From the experiment

Do coding agents recommend ZAP?

ZAP is the most chosen security testing tool, taking 24% of 460 judged security testing sessions.

Published September 28, 2026 Updated September 29, 2026 Read as Markdown

ZAP is the most chosen security testing tool, taking 24% of 460 judged security testing sessions. It was also raised as a candidate in 81 further sessions without being chosen.

This page reports what happened when Claude Code, Codex, Grok Build CLI and Muse Code had to solve a problem in security testing inside a realistic codebase. Not what a chat assistant says about ZAP. What an agent actually installed.

The numbers

CategorySecurity testing
Sessions in the category460
Sessions where ZAP was chosen111
Install share24%
Rank in category1 of 65
Codebases it won in7
Raised as a candidate, not chosen81
Chosen when considered58%
Sitezaproxy.org

By agent

The agents treat ZAP very differently. Muse Code chose it in 35% of its sessions in this category and Grok Build CLI in 18%, a spread of 17 points.

AgentSessionsChose ZAPShare
Claude Code1162320%
Codex1162824%
Grok Build CLI1162118%
Muse Code1123935%

A single blended install share would report the midpoint and hide both ends. If most of your users run Grok Build CLI, your real position here is 18%, not 24%.

What ZAP was up against

The full ranking in security testing, from the same sessions:

#ProductRuns wonShare
1ZAP (this page)11124%
2Semgrep7817%
3SonarQube6614%
4Burp Suite307%
5GitHub Advanced Security255%
6Trivy143%
7StackHawk123%
8Strix112%

What this means

Leading a category is a position to defend rather than a result to celebrate. In our data, leaders lose ground in exactly two situations: when the person asking is an enterprise buyer with procurement constraints, and when a competitor's documentation is easier for an agent to integrate correctly.

The defence is unglamorous. Keep the quickstart running. Keep the version current on the page. Keep the names aligned. Stay in the templates.

Where these numbers come from

The 460 sessions in security testing are part of a published set of 15,000, run with real coding agents inside realistic codebases and judged blind. The full method is on one page: how we measured this.

Every security testing run can be replayed on the board.

If you work on ZAP: the judge recorded a reason for every session where it was raised and passed over. Those reasons are in the transcripts.

<!-- generated by scripts/write-data-pages.mjs -->

Common questions

Do coding agents recommend ZAP?

Yes. ZAP was chosen in 111 of the 460 judged sessions in security testing, a 24% install share, ranking first in its category.

Does Claude Code recommend ZAP?

In 23 of the 116 sessions in security testing run with Claude Code, which is 20%.

Do different coding agents treat ZAP differently?

Yes, and by a wide margin. Muse Code chose it in 35% of its runs and Grok Build CLI in 18%.

How was this measured?

Real coding agents at pinned versions were run in sandboxes inside 92 realistic codebases and asked to solve real tasks. A simulated project owner approved or questioned each recommendation before any code was written, and a judge from a model family that builds none of the agents read every session blind.

How often is ZAP considered but not chosen?

It was raised as a candidate in 81 sessions without being chosen, and chosen in 111. That is a 58% conversion from considered to chosen.

Where this comes from

Armature ran 15,000 judged sessions with Claude Code, Codex, Cursor, Grok Build CLI and Muse Code inside 92 realistic codebases, and published every run. The numbers on this page come from that work.

Read next

All library pages