The ".zip" TLD isn't itself a security risk, but it should never have been created in the first place due to the overlap with .zip files.
Understanding the context of why the .zip TLD is a bad idea, you should be questioning the general competence of a web admin that would intentionally purchase and operate a .zip website. There are plenty of other cheap TLDs available that do not overlap with common file extensions. It's such an obvious and avoidable problem that you have to wonder what other obvious problems they are failing to avoid.
Among other serious problems, this would disenfranchise all military service members stationed or deployed outside their home state. The Democrats really should be making a big deal out of that.