
Simon Bennetts — OWASP ZAP: past, present, and future
Om avsnittet
How do you make a powerful security testing tool approachable to the developers who need it? ZAP project founder Simon Bennetts traces the project from his own experience of a penetration test to a community tool built for learning and automation. Speaking with Robert at CodeMash, he explains the origins of ZAP’s name, the thinking behind its browser-based Heads Up Display, and why usability matters as features multiply. They also discuss ZAP’s API, automated testing, volunteer contributions, and the difficulty of turning a long list of ideas into releases. This conversation captures the project’s direction at the time of recording and gives newcomers a clear picture of how to start using and contributing to ZAP.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Simon Bennetts:
→ Simon Bennetts on LinkedIn
→ ZAP
Mentioned in this episode:
→ ZAP Heads Up Display
→ ZAP API documentation
→ ZAP source code
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 ZAP’s past, present, and future with Simon Bennetts
01:51 A developer’s security wake-up call
04:24 How the ZAP project began
07:41 The story behind the name ZAP
09:44 Bringing security tools into the browser with the HUD
14:38 Browser support and the HUD’s implementation
15:32 How to contribute to ZAP
17:20 Too many ideas and too few contributors
17:56 Integrating OWASP guidance and explaining coverage
19:31 Automating testing through the ZAP API
21:47 Downloads and Docker adoption
23:00 Planning releases with a volunteer team
24:24 Where to find ZAP
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.