Try our new research platform with insights from 80,000+ expert users

Fortify WebInspect vs PortSwigger Burp Suite Professional comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortify WebInspect
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd), DevSecOps (8th)
PortSwigger Burp Suite Prof...
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
62
Ranking in other categories
Application Security Tools (8th), Static Application Security Testing (SAST) (6th), Fuzz Testing Tools (1st)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Fortify WebInspect is designed for Dynamic Application Security Testing (DAST) and holds a mindshare of 30.1%, down 33.7% compared to last year.
PortSwigger Burp Suite Professional, on the other hand, focuses on Application Security Tools, holds 1.8% mindshare, down 2.0% since last year.
Dynamic Application Security Testing (DAST)
Application Security Tools
 

Featured Reviews

Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
Anton Krivonosov - PeerSpot reviewer
A special tool for penetration testers or security specialists to conduct security assessments
We use the solution for security assessments. It's a special tool for penetration testers or security specialists PortSwigger Burp Suite Professional is a standard tool in the security industry. It's a stable solution that has many features. You can download different plugins if you don't have…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution's technical support was very helpful."
"The solution is easy to use."
"It is easy to use, and its reporting is fairly simple."
"The feature that has been most influential in identifying vulnerabilities is its ability to crawl the website, understand the structure, and analyze the network packets sent and received."
"Guided Scan option allows us to easily scan and share reports."
"The most valuable feature of this solution is the ability to make our customers more secure."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"The user interface is ok and it is very simple to use."
"This tool is more accurate than the other solutions that we use, and reports fewer false positives."
""The product is very good just the way it is; It has everything already well established and functions great. I can't see any way for this current version to be improved.""
"The most valuable feature of PortSwigger Burp Suite Professional is the Burp Intruder tool."
"I have found the best features to be the performance and there are a lot of additional plugins available."
"The initial setup is simple."
"Some of the extensions, available using Burp Extender, are also very good and we have found issues by using them."
"Enables automation of different tasks such as authorization testing."
"The tool provides complimentary services. It allows you to add a lot of extensions, and you can get extensions quite often. It is quite a flexible application."
 

Cons

"Not sufficiently compatible with some of our systems."
"Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environment."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"I want to enhance automation. Currently, Fortify WebInspect can scan and find vulnerabilities, but users with specific skills need to interpret the results and understand how to address them."
"A localized version, for example, in Korean would be a big improvement to this solution."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"We have often encountered scanning errors."
"The solution’s pricing could be improved."
"The solution’s pricing could be improved."
"The Burp Collaborator needs improvement. There also needs to be improved integration."
"Scanning needs to be improved in enterprise and professional versions."
"Mitigating the issues and low confluence issues needs some improvement. Implementing demand with the ChatGPT under the web solution is an additional feature I would like to see in the next release."
"The initial setup is a bit complex."
"The vendor must provide documentation on how to use the new API feature."
"The price could be better. The rest is fine."
 

Pricing and Cost Advice

"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"The pricing is not clear and while it is not high, it is difficult to understand."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"It’s a fair price for the solution."
"This solution is very expensive."
"The price is okay."
"Fortify WebInspect is a very expensive product."
"There are different licenses available that include a free version."
"Our licensing cost is approximately $400 USD per year."
"It has a yearly license. I am satisfied with its price."
"PortSwigger Burp Suite Professional is an expensive solution."
"We are using the community version, which is free."
"PortSwigger Burp Suite Professional is expensive compared to other tools."
"The pricing of the solution is cost-effective and is best suited for small and medium-sized businesses."
"At $400 or $500 per license paid annually, it is a very cheap tool."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
15%
Government
14%
Manufacturing Company
13%
Computer Software Company
17%
Financial Services Firm
12%
Government
11%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
Fortify WebInspect can be a bit expensive. However, considering its stability and reliability in meeting current standards, the cost is justified. Still, making the cost more affordable for multipl...
What needs improvement with Fortify WebInspect?
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about PortSwigger Burp Suite Professional?
The solution helped us discover vulnerabilities in our applications.
What is your experience regarding pricing and costs for PortSwigger Burp Suite Professional?
The pricing for Burp Suite Professional is not very high, however, it could be more flexible for clients.
 

Also Known As

Micro Focus WebInspect, WebInspect
Burp
 

Overview

 

Sample Customers

Aaron's
Google, Amazon, NASA, FedEx, P&G, Salesforce
Find out what your peers are saying about Fortify WebInspect vs. PortSwigger Burp Suite Professional and other solutions. Updated: May 2022.
824,053 professionals have used our research since 2012.