Checkmarx One vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Average Rating
7.6
Number of Reviews
67
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (11th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Imperva Web Application Fir...
Average Rating
8.6
Number of Reviews
47
Ranking in other categories
Web Application Firewall (WAF) (6th)
 

Market share comparison

As of June 2024, in the Application Security Tools category, the market share of Checkmarx One is 13.2% and it decreased by 13.7% compared to the previous year. The market share of Imperva Web Application Firewall is 0.0% and it decreased by 76.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
Unique Categories:
Static Application Security Testing (SAST)
10.2%
Vulnerability Management
1.3%
Web Application Firewall (WAF)
7.0%
 

Featured Reviews

RB
Jul 11, 2022
Useful automation , detailed reports, but scalability could improve
We use Checkmarx as a code analysis tool We have always used some kind of code analysis tool and Checkmarx has been working for us at this time. We like the tool. The most valuable feature of Checkmarx are the automation and information that it provides in the reports. I am using Checkmarx for…
AA
Feb 5, 2024
A proactive security solution that protects web applications and APIs and enables easy administration
The solution is used by SMBs and enterprises that have a lot of websites that they need to protect Since the product is categorized in Gartner as a Web Application and API Protection tool, it protects APIs and web applications. It provides bot and client-side protection. I have done POCs. Once…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Apart from software scanning, software composition scanning is valuable."
"The main advantage of this solution is its centralized reporting functionality, which lets us track issues, then see and report on the priorities via a web portal."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"From my point of view, it is the best product on the market."
"The value you can get out of the speedy production may be worth the price tag."
"The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"It's not an obstacle for developers. They can easily write their code and make it more secure with Checkmarx."
"The most valuable features of Imperva Web Application Firewall are the monitoring of databases and the dashboards are easy to understand."
"The most valuable feature of Imperva, in addition to its strong knowledge base, is its effective protection for web applications."
"Its inline transferring mode is the most valuable because it is 100% transparent. When you change the IP, there is no change on the network side. If you can't and want to try to reach an IP, you can reach the server IP. There are many other advanced security features in it. The smallest appliances of Imperva can handle the highest traffic at a customer site. For example, a smaller appliance from Imperva can provide you the same security as an F5 product."
"It has fewer false positives"
"The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
"The features I have found most valuable with Imperva Web Application Firewall are account takeover protection, advanced bot protection, and API security."
"The solution has been quite stable. I have not seen any bugs at all."
"There are a number of features that are valuable such as the account takeover and various antivirus features."
 

Cons

"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"Checkmarx is not good because it has too many false positive issues."
"We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
"I would like to see the tool’s pricing improved."
"Creating and editing custom rules in Checkmarx is difficult because the license for the editor comes at an additional cost, and there is a steep learning curve."
"I would like to see the DAST solution in the future."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
"The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"They can provide an option to create reports, automatically import the entire report, and create rules again. In a real-life crisis, it would be helpful to be able to import a report and generate security rules from that report. I should be able to create a simple query and import the reports automatically. It can maybe also tell us the format of the report."
"Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
"Some of the features should be included in the next release is a file integrating monitoring tool. This feature should be improved."
"One potential improvement for Imperva is enhancing its alert system."
"Sometimes, support tickets don't get addressed quickly."
"I would like the solution to improve its support response time."
 

Pricing and Cost Advice

"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"We have purchased an annual license to use this solution. The price is reasonable."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"It is an expensive solution."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"It is the right price for quality delivery."
"The tool is expensive."
"The price is high compared to other solutions like FortiWeb."
"The cost of this solution depends on the platform."
"The price of this solution is a little bit high compared to competitors."
"It is very costly, but the return on investment is very high. Its cost was around $70,000, and we got it back in just six months."
"The pricing is somewhat expensive. It is actually a huge investment when compared to other countries."
"Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF."
"Imperva Web Application Firewall's pricing is expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
9%
Government
5%
Financial Services Firm
18%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The solution's price is high and you pay based on the number of users.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Learn More

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Checkmarx One vs. Imperva Web Application Firewall and other solutions. Updated: March 2019.
787,061 professionals have used our research since 2012.