Ajax Spider

The 'Ajax Spider' tool starts the 'ajax' spider. This launches browsers that can handle links defined using JavaScript. It is much slower than the 'traditional' spider but it will be able to handle sites that make heavy use of JavaScript much more effectively.

When you click on the 'Ajax Spider' tool a dialog will be displayed which allows you to start the ajax spider. You will not be able to ajax spider sites that are not in scope, but the dialog will detect that and give you the option to add the site to the scope.

The start dialog allows you to select either Firefox or Chrome. You will need to have these browsers installed in order to be able to use them. If you select the 'headless' option of either browser then they will be started in 'headless' mode so you will not see them running. This is usually the best option as this prevents new browsers from popping up on your screen. If you think the ajax spider is not handling your site correctly then try launching the non headless versions - that will allow you to see what the browsers are doing.

When the ajax spider is started the tool will only show you that it is running - it does not currently show how far it has progressed. As with the traditional spider you will be able to see all of the pages that the ajax spider has found via the Sites tree. If you click on the Ajax Spider tool while it is running then you will be given the option to stop it. You may well see alerts being raised after you start the ajax spider as ZAP passively scans all of the URLs it finds.