First things first both are having their own merits, however in my personal experience ZAP can replace your burpsuite for sure considering the License. Also as the latest ZAP versions are covering more advanced techniques and spidering patterns with lots of options in it, it is worth considering ZAP. However remember that burpsuite from latest versions with inbuilt chromium and it's emerging plugin support (Installable jars) you can use burp to the fullest and you can keep it as a swiss knife for your web and app pentesting. Couple of extensions in burp pro are interesting especially the race condition one. I always prefer using Burp and at instances I go with ZAP.
One of the most popular comparisons on IT Central Station is OWASP Zap vs PortSwigger Burp.
People like you are trying to decide which one is best for their company. Can you help them out?
What is the biggest difference between OWASP Zap and PortSwigger Burp? Which of these two solutions would you recommend to a colleague evaluating application security testing tools and why?Thanks for helpin...