Try our new research platform with insights from 80,000+ expert users

Fortify WebInspect vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortify WebInspect
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
20
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd), DevSecOps (8th)
Qualys Web Application Scan...
Average Rating
7.8
Reviews Sentiment
7.4
Number of Reviews
35
Ranking in other categories
Application Security Tools (12th), Static Application Security Testing (SAST) (11th)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Fortify WebInspect is designed for Dynamic Application Security Testing (DAST) and holds a mindshare of 28.4%, down 34.1% compared to last year.
Qualys Web Application Scanning, on the other hand, focuses on Application Security Tools, holds 1.9% mindshare, down 2.3% since last year.
Dynamic Application Security Testing (DAST)
Application Security Tools
 

Featured Reviews

Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
SubhajitAich - PeerSpot reviewer
A stable solution that can be used for infrastructure vulnerability scanning and web application scanning
Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly. Compared to other solutions like Tenable and Rapid7, you need to navigate a lot to get the actual results out of Qualys Web Application Scanning. If I have to search for one thing within the entire console, I have to look for it randomly. It's not very easy and very comfortable to find something. Overall, it's a very good solution, but it will be very good if the tool is more user-friendly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The feature that has been most influential in identifying vulnerabilities is its ability to crawl the website, understand the structure, and analyze the network packets sent and received."
"The tool provides comprehensive vulnerability assessments which help ensure our deliverables are as free from vulnerabilities as possible. It has also streamlined our web application vulnerability assessments, assisting us in delivering secure applications to our clients."
"Good at scanning and finding vulnerabilities."
"The accuracy of its scans is great."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"Fortify WebInspect is a scalable solution, it is good for a lot of applications."
"Reporting, centralized dashboard, and bird's eye view of all vulnerabilities are the most valuable features."
"The most valuable feature is the static analysis."
"We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
"Qualys Web Application Scanning has multiple features like threat protection and container security scanning in one box."
"You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
"It scans web applications to identify vulnerabilities during deployment."
"The tool links vulnerabilities with DDIs and gives a complete overview of the application. The continuous monitoring capability is good."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"It is a cloud-based solution, so it is easy to scale."
"​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​"
 

Cons

"I would like WebInspect's scanning capability to be quicker."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"We have had a problem with authentification."
"Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environment."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"One thing I would like to see them introduce is a cloud-based platform."
"Not sufficiently compatible with some of our systems."
"It took us between eight and ten hours to scan an entire site, which is somewhat slow and something that I think can be improved."
"The virus code updates are not frequent enough."
"The support could be faster."
"The reporting contains too many false positives."
"One area for improvement is the user interface. The new UI, which was recently upgraded, feels more complex and less user-friendly than the old version."
"The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."
"The software’s pricing could be improved."
"The solution needs to adjust its pricing. They should make it more affordable."
"It should have better automatic reporting."
 

Pricing and Cost Advice

"The pricing is not clear and while it is not high, it is difficult to understand."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"This solution is very expensive."
"It’s a fair price for the solution."
"The price is okay."
"Fortify WebInspect is a very expensive product."
"The product is expensive, at least initially, in comparison to other products in this category."
"It is an expensive platform."
"The product has a very good licensing model."
"Qualys Web Application Scanning's pricing is a bit expensive compared to other solutions available in the market."
"The product pricing is fair and reasonably priced."
"Try the free trial of the product to understand the basic working mechanisms.​"
"We normally purchase an annual license."
"The cost is $30,000 USD for one year to cover WAS (Web Application Security) and the VM (Virtual Machine) security in a company with 200 employees."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
831,158 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
16%
Government
13%
Manufacturing Company
13%
Computer Software Company
16%
Financial Services Firm
16%
Manufacturing Company
10%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
Fortify WebInspect can be a bit expensive. However, considering its stability and reliability in meeting current standards, the cost is justified. Still, making the cost more affordable for multipl...
What needs improvement with Fortify WebInspect?
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of...
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What needs improvement with Qualys Web Application Scanning?
One area for improvement is the user interface. The new UI, which was recently upgraded, feels more complex and less user-friendly than the old version. However, as we continue to use it, we antici...
 

Also Known As

Micro Focus WebInspect, WebInspect
Qualys WAS
 

Learn More

 

Overview

 

Sample Customers

Aaron's
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about Fortify WebInspect vs. Qualys Web Application Scanning and other solutions. Updated: May 2022.
831,158 professionals have used our research since 2012.