Software Alternatives & Startups

OpenVAS VS Zed Attack Proxy

Compare OpenVAS VS Zed Attack Proxy and see what are their differences

OpenVAS

The Open Vulnerability Assessment System (OpenVAS) is a framework of several services and tools...

Rating
0 reviews
Zed Attack Proxy

The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding...

Rating
0 reviews
Pricing
Open source

Which is more popular?

Based on our record, OpenVAS seems to be more popular. It has been mentioned 6 times since March 2021.

social mentions
6 vs 0
Security popularity
100% vs 0%
alternatives listed
240+ vs 66

Base details

Website, pricing, platforms and company facts side by side.

OpenVAS
Zed Attack Proxy
Website openvas.org zaproxy.org
Pricing
Open source
Listed in

Features and specs

What each product offers, as listed by its team.

OpenVAS 5 features
Zed Attack Proxy 5 features
  • Open Source
    OpenVAS is an open-source vulnerability scanning tool, which means it is free to use and the source code is available for customization.
  • Comprehensive Scanning
    It offers comprehensive vulnerability scanning capabilities, including a wide range of tests for network vulnerabilities, web application security, and compliance checks.
  • Regular Updates
    The tool receives regular updates, ensuring that it keeps up with the latest vulnerabilities and security threats.
  • Community Support
    OpenVAS has a strong community of users and developers who contribute to its development and provide support through forums and other channels.
  • Integration Capabilities
    OpenVAS can be integrated with other security tools and systems, enhancing its utility in a broader security infrastructure.

Possible disadvantages

  • Complex Setup
    Setting up OpenVAS can be complex and time-consuming, requiring a fair amount of technical expertise.
  • Resource Intensive
    Running OpenVAS can be resource-intensive, potentially requiring significant CPU and memory, especially during large-scale scans.
  • False Positives
    Like many vulnerability scanning tools, OpenVAS can generate false positives, which can result in additional effort to validate findings.
  • User Interface
    The user interface can be less intuitive compared to some commercial vulnerability scanners, potentially increasing the learning curve for new users.
  • Limited Real-Time Capabilities
    OpenVAS is more focused on periodic scanning rather than real-time vulnerability detection and management.
  • Open Source
    Zed Attack Proxy (ZAP) is open-source software, which means it's free to use and the source code is available for modification and improvement by the community.
  • Active Community
    ZAP has a robust and active community that contributes to its continuous improvement, provides support, and develops plugins and extensions.
  • Ease of Use
    ZAP is designed to be user-friendly, with a simple and intuitive interface, making it suitable for both beginners and advanced users.
  • Comprehensive Toolset
    ZAP offers a wide range of tools and features for automated and manual testing of web applications, including spidering, scanning, proxying, and reporting.
  • Cross-Platform
    ZAP runs on multiple platforms, including Windows, Linux, and macOS, providing flexibility for users regardless of their operating system.

Possible disadvantages

  • Performance Issues
    ZAP can be resource-intensive, which might lead to performance slowdowns, especially when scanning large applications or using a lot of active scan rules.
  • Steep Learning Curve for Advanced Features
    While the basic functions are user-friendly, utilizing advanced features and customizations can require a deeper understanding and can be complex for newcomers.
  • Plugin Dependency
    Relying on community-developed plugins can sometimes be problematic if they are not updated in line with the core tool, potentially leading to compatibility issues.
  • Limited Commercial Support
    Since ZAP is open source, it lacks dedicated commercial support, which may be a disadvantage for enterprises requiring guaranteed support services.
  • False Positives
    As with many security scanning tools, ZAP may generate false positives, which requires manual verification and can add to the time and effort required in a security assessment.

Analysis

An editorial look at what each product does well and who it suits.

OpenVAS
Zed Attack Proxy

Overall verdict

  • OpenVAS is a good choice for those seeking a reliable and free vulnerability management solution. However, users should be prepared for a potentially steep learning curve and the need for manual configuration to tailor the scanner to their specific environment.

Why this product is good

  • OpenVAS is a comprehensive open-source vulnerability scanner that is widely respected within the cybersecurity community. It provides extensive scanning capabilities, a regularly updated database of vulnerabilities, and supports a wide range of network protocols. The tool is versatile and can be integrated with other software for enhanced security operations. It is well-suited for detecting vulnerabilities in the network and identifying security issues that need to be addressed.

Recommended for

    OpenVAS is ideal for small to medium-sized organizations looking for a cost-effective vulnerability scanning solution. It's also suitable for cybersecurity professionals who have the technical expertise to configure and maintain the scanner, as well as enthusiasts or students who are keen on learning more about vulnerability management using open-source tools.

No analysis of Zed Attack Proxy yet.

Videos

Walkthroughs and reviews on video.

OpenVAS 3 videos + Add
Zed Attack Proxy 3 videos + Add

How to find Exploits with OpenVAS

More videos

  • - Vulnerability Analysis with OpenVAS | Scanning and Reconnaissance
  • - Vulnerability Identification and Remediation Cybrary Lab | Ep. 3 Kali Linux, OpenVAS, + more

Zed Attack Proxy ZAP Tutorial #6 - Forced Browsing

More videos

  • - Zed Attack Proxy ZAP Tutorial #2 - ein einfacher Angriff
  • - Zed Attack Proxy ZAP Tutorial #11 - Kontexte - Authentifikation und mehr

Category popularity

How often each product is chosen within a category, 0–100% relative to the other.

Score bands 0–20 21–40 41–50 51–60 61–100
OpenVAS
Zed Attack Proxy
100% 100%
0% 0%
0% 0%
100% 100%
83% 83%
17% 17%
81% 81%
19% 19%

User comments

Share your experience with using OpenVAS and Zed Attack Proxy. For example, how are they different and which one is better?

Log in or Post with

Reviews and articles

External articles and on-site reviews we used to compare the two products.

OpenVAS no reviews yet
Zed Attack Proxy no reviews yet

View more

We have no reviews of Zed Attack Proxy yet. Be the first one to post

Social recommendations and mentions

Recommendations tracked on public social media and blogs since March 2021.

OpenVAS 6 mentions
Zed Attack Proxy 0 mentions
  • Link CVE to installed applications?
    Otherwise your on the right path checkout the open source Greenbones OpenVAS (this was Nessus before they closed source and became corporate) or Project Discovery Nuclei. Source: over 3 years ago
  • What should I be doing as the sole sysadmin for a company to keep up with security?
    Personally, I was lucky enough to get a license to Nessus for my own scanning, however you can use OpenVAS for some free to scan. Scanners aren't 100% correct no matter where you go but it'll give you some things to look at. OpenVAS. Source: over 4 years ago
  • Wanting to protect my own homelab
    Https://openvas.org/ OpenVAS is free and fairly capable. It might struggle cpu on a pi... Might need quite a bit of ram, but I'm hoping you've got some beefier kit in your stack. Source: over 4 years ago

View more

Tracking Zed Attack Proxy since Mar 2021.

Alternatives to OpenVAS and Zed Attack Proxy

When comparing OpenVAS and Zed Attack Proxy, you can also consider the following products.