Try our new research platform with insights from 80,000+ expert users

Fortify WebInspect vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Customer Service

Sentiment score
4.9
Fortify WebInspect support receives varied reviews, with some citing slow responses, while others praise quick resolutions and knowledgeable staff.
No sentiment score available
 

Room For Improvement

Sentiment score
4.6
Fortify WebInspect users want improved cloud integration, user-friendliness, efficiency, mobile testing, and better reporting with reduced resource consumption.
No sentiment score available
 

Scalability Issues

Sentiment score
7.1
Fortify WebInspect offers scalability, with cloud setups excelling, but on-premises deployments face limitations and budget concerns.
No sentiment score available
 

Setup Cost

No sentiment score available
Fortify WebInspect is seen as expensive with complex licensing; suited for larger enterprises, but costly for smaller ones.
No sentiment score available
 

Stability Issues

Sentiment score
7.5
Fortify WebInspect is stable but struggles with complex sites, showing occasional bugs and resource-heavy performance issues.
No sentiment score available
 

Valuable Features

Sentiment score
8.3
Fortify WebInspect delivers efficient vulnerability detection, scalable scanning, and user-friendly reporting with easy setup and security standard alignment.
No sentiment score available
 

Categories and Ranking

Fortify WebInspect
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd), DevSecOps (9th)
OWASP Zap
Average Rating
7.6
Reviews Sentiment
7.4
Number of Reviews
37
Ranking in other categories
Static Application Security Testing (SAST) (7th)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Fortify WebInspect is designed for Dynamic Application Security Testing (DAST) and holds a mindshare of 31.2%, down 33.7% compared to last year.
OWASP Zap, on the other hand, focuses on Static Application Security Testing (SAST), holds 5.1% mindshare, down 6.3% since last year.
Dynamic Application Security Testing (DAST)
Static Application Security Testing (SAST)
 

Featured Reviews

Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
AnkithKumar - PeerSpot reviewer
Great for automating and testing and has tightened our security
I'd like to see more regular updates with new features and I'd like to see resources where users can internally access a learning module from the tool. It would be helpful for any user interested in developing their skills. They have all the built-ins but it's not user-friendly in the sense that the UI is not as easy as you'd find in a solution such as the Burp Suite.
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
816,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
16%
Government
14%
Manufacturing Company
13%
Computer Software Company
19%
Financial Services Firm
12%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
Fortify WebInspect can be a bit expensive. However, considering its stability and reliability in meeting current standards, the cost is justified. Still, making the cost more affordable for multipl...
What needs improvement with Fortify WebInspect?
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
 

Also Known As

Micro Focus WebInspect, WebInspect
No data available
 

Learn More

 

Overview

 

Sample Customers

Aaron's
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Fortify WebInspect vs. OWASP Zap and other solutions. Updated: May 2022.
816,406 professionals have used our research since 2012.