Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Average Rating
7.6
Reviews Sentiment
7.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (16th), Static Code Analysis (2nd), API Security (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Imperva Web Application Fir...
Average Rating
8.6
Number of Reviews
51
Ranking in other categories
Web Application Firewall (WAF) (6th)
 

Mindshare comparison

Checkmarx One and Imperva Web Application Firewall aren’t in the same category and serve different purposes. Checkmarx One is designed for Application Security Tools and holds a mindshare of 12.9%, down 15.0% compared to last year.
Imperva Web Application Firewall, on the other hand, focuses on Web Application Firewall (WAF), holds 6.4% mindshare, down 7.1% since last year.
Application Security Tools
Web Application Firewall (WAF)
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Feb 19, 2024
Provides good security analysis and security identification within the source code
We use the solution to validate the source code and do SAST and security analysis. Checkmarx dynamics code analysis improved our software security posture by showcasing vulnerabilities within the code and identifying or providing recommendations on how to improve The solution's user interface…
Abdullah Jin - PeerSpot reviewer
Sep 9, 2024
Offers bot protection and DDoS Protection and protects public-facing portals
Support is one thing I wish Imperva could improve. They follow the phone model and keep rotating you from one customer service person to another. The layer one support isn't very clear about the workings of the product. My feedback is primarily about Imperva Cloud, not on-premise. On-premise is a whole new story. Support is the issue for Imperva Cloud. It's also a bit pricey. It's a premium service and very expensive. The licensing model is not very straightforward. Every feature is priced separately, and to enjoy maximum protection, you'll have to spend a lot of money. The licensing model is a bit complex, and each feature is very pricey. For example, API security and web application protection are two separate license packages.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It can integrate very well with DAST solutions. So both of them are combined into an integrated solution for customers running application security."
"It gives the proper code flow of vulnerabilities and the number of occurrences."
"The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important."
"The user interface is modern and nice to use."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"The most valuable feature is the simple user interface."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"Imperva Web Application Firewall is a highly stable solution and is very mature."
"Imperva is a Gartner leader, so its scalability, performance, and features are excellent."
"The solution can scale."
"The solution is very scalable. It is one of the most important features. You can also expand resources and features as well."
"The most valuable feature of Imperva, in addition to its strong knowledge base, is its effective protection for web applications."
"Learning mode and custom policies are helpful features."
"The compliance is the most valuable aspect."
"It mitigates all of the availabilities of risks around web applications."
 

Cons

"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe. It would help if there was more scanning or if the process was more automated."
"I would like to see the DAST solution in the future."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"I would like to see the rate of false positives reduced."
"The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
"The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."
"The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."
"The tool's UI is complicated. It would be best to have a more accessible UI dashboard to make the job easier."
"I would like to improve the tool's turnaround time in terms of support."
"It would be useful if the solution used more intelligence in attack protection. For example, firewalls are to be dependent on the configuration, but if they could have some data science around it the solution would be even better. The profiling of the traffic, and making decisions surrounding that should be intelligence-based, instead of being based on the configuration of the firewall itself."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"Imperva Web Application Firewall could improve the API integration. It was complex for us. Additionally, The onboarding could be better."
"The signature updates could be faster. Sometimes we have to upload signatures to the Imperva portal for checking and analysis before we can use them."
"Imperva Web Application Firewall is a good system, but we found that the visibility of the diverse-path server, e.g. where the traffic is coming from, the different IPs, etc., needs improvement."
"The process to upgrade from one version to another can be a lot simpler than it is currently."
 

Pricing and Cost Advice

"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"I believe pricing is better compared to other commercial tools."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"Its price is fair. It is in or around the right spot. Ultimately, if the price is wrong, customers won't commit, but they do tend to commit. It is neither too cheap nor too expensive."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"It's an excellent product, but it can be very costly."
"The pricing is somewhat expensive. It is actually a huge investment when compared to other countries."
"Imperva’s pricing is a bit higher in the market since it offers a full-blown WAF."
"The tool is expensive."
"The solution's pricing is an issue."
"Imperva Web Application Firewall's pricing is expensive."
"Make sure you understand the way that Imperva charges. It's very affordable. However, I would like to see a package with the Virtual Patching included. You get to do patching separately."
"The price of this solution is a little bit high compared to competitors."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
815,854 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
Financial Services Firm
17%
Computer Software Company
14%
Manufacturing Company
7%
Insurance Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DefensePro and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Learn More

 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Checkmarx One vs. Imperva Web Application Firewall and other solutions. Updated: March 2019.
815,854 professionals have used our research since 2012.