No more typing reviews! Try our Samantha, our new voice AI agent.

OWASP Zap vs Polaris Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OWASP Zap
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
Static Application Security Testing (SAST) (14th)
Polaris Platform
Average Rating
8.0
Reviews Sentiment
3.2
Number of Reviews
1
Ranking in other categories
Software Composition Analysis (SCA) (14th), Static Code Analysis (12th), Dynamic Application Security Testing (DAST) (11th)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. OWASP Zap is designed for Static Application Security Testing (SAST) and holds a mindshare of 2.9%, down 5.1% compared to last year.
Polaris Platform, on the other hand, focuses on Software Composition Analysis (SCA), holds 1.6% mindshare, down 1.7% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
OWASP Zap2.9%
SonarQube14.5%
Checkmarx One9.2%
Other73.4%
Static Application Security Testing (SAST)
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
Polaris Platform1.6%
Snyk11.1%
Black Duck SCA9.2%
Other78.1%
Software Composition Analysis (SCA)
 

Featured Reviews

Amit Beniwal - PeerSpot reviewer
Project Manager at Al Hassan LLC
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.
Alina-Eugenia Negulescu - PeerSpot reviewer
Head of Procurement and Vendor Manger at twoday
Company consistently identifies security vulnerabilities with current solution but considers moving to a more developer-oriented tool due to complexity and costs
I wouldn't recommend it for small and medium customers, both in terms of the complexity and organizational processes and operational processes around it. I wouldn't go with Black Duck. It's not straightforward as it is with more developer-oriented and plug-and-play versions, so it requires a bit of knowledge and documentation to set it up. On the support part, in the past, we had some issues regarding the availability of the information on the knowledge portal. That was particularly due to the fact that when they integrated their knowledge hub or knowledge portal different kind of documentation, they have not adapted the text. There were circular references on the documentation that was misleading and confusing our people rather than helping them.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This is a very mature tool; it is capable of facilitating the work of many security experts, and I highly recommend it for beginners and advanced users when some other tools fail to catch traffic."
"We use OWASP Zap for web application security scanning."
"It scans while you navigate, then you can save the requests performed and work with them later."
"The product has improved our application security engagement, helps with our in-house review so we sometimes don't need an external third-party tester, and once we get it from OWASP Zap, we have an idea of the inherent vulnerabilities in the application, which is a plus to save cost and improve our application accuracy practice."
"This solution has improved my organization because it has made us feel safer doing frequent deployments for web applications. If we have something really big, we might get some professional company in to help us but if we're releasing small products, we will check it ourselves with Zap. It makes it easier and safer."
"The product helps users to scan and fix vulnerabilities in the pipeline."
"ZAP is easy to use. The automated scan is a powerful feature. You can simulate attacks with various parameters. ZAP integrates well with SonarQube."
"Fuzzer and Java APIs help a lot with our custom needs."
"We have detected security vulnerabilities, which is absolutely one big benefit."
 

Cons

"I would like to see a version of “repeater” within OWASP ZAP, a tool capable of sending from one to 1000 of the same requests, but with preselected modified fields, changing from a predetermined word ​list, or manually created."
"I would recommend this product to people although I think it is very difficult to deploy and we also have issues with maintenance."
"The product should allow users to customize the report based on their needs."
"We get too many false positives and that should definitely be improved."
"It's possibly just a limitation of the product itself but sometimes it won't scan a particular website so you have to manually go in and make some configuration changes."
"The documentation is lacking and out-of-date, it really needs more love."
"Lacks resources where users can internally access a learning module from the tool."
"OWASP should work on reducing false positives by using AI and ML algorithms. They should expand their capabilities for broader coverage of business logic flaws and complex issues."
"I wouldn't recommend it for small and medium customers, both in terms of the complexity and organizational processes and operational processes around it."
 

Pricing and Cost Advice

"OWASP Zap is free to use."
"It's free and open, currently under the Apache 2 license. If ZAP does what you need it to do, selling a free solution is a very easy."
"OWASP ZAP is a free tool provided by OWASP’s engineers and experts. There is an option to donate."
"We have used the freeware version. I believe Zap only has freeware."
"The solution’s pricing is high."
"The tool is open source."
"It's free. It's good for us because we don't know what the extent of our use will be yet. It's good to start with something free and easy to use."
"This solution is open source and free."
Information not available
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
900,644 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
10%
Financial Services Firm
9%
University
9%
Manufacturing Company
8%
Manufacturing Company
13%
Financial Services Firm
10%
Computer Software Company
10%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise22
No data available
 

Questions from the Community

Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
What needs improvement with OWASP Zap?
The improvement that has to be done for APIs focuses on manual activities where the feature exists, but it is not at the same level as what Burp Suite does with intercepting and tools such as Postm...
What is your experience regarding pricing and costs for Polaris Platform?
In my opinion, I think that it's a very good product for mature companies. It is quite expensive compared with competitors, with other providers of similar services of application security manageme...
What needs improvement with Polaris Platform?
I wouldn't recommend it for small and medium customers, both in terms of the complexity and organizational processes and operational processes around it. I wouldn't go with Black Duck. It's not str...
What is your primary use case for Polaris Platform?
The product teams use them under supervision from the security department. I'm not extremely familiar with the details on how the product teams are using it, but I think they have integrated it int...
 

Overview

 

Sample Customers

1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Information Not Available
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: May 2026.
900,644 professionals have used our research since 2012.