Web system security has become a top priority amid the current surge in digital security threats. This study aims to identify vulnerabilities on the Sidodadi Subdistrict website in Bandar Lampung City using OWASP ZAP and to analyze the risk levels of these vulnerabilities using the OWASP Risk Rating method in order to map system weaknesses and formulate solutions. The methodology applied consisted of system scanning, analysis of findings, and implementation of fixes. The initial assessment identified 15 security vulnerabilities, classified into the categories of Broken Access Control, Security Misconfiguration, Cryptographic Failures, Vulnerable and Outdated Components, and Software and Data Integrity Failures. After the remediation and re-verification phases were completed, the number of vulnerabilities decreased to 12. Various remediation solutions including tightening the Content Security Policy (CSP), implementing advanced encryption, and reconfiguring cookies and HTTP headers were found to be effective in reducing the system’s vulnerability level. The retest results showed that the number of vulnerabilities decreased to 12 findings, representing a 20% reduction. Thus, the use of OWASP ZAP and the OWASP Risk Rating method proved effective in identifying, evaluating, and helping to prioritize vulnerability mitigation to improve the security of the Sidodadi Subdistrict website in Bandar Lampung City.
Copyrights © 2026