Try our new research platform with insights from 80,000+ expert users

Apache JMeter vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.0
Apache JMeter is cost-effective, scalable, and integrates with CICD, offering significant ROI without licensing costs.
Sentiment score
1.7
HCL AppScan enhances architecture with fewer errors and improved security, achieving 50% return and 20% cost savings.
With Apache JMeter, I have gained great statistics for performance and server metrics.
Automation Architect at Aion Digital
 

Customer Service

Sentiment score
6.3
Apache JMeter relies on a large community for support, offering helpful but sometimes delayed assistance compared to commercial tools.
Sentiment score
5.6
HCL AppScan's support is responsive with mixed reviews, facing regional challenges and lagging behind competitors like Veracode.
With AI models ChatGPT, troubleshooting issues has become very easy for us.
Principal Performance Architect at Tecnotree Corporation
The support for Apache JMeter is excellent.
Software QA Engineer at a consultancy with 10,001+ employees
Apache JMeter has strong support through its vast Java-based community on platforms like Stack Overflow.
Automation Architect at Aion Digital
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
There is still room for improvement when it comes to the speed of response.
Founder Director at Techsa Services
 

Scalability Issues

Sentiment score
6.6
Apache JMeter is scalable but faces challenges with high loads and complex configurations, benefiting from distributed and cloud setups.
Sentiment score
3.9
HCL AppScan is scalable yet varies by license, integration issues, infrastructure compatibility, and CI/CD pipeline design effectiveness.
We do have some methods where we can distribute the complete load between multiple systems and then try to do our testing.
QA Manager at Synechron
JMeter is highly scalable, easily handling increased loads through the use of multiple servers.
Software QA Engineer at a consultancy with 10,001+ employees
This restricts the number of users and necessitates increasing load agents or distributing the script across multiple machines.
Senior Solution Architect at HCLSoftware
 

Stability Issues

Sentiment score
7.2
Apache JMeter is reliable but faces stability issues with high loads and requires careful management for enterprise applications.
Sentiment score
7.2
HCL AppScan is stable and reliable, with minor hardware issues, improved by recent upgrades enhancing performance and stability.
JMeter performs exceptionally well, especially in non-GUI mode, which supports high loads efficiently.
Software QA Engineer at a consultancy with 10,001+ employees
Several necessary features still need improvements, specifically in terms of reports and additional functionalities compared to other commercial tools.
Senior Solution Architect at HCLSoftware
Previous versions of Apache JMeter were a little unstable, but the new versions are very stable.
Principal Performance Architect at Tecnotree Corporation
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Founder Director at Techsa Services
 

Room For Improvement

Apache JMeter needs enhanced user-friendliness, scalability, protocol support, and better integration with CI/CD tools and documentation.
HCL AppScan requires improvements in vulnerability detection, usability, integration, performance, support, pricing, and language/codebase compatibility to stay competitive.
With AI becoming more prominent, they can implement features where it can generate code by itself based on the results or provide suggestions.
Principal Performance Architect at Tecnotree Corporation
Currently, we need to use multiple separate JMeter instances to simulate reductions in load, which isn't ideal.
Software QA Engineer at a consultancy with 10,001+ employees
The tool needs improvements related to client-side metrics, integrating with tools like YSlow or HTTP Watch, and enhancing mobile testing capabilities.
Senior Solution Architect at HCLSoftware
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
Founder Director at Techsa Services
 

Setup Cost

Apache JMeter is a cost-effective, open-source performance testing tool suitable for smaller projects with extensive community and plugin support.
HCL AppScan is considered expensive but cost-effective, with varied pricing opinions influenced by its premium features and discounts.
Using JMeter helps us avoid additional costs for high-load testing since it is open-source and allows for unlimited virtual users at no extra cost.
Software QA Engineer at a consultancy with 10,001+ employees
It's a cost-effective solution.
Senior Solution Architect at HCLSoftware
Apache JMeter is completely free as it is open-source.
Sr.Engineer csit Quality Assurance at Verizon
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
 

Valuable Features

Apache JMeter offers a user-friendly, open-source platform for scalable, automated, and cost-effective performance testing with strong community support.
HCL AppScan detects vulnerabilities, integrates with agile processes, offers scalability, user-friendly features, and AI-enhanced rapid scanning for security.
JMeter facilitates scripting capabilities, which include options for Groovy scripts.
Senior Solution Architect at HCLSoftware
It's useful for both the person conducting the test and the higher management, like project managers or senior executives, who may not know about the test.
Performance Test Engineer at CEI
Despite being open source, it offers features comparable to paid tools.
Sr.Engineer csit Quality Assurance at Verizon
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
Founder Director at Techsa Services
 

Categories and Ranking

Apache JMeter
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
96
Ranking in other categories
Performance Testing Tools (1st), Load Testing Tools (1st), API Testing Tools (2nd)
HCL AppScan
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
44
Ranking in other categories
Application Security Tools (20th), Static Application Security Testing (SAST) (17th), Dynamic Application Security Testing (DAST) (4th)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Apache JMeter is designed for Performance Testing Tools and holds a mindshare of 12.8%, down 24.2% compared to last year.
HCL AppScan, on the other hand, focuses on Application Security Tools, holds 2.3% mindshare, down 2.6% since last year.
Performance Testing Tools Market Share Distribution
ProductMarket Share (%)
Apache JMeter12.8%
OpenText Professional Performance Engineering (LoadRunner Professional)12.1%
Tricentis NeoLoad10.0%
Other65.1%
Performance Testing Tools
Application Security Tools Market Share Distribution
ProductMarket Share (%)
HCL AppScan2.3%
SonarQube17.9%
Checkmarx One10.2%
Other69.6%
Application Security Tools
 

Featured Reviews

RR
Principal Performance Architect at Tecnotree Corporation
Have built custom performance test scripts and integrated them into automated pipelines seamlessly
Apache JMeter has its own pros and cons when compared to other tools. It is easy to use the tool and it has open-source capability so we can build our custom scripts and execute them. It provides other capabilities, such as integrating a database and connecting to other application servers for monitoring and related functions. We use dynamic HTML reporting, which helps us in testing analysis by pinpointing the bottlenecks based on the reports. We can identify the specific areas that need attention, troubleshoot them, and report to the development team. The user-friendly GUI for creating and managing tests makes it very easy to drag and drop samplers. For example, if you want the HTTP sampler, you can drag and drop it and use it. For configurations, we have other samplers. For results, we have the view results samplers that we can also drag and drop. The UI is good in comparison with other tools. Regarding integration with CI/CD pipelines, we can create Apache JMeter scripts and use the Docker image. From the image, whatever scripting we have done can be connected. We can use the CI/CD pipelines and connect them with Jenkins tools and GitHub. Then we can create the pipelines and automate the end-to-end flow. For connecting Jenkins to Apache JMeter, JMeter plugins are available, and we have used them. Apache JMeter also has some third-party plugins, which are not native samplers. If we want to use custom test executions, we definitely use all the different plugins available in Apache JMeter. The capability to simulate users has impacted testing resources and outcomes as Apache JMeter is based on Java, which has a limit to the users in a particular load generator. Apache JMeter provides distributed load testing where you can connect multiple PCs in a master and slave concept, allowing you to pump the load with any number of users. In the past, I have done load testing with 10,000 users by connecting the Apache JMeter distributed network in BlazeMeter. There is a cloud version available, the updated BlazeMeter, and I used that. It is very easy to launch load generators in BlazeMeter, and then we can run the test, scaling up beyond 10,000 users.
Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Has improved identification of encryption and authentication issues across cloud and on-prem applications
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interface. However, there is one feature called SCA, which stands for Software Composition Analysis, that could be improved. When I'm doing an application scan, HCL AppScan has the ability to generate information about what components are in use. For example, if I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present. I would like to see more detailed reports from the tool. Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities. For instance, I could identify that I had the Log4j vulnerability and know that I need to fix my application accordingly. If they add the features I'm describing, I would consider giving them a higher rating. However, I've only been experienced with the product for three months.
report
Use our free recommendation engine to learn which Performance Testing Tools solutions are best for your needs.
881,036 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
12%
Manufacturing Company
8%
Retailer
6%
Computer Software Company
12%
Financial Services Firm
12%
Government
11%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise24
Large Enterprise56
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise31
 

Questions from the Community

How does Postman compare with Apache JMeter?
Postman lets you easily define variables, which then get updated automatically. This is a huge time-saver and makes processes very efficient. We can also export the test cases we create and share t...
How does BlazeMeter compare with Apache JMeter?
Blazemeter is a continuous testing platform that provides scriptless test automation. It unifies functional and performance testing, enabling users to monitor and test public and private APIs. We ...
What do you like most about Apache JMeter?
I appreciate JMeter's simplicity and power for performance testing.
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interf...
What is your primary use case for HCL AppScan?
I'm currently working with BigFix and HCL AppScan. At least three people in my company are using HCL AppScan. Since we are a reseller, we run it in both lab environments and live production applica...
 

Also Known As

JMeter
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

AOL, Orbitz, Innopath Software, PrepMe, Sapient, Corporate Express Australia, CSIRO, Ephibian, Talis, DATACOM, ALALOOP, eFusion, Panter, Sourcepole, University of Western Cape
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about Apache, Tricentis, Perforce and others in Performance Testing Tools. Updated: January 2026.
881,036 professionals have used our research since 2012.