The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers*. It can help you automatically find security vulnerabilities in your web applications while you are developing and testing your applications. Its also a great tool for experienced pentesters to use for manual security testing.
API Details: https://github.com/zaproxy/zaproxy/wiki/ApiDetails
GitHub Repo: https://github.com/vinay-qa/zap-webdriver
- Download ZAP and install.
- It generally runs on port 8080. Change your browsers proxy settings to localhost and 8080
- You can also use tools like foxyproxy to do the same
- Test a web app and see if ZAP is able to see your navigations on the History tab.