Skip to content
psiinon edited this page Apr 4, 2013 · 13 revisions

Zest is a specialized scripting language developed by the Mozilla security team and is intended to be used in web oriented security tools.

It is completely free, open source and can be included in any tool whether open or closed, free or commercial.

Version 1 of Zest:

  • Is aimed at creating scripts for reproducing basic security vulnerabilities
  • Includes a Java reference implementation
  • Has been included in a proof-of-concept OWASP ZAP add-on

Zest scripts are written in JSON, but the expectation is that scripts will be written using graphical interfaces.

While Zest can have many uses we have focused on one particular use case for the first version: reproducing security vulnerabilities
For more technical details about Zest see: Zest Core.

The first version of Zest is intentionally very basic. Future versions of Zest are planned which will significantly increase the scope of the language.

All constructive feedback is very welcome.

Anyone can contribute to the onward development of Zest, and teams or individuals who develop security tools are especially welcome to join and help shape Zest's future.

Clone this wiki locally