Zed Attack Proxy (ZAP) is an open source security and privacy application designed to help web application security professionals assess the security of their web applications. It is a powerful tool that can be used to test the security of web applications, detect common vulnerabilities, and help protect sites from malicious attacks. ZAP can be used to detect SQL injection, cross-site scripting (XSS) and other vulnerabilities. It can also be used to audit web applications for compliance with security standards such as OWASP Application Security Verification Standard (ASVS). ZAP can also be used to automate security testing of web applications, allowing for continuous integration of security tests. It is a popular tool for web application security professionals, and is also used by developers and security researchers.
Skipfish is no longer maintained. The latest version, 2.10 beta, released in December 2012, is still available for download from Google Code Archive