Roadmap

No target dates are given as much of the work on ZAP is done by volunteers. We also aim to react very quickly to urgent issues which inevitably delays other planned work.

For details of how to sponsor ZAP developments see the Support page.

These are the major items on ZAP’s roadmap for the next few years:

Year Status
Sponsor Item
2026 ⌚ Planned Checkmarx Ltd. Release 2.18
2026 ⌚ Planned Checkmarx Ltd. Improved Modern App Crawling
2026 ⌚ Planned Checkmarx Ltd. Improved Client Side Vulnerability Detection
2026 ⌚ Planned Checkmarx Ltd. Expand Custom Payloads support to additional rules
2026 ⌚ Planned Expand PCAP import support
2026 ⌚ Planned Expand gRPC support
2026 ⚡ In progress Checkmarx Ltd. Improved Authentication Handling
2026 ⚡ In progress Checkmarx Ltd. Automation Framework enhancements
2026 ⚡ In progress Move Break Functionality to an add-on
2026 ⚡ In progress OpenSSF Best Practices: Silver Currently 54 of 55 criteria met
2026 ⚡ In progress Ensure alert details and examples are complete and up to date
n/a ♻ Ongoing Continue working on issues
n/a ♻ Ongoing Continue improving scan rules
n/a ♻ Ongoing Move core functionality to add-ons
2025 🎉 Finished Checkmarx Ltd. Release 2.17
2025 🎉 Finished Checkmarx Ltd. Release 2.16
2025 🎉 Finished Checkmarx Ltd. Move Passive Scanner to an add-on
2025 🎉 Finished Checkmarx Ltd. Promote the Custom Payloads add-on to Release