We performed a comparison between OWASP Zap and Synopsys API Security Testing based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Static Application Security Testing (SAST)."The solution is scalable."
"This solution has improved my organization because it has made us feel safer doing frequent deployments for web applications. If we have something really big, we might get some professional company in to help us but if we're releasing small products, we will check it ourselves with Zap. It makes it easier and safer."
"The HUD is a good feature that provides on-site testing and saves a lot of time."
"The scalability of this product is very good."
"They offer free access to some other tools."
"The API is exceptional."
"The OWASP's tool is free of cost, which gives it a great advantage, especially for smaller companies to make use of the tool."
"The vulnerabilities that it finds, because the primary goal is to secure applications and websites."
"The most valuable features of Synopsys API Security Testing are the metrics, results, and threat vectors that it shares."
"I'd like to see a kind of feature where we can just track what our last vulnerability was and how it has improved or not. More reports that can have some kind of base-lining, I think that would be a good feature too. I'm not sure whether it can be achieved and implement but I think that would really help."
"It would be a great improvement if they could include a marketplace to add extra features to the tool."
"Sometimes, we get some false positives."
"OWASP Zap needs to extend to mobile application testing."
"The documentation is lacking and out-of-date, it really needs more love."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"There's very little documentation that comes with OWASP Zap."
"It doesn't run on absolutely every operating system."
"The solution required us to use our team and we spoke to Synopsys API Security Testing's support to do the implementation. We use two people from our team for the implementation. and one person for maintenance."
Earn 20 points
OWASP Zap is ranked 7th in Static Application Security Testing (SAST) with 37 reviews while Synopsys API Security Testing is ranked 30th in Static Application Security Testing (SAST). OWASP Zap is rated 7.6, while Synopsys API Security Testing is rated 7.0. The top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". On the other hand, the top reviewer of Synopsys API Security Testing writes "Useful threat vectors, beneficial results, but implementation needed support". OWASP Zap is most compared with SonarQube, Acunetix, Qualys Web Application Scanning, Veracode and PortSwigger Burp Suite Professional, whereas Synopsys API Security Testing is most compared with Seeker and Fortify WebInspect.
See our list of best Static Application Security Testing (SAST) vendors.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.