We performed a comparison between OWASP Zap and Synopsys API Security Testing based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Static Application Security Testing (SAST)."The most valuable feature is scanning the URL to drill down all the different sites."
"Automatic scanning is a valuable feature and very easy to use."
"The OWASP's tool is free of cost, which gives it a great advantage, especially for smaller companies to make use of the tool."
"The stability of the solution is very good."
"The reporting is quite intuitive, which gives you a clear indication of what kind of vulnerability you have that you can drill down on to gather more information."
"The interface is easy to use."
"The HUD is a good feature that provides on-site testing and saves a lot of time."
"Two features are valuable. The first one is that the scan gets completed really quickly, and the second one is that even though it searches in a limited scope, what it does in that limited scope is very good. When you use Zap for testing, you're only using it for specific aspects or you're only looking for certain things. It works very well in that limited scope."
"The most valuable features of Synopsys API Security Testing are the metrics, results, and threat vectors that it shares."
"The documentation needs to be improved because I had to learn everything from watching YouTube videos."
"Too many false positives; test reports could be improved."
"Sometimes, we get some false positives."
"The ability to search the internet for other use cases and to use the solution to make applications more secure should be addressed."
"I prefer Burp Suite to SWASP Zap because of the extensive coverage it offers."
"The forced browse has been incorporated into the program and it is resource-intensive."
"Zap could improve by providing better reports for security and recommendations for the vulnerabilities."
"It would be nice to have a solid SQL injection engine built into Zap."
"The solution required us to use our team and we spoke to Synopsys API Security Testing's support to do the implementation. We use two people from our team for the implementation. and one person for maintenance."
Earn 20 points
OWASP Zap is ranked 7th in Static Application Security Testing (SAST) with 37 reviews while Synopsys API Security Testing is ranked 30th in Static Application Security Testing (SAST). OWASP Zap is rated 7.6, while Synopsys API Security Testing is rated 7.0. The top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". On the other hand, the top reviewer of Synopsys API Security Testing writes "Useful threat vectors, beneficial results, but implementation needed support". OWASP Zap is most compared with SonarQube, Acunetix, Qualys Web Application Scanning, Veracode and PortSwigger Burp Suite Professional, whereas Synopsys API Security Testing is most compared with Seeker and Fortify WebInspect.
See our list of best Static Application Security Testing (SAST) vendors.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.