My feedback to ZAP project and it's core team.
Zap Proxy
↓
Very capable platform
↓
Documentation + add-ons
↓
Automation Framework / API / MCP / LLM
↓
But fewer structured ZAP-specific practical exercises / labs.
Who am I ? @prabinBNYFXBB , 22 yrs old , a noob , beginner in web pentesting . I first came across burpsuite in 2023 through tryhackme platform . Later learn , Portswigger's Web Security Acedemy labs and try solving thems . And they are well made across burpsuite and more than 35% labs need PRO edition not community one , so after that I find about ZAP proxy , an open source , free proxy (comparable to Burpsuite pro and more) and solving portswigger labs but it's painful to learn two proxies side by side comparing each proxies , UI features as acedemy's labs solutions are based on burpsuite UI.
One similar but interesting incident is happening which I think I should discussed here , in ZAP proxy while doing fuzzing I found simple, cluster bomb modes only at first and then I wrote script for batterRam and pitchfork with help of AI , but later found , it has Breadth first , and Depth first modes , meaning all four fuzzing modes possible are available . Similarities there are too many things we don't know about it's features .
( My request to the ZAP team )
Could the ZAP project consider creating an official: "ZAP Desktop Academy" or "ZAP Feature Labs" focused specifically on learning the ZAP application through hands-on exercises? ZAP already has the technology, documentation, add-ons, automation capabilities , API , MCP , and test applications.
What I think would complete the ecosystem is a structured practical learning layer that teaches people how to actually use all of it.
That would make ZAP much easier for beginners to learn without having to constantly translate workflows from Burp Suite.