Try our new research platform with insights from 80,000+ expert users

Apache JMeter vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
Apache JMeter offers scalable, cost-effective performance testing, integrating well with CICD and outperforming HP Performance Center in returns.
Sentiment score
2.1
HCL AppScan enhances architecture with fewer errors and improved security, achieving 50% return and 20% cost savings.
With Apache JMeter, I have gained great statistics for performance and server metrics.
 

Customer Service

Sentiment score
6.3
Apache JMeter relies on community support, praised for efficiency but lacking the dedicated assistance of commercial tools.
Sentiment score
5.4
HCL AppScan's support is responsive with mixed reviews, facing regional challenges and lagging behind competitors like Veracode.
With AI models ChatGPT, troubleshooting issues has become very easy for us.
The support for Apache JMeter is excellent.
Apache JMeter has strong support through its vast Java-based community on platforms like Stack Overflow.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
 

Scalability Issues

Sentiment score
6.6
Apache JMeter is scalable for large loads, but requires careful configuration and infrastructure, especially for enterprise-level setups.
Sentiment score
4.9
HCL AppScan is scalable yet varies by license, integration issues, infrastructure compatibility, and CI/CD pipeline design effectiveness.
JMeter is highly scalable, easily handling increased loads through the use of multiple servers.
This restricts the number of users and necessitates increasing load agents or distributing the script across multiple machines.
For backend automation and performance testing with web services, web APIs, and queue management systems, I would rate Apache JMeter's scalability as between eight and nine.
 

Stability Issues

Sentiment score
7.2
Apache JMeter is stable but may face memory issues under high loads; effective in non-GUI mode with proper management.
Sentiment score
6.8
HCL AppScan is stable and reliable, with minor hardware issues, improved by recent upgrades enhancing performance and stability.
JMeter performs exceptionally well, especially in non-GUI mode, which supports high loads efficiently.
Several necessary features still need improvements, specifically in terms of reports and additional functionalities compared to other commercial tools.
Previous versions of Apache JMeter were a little unstable, but the new versions are very stable.
 

Room For Improvement

Apache JMeter needs UI, reporting, and automation improvements to handle complex scenarios, large loads, and enhance overall usability.
HCL AppScan requires improvements in vulnerability detection, usability, integration, performance, support, pricing, and language/codebase compatibility to stay competitive.
With AI becoming more prominent, they can implement features where it can generate code by itself based on the results or provide suggestions.
Currently, we need to use multiple separate JMeter instances to simulate reductions in load, which isn't ideal.
The tool needs improvements related to client-side metrics, integrating with tools like YSlow or HTTP Watch, and enhancing mobile testing capabilities.
 

Setup Cost

Enterprise users prefer Apache JMeter for its cost-effectiveness and flexibility in performance testing without licensing fees.
HCL AppScan is considered expensive but cost-effective, with varied pricing opinions influenced by its premium features and discounts.
Using JMeter helps us avoid additional costs for high-load testing since it is open-source and allows for unlimited virtual users at no extra cost.
It's a cost-effective solution.
Apache JMeter is completely free as it is open-source.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
 

Valuable Features

Apache JMeter is praised for its user-friendliness, cost-effectiveness, plugin support, and integration capabilities in performance testing.
HCL AppScan detects vulnerabilities, integrates with agile processes, offers scalability, user-friendly features, and AI-enhanced rapid scanning for security.
JMeter facilitates scripting capabilities, which include options for Groovy scripts.
It's useful for both the person conducting the test and the higher management, like project managers or senior executives, who may not know about the test.
Despite being open source, it offers features comparable to paid tools.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
 

Categories and Ranking

Apache JMeter
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
95
Ranking in other categories
Performance Testing Tools (1st), Load Testing Tools (1st), API Testing Tools (2nd)
HCL AppScan
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
43
Ranking in other categories
Application Security Tools (15th), Static Application Security Testing (SAST) (14th), Dynamic Application Security Testing (DAST) (1st)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Apache JMeter is designed for Performance Testing Tools and holds a mindshare of 16.1%, down 24.8% compared to last year.
HCL AppScan, on the other hand, focuses on Application Security Tools, holds 2.5% mindshare, down 2.6% since last year.
Performance Testing Tools Market Share Distribution
ProductMarket Share (%)
Apache JMeter16.1%
OpenText Professional Performance Engineering (LoadRunner Professional)13.6%
Tricentis NeoLoad12.9%
Other57.4%
Performance Testing Tools
Application Security Tools Market Share Distribution
ProductMarket Share (%)
HCL AppScan2.5%
SonarQube Server (formerly SonarQube)20.4%
Checkmarx One10.4%
Other66.7%
Application Security Tools
 

Featured Reviews

Shashidhara Allalappa - PeerSpot reviewer
Extensive Protocol Support and Precise Reporting Elevate Testing, Though GUI Usability Needs Improvement
The GUI of Apache JMeter is not that user-friendly because we have many proxies, and we have to record through the proxy. With the limited SSL we have, we cannot use it for UI, which is a drawback. However, Apache JMeter is really good for REST APIs. I don't think there are any other areas other than the GUI that I would want improved about Apache JMeter; it is generally good and supports multiple protocols.
AnshulTomar - PeerSpot reviewer
Scalable platform with efficient static and dynamic testing features
We use the product for Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). By integrating AppScan into our CI/CD pipelines, aligned with Agile methodologies, we ensure that security testing becomes an integral part of the software development lifecycle The…
report
Use our free recommendation engine to learn which Performance Testing Tools solutions are best for your needs.
872,019 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
7%
Government
7%
Computer Software Company
15%
Financial Services Firm
12%
Government
10%
Manufacturing Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise24
Large Enterprise55
By reviewers
Company SizeCount
Small Business13
Midsize Enterprise6
Large Enterprise31
 

Questions from the Community

How does Postman compare with Apache JMeter?
Postman lets you easily define variables, which then get updated automatically. This is a huge time-saver and makes processes very efficient. We can also export the test cases we create and share t...
How does BlazeMeter compare with Apache JMeter?
Blazemeter is a continuous testing platform that provides scriptless test automation. It unifies functional and performance testing, enabling users to monitor and test public and private APIs. We ...
What do you like most about Apache JMeter?
I appreciate JMeter's simplicity and power for performance testing.
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
 

Also Known As

JMeter
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

AOL, Orbitz, Innopath Software, PrepMe, Sapient, Corporate Express Australia, CSIRO, Ephibian, Talis, DATACOM, ALALOOP, eFusion, Panter, Sourcepole, University of Western Cape
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about Apache, Perforce, Tricentis and others in Performance Testing Tools. Updated: October 2025.
872,019 professionals have used our research since 2012.