/addons/technology-detection/
https://github.com/zaproxy/zap-extensions/
2023-03-03
17833044
2.12.0
commonlib
>= 1.7.0 & < 2.0.0
webdriverlinux
Linux WebDrivers
Linux WebDrivers for Firefox and Chrome.
ZAP Dev Team
52
webdriverlinux-release-52.zap
release
<h3>Changed</h3>
<ul>
<li>Update ChromeDriver to 111.0.5563.64.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/webdriverlinux-v52/webdriverlinux-release-52.zap
SHA-256:7b26e523549428b45ceeca59eea7d6002103a84d12230da5b3c1a93263c426ff
https://www.zaproxy.org/docs/desktop/addons/linux-webdrivers/
https://github.com/zaproxy/zap-extensions/
2023-03-09
16517468
2.12.0
webdrivermacos
MacOS WebDrivers
MacOS WebDrivers for Firefox and Chrome.
ZAP Dev Team
52
webdrivermacos-release-52.zap
release
<h3>Changed</h3>
<ul>
<li>Update ChromeDriver to 111.0.5563.64.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/webdrivermacos-v52/webdrivermacos-release-52.zap
SHA-256:2af598f939f0c5e195b8338deaa0e46bf3dd86cdd4219dfc94b942eb17830f0c
https://www.zaproxy.org/docs/desktop/addons/macos-webdrivers/
https://github.com/zaproxy/zap-extensions/
2023-03-09
21819726
2.12.0
webdriverwindows
Windows WebDrivers
Windows WebDrivers for Firefox and Chrome.
ZAP Dev Team
51
webdriverwindows-release-51.zap
release
<h3>Changed</h3>
<ul>
<li>Update ChromeDriver to 111.0.5563.64.</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/webdriverwindows-v51/webdriverwindows-release-51.zap
SHA-256:a830ac04615c480c3d6b2886fd6f06c72a79f2a963a453d1f64ee2716d98025e
https://www.zaproxy.org/docs/desktop/addons/windows-webdrivers/
https://github.com/zaproxy/zap-extensions/
2023-03-09
10458973
2.12.0
websocket
WebSockets
Allows you to inspect WebSocket communication.
ZAP Dev Team
28
websocket-release-28.zap
release
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevent exception if no display (Issue 3978).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/websocket-v28/websocket-release-28.zap
SHA-256:8d5eb20545f534a0631bb6c90a73c7ec75c19d4fe65741e275a2877383a89f61
https://www.zaproxy.org/docs/desktop/addons/websockets/
https://github.com/zaproxy/zap-extensions/
2023-01-03
1403392
2.12.0
zest
Zest - Graphical Security Scripting Language
A graphical security scripting language, ZAPs macro language on steroids
ZAP Dev Team
38
zest-beta-38.zap
beta
<h3>Changed</h3>
<ul>
<li>Maintenance changes.</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Prevent exception if no display (Issue 3978).</li>
</ul>
https://github.com/zaproxy/zap-extensions/releases/download/zest-v38/zest-beta-38.zap
SHA-256:670c122b802fe548bc8a4f9d2c2b2a97f7ba5b7e607dc140d6d1b3917cc8d9b9
https://www.zaproxy.org/docs/desktop/addons/zest/
https://github.com/zaproxy/zap-extensions/
2023-01-03
13582355
2.12.0
network
>=0.2.0
scripts
selenium
15.*