The web application security has currently become a very significant area of scholarship, the best way to deal with it is to use web application security scanner to discover the architectural weaknesses and vulnerabilities in the web application. A standard has been constructed by OWASP which lists common risks. The goal of this paper is to use OWASP Top 10 to compare and contrast the Open Source Web Application Security Scanners, and then determine the best of them. The study shows that W3AF 1.2, arachniv0.4.0.3 and Skipfish 2.07 are the most suitable ones because they have 0.863826, 0.79922, and 0.781676 averages respectively. So the web developer or administrator can use them together, choose one, or modify it by adding the missing feature and make his/her own application.