We performed a comparison between GitLab and Rapid7 InsightAppSec based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The dashboard and interface make it easy to use."
"The most valuable feature of GitLab is the automatic merging of code."
"The solution's service delivery model is fantastic."
"Key features allow creation of well-presented Wiki that includes ideas, development, and domains."
"CI/CD is valuable for me."
"It is scalable."
"We use the Git repository and tagging feature. We are a product-based company and use this solution to move to a forward or backward tag."
"The code merging capability is something that we use very frequently."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"It is very convenient to get reports from the tool, which offers high-level environmental statistics."
"In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"We have seen measurable decrease in the mean time to respond to threats by 20 percent."
"The product’s most valuable feature is UI. It is easy to manage and find vulnerabilities in the application."
"The solution is stable."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"GitLab would be improved with the addition of templates for deployment on local PCs."
"I used Spring Cloud config and to connect that to GitLab was so hard."
"The integration and storage capabilities could be better."
"Even if I say I want some improvement, they will say it is already planned in the first quarter, second quarter, or third quarter. That said, most everything is quite improved already, and they're improving even further still."
"The price of GitLab could improve, it is high."
"The solution could improve by providing more integration into the CI/CD pipeline, an autocomplete search tool, and more supporting documentation."
"As GitLab is not perfect, what needs improvement in the solution is the Wiki feature of the groups or the repertories because currently, it's not searchable by default. You'll need an indexing service such as Elasticsearch to make it searchable, and that requires too much work, so for me, it's the main feature that should be improved in GitLab. In the next version of the solution, from the top of my head, the documentation could be improved. Besides the Wiki, it would be good if there's documentation that would be automatically generated based on the code repository. In other words, there should be some tutorials from GitLab for developers in the next release."
"The documentation is confusing."
"I would like more details of what the product can do."
"We'd like to see integrations with WAF solutions."
"They should add more features. I would like to see them do a little more on static analysis and also interactivity analysis. Currently, it does very basic static analysis. It could do a little more static analysis, which is something that would help. A lot more interactivity analysis should also be there. It should basically look at security during interactivity."
"The only concern I have with Rapid7 is that it does not provide enough information about vulnerabilities within AppSec."
"We get a lot of false positives during the tests."
"The product’s pricing could be flexible."
"The reporting is definitely an aspect of the solution that's in need of some work. We found that we'd try to use widgets, but often getting them to work for us wasn't very clear. They need to be more user friendly or offer better instructions."
"In the future, if they can have integration with a lot of ticketing systems then it would be amazing."
GitLab is ranked 6th in Application Security Tools with 70 reviews while Rapid7 InsightAppSec is ranked 3rd in Dynamic Application Security Testing (DAST) with 12 reviews. GitLab is rated 8.6, while Rapid7 InsightAppSec is rated 8.6. The top reviewer of GitLab writes "Powerful, mature, and easy to set up and manage". On the other hand, the top reviewer of Rapid7 InsightAppSec writes "A highly scalable and robust product that enables users to automate scans". GitLab is most compared with Microsoft Azure DevOps, SonarQube, Bamboo, AWS CodePipeline and Tekton, whereas Rapid7 InsightAppSec is most compared with Rapid7 AppSpider, OWASP Zap, PortSwigger Burp Suite Professional, Fortify WebInspect and Acunetix. See our GitLab vs. Rapid7 InsightAppSec report.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.