We have started to document how to configure ZAP against well known vulnerable apps:
https://www.zaproxy.org/docs/testapps/ Let
@psiinon know if you have any feedback or specific requests
ZAP – ZAP Vs Test Apps
The world’s most widely used web app scanner. Free and open source. ZAP is a community project actively maintained by a dedicated international team, and a GitHub Top 1000 project.
ZAP – Is My App Security Testable?
The world’s most widely used web app scanner. Free and open source. ZAP is a community project actively maintained by a dedicated international team, and a GitHub Top 1000 project.

ZAP Updates - April 2025
April 2025 updates and ongoing feature development statuses.
ZAP
ZAP Wins Inaugural DefectDojo Award for Open-Source Cybersecurity
ZAP was recognised as being one of the best dynamic application security testing (DAST) Tools.
ZAP
PortSwigger Labs: Broken Brute-Force Protection, IP Block
Walkthrough for the PortSwigger lab, “Broken brute-force protection, IP block”.
ZAP
ZAP Updates - March 2025
We released 2.16.1 and made more authentication handling improvements.
ZAPZAP by Checkmarx 2.16.1 has just been released. This is a bug fix release, along with some minor enhancements.
See
https://www.zaproxy.org/blog/2025-03-25-zap-2-16-1/
ZAP 2.16.1
ZAP 2.16.1 has just been released. This is a bug fix release, along with some minor enhancements
ZAP
ZAP Updates - February 2025
Authentication, authentication, authentication… And there will be a 2.16.1 release “soon”.
ZAPSolving Portswigger Lab File Path Traversal Simple Case with ZAP
Video and explanation of How to Solve the Portswigger labs using ZAP, in this case: ‘Path Traversal Simple Case’
ZAPThere's now a ZAP Slack that's open to everyone. You can get an invite to it via
https://www.zaproxy.org/slack/invite