logo

New ZAP PTK Add-On Converts Browser Security Findings Into Native ZAP Alerts

ID: 8fce9636-afdc-53a3-99e3-8f6c89ef644b

STIX ID: report--8fce9636-afdc-53a3-99e3-8f6c89ef644b

Feed Name: GBHackers

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Divya

...
...

The report announces OWASP ZAP PTK Add-on 0.3.0, which integrates browser-based client-side security findings (SAST, IAST, DAST) into native ZAP alerts, adds 142 PTK-tagged alert types, and supports features like custom rule selection and auto-start scanning. It explains how PTK helps detect client-side issues in modern SPAs (e.g., DOM-based XSS and unsafe JavaScript patterns) that traditional proxy tools miss and provides step-by-step instructions to install and run the integration for testing (using OWASP Juice Shop as an example).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.