We performed a comparison between OWASP Zap and Synopsys API Security Testing based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Static Application Security Testing (SAST)."The stability of the solution is very good."
"Simple to use, good user interface."
"Automatic scanning is a valuable feature and very easy to use."
"Fuzzer and Java APIs help a lot with our custom needs."
"The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, it's very difficult."
"They offer free access to some other tools."
"The community edition updates services regularly. They add new vulnerabilities into the scanning list."
"The solution is good at reporting the vulnerabilities of the application."
"The most valuable features of Synopsys API Security Testing are the metrics, results, and threat vectors that it shares."
"It would be beneficial to enhance the algorithm to provide better summaries of automatic scanning results."
"Online documentation can be improved to utilize all features of ZAP and API methods to make use in automation."
"Lacks resources where users can internally access a learning module from the tool."
"I'd like to see a kind of feature where we can just track what our last vulnerability was and how it has improved or not. More reports that can have some kind of base-lining, I think that would be a good feature too. I'm not sure whether it can be achieved and implement but I think that would really help."
"There's very little documentation that comes with OWASP Zap."
"The ability to search the internet for other use cases and to use the solution to make applications more secure should be addressed."
"Sometimes, we get some false positives."
"The technical support team must be proactive."
"The solution required us to use our team and we spoke to Synopsys API Security Testing's support to do the implementation. We use two people from our team for the implementation. and one person for maintenance."
Earn 20 points
OWASP Zap is ranked 8th in Static Application Security Testing (SAST) with 37 reviews while Synopsys API Security Testing is ranked 35th in Static Application Security Testing (SAST). OWASP Zap is rated 7.6, while Synopsys API Security Testing is rated 7.0. The top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". On the other hand, the top reviewer of Synopsys API Security Testing writes "Useful threat vectors, beneficial results, but implementation needed support". OWASP Zap is most compared with SonarQube, Acunetix, Qualys Web Application Scanning, Veracode and PortSwigger Burp Suite Professional, whereas Synopsys API Security Testing is most compared with Seeker and Fortify WebInspect.
See our list of best Static Application Security Testing (SAST) vendors.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.