The latest weekly release does not include the AJAX Spider and DOM XSS add-ons.
You can install them via the Marketplace as usual, but we recommend you using the Client Spider and OWASP PTK add-ons instead.
For more details see zaproxy.org/blog/2026-09-08-…#zaproxy#appsec
ZAP updates for August.
We’re removing 2 add-ons from the nightly and weekly releases, so if you use those then make sure you read it to understand the implications.
zaproxy.org/blog/2026-09-08-…#zaproxy#appsec
Big announcement!
We now recommend that you use the Client Spider for crawling modern web apps, instead of the AJAX Spider.
More details in the blog post:
zaproxy.org/blog/2026-07-06-…#zaproxy#appsec
An Insecure Java Deserialization vulnerability has been reported in a ZAP add-on via @neo_ai_engineer
Update your ZAP add-ons now, and definitely update from older versions of ZAP.
For more details see: zaproxy.org/blog/2026-06-24-…
ZAP now has a dedicated OWASP PTK active scan rule, so you can run the PTK rules in the ZAP active scanner.
Check out the dramatic improvement in the scores vs Google Firing Range!
zaproxy.org/blog/2026-06-05-…#zaproxy#owaspptk#appsec
In May ZAP learned to scan MCP servers as a first-class target, OWASP PTK automation reached Phase 1, and the Params extension moved out of the core into its own add-on.
zaproxy.org/blog/2026-06-02-…#zaproxy#appsec