ZAP by Checkmarx, a tool for finding vulnerabilities in web applications
The Zed Attack Proxy (ZAP) by Checkmarx is one of the world’s most popular security tools.
It is free and open source.
It can help you automatically find security vulnerabilities in your web applications
while you are developing and testing your applications.
Its also a great tool for experienced pentesters to use for manual security testing.