Try our new research platform with insights from 80,000+ expert users

Fortify WebInspect vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Fortify WebInspect
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
21
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd), DevSecOps (7th)
Qualys Web Application Scan...
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
38
Ranking in other categories
Application Security Tools (12th), Static Application Security Testing (SAST) (9th)
 

Mindshare comparison

While both are Application Lifecycle Management solutions, they serve different purposes. Fortify WebInspect is designed for Dynamic Application Security Testing (DAST) and holds a mindshare of 23.9%, down 32.6% compared to last year.
Qualys Web Application Scanning, on the other hand, focuses on Application Security Tools, holds 2.0% mindshare, down 2.2% since last year.
Dynamic Application Security Testing (DAST)
Application Security Tools
 

Featured Reviews

Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
SubhajitAich - PeerSpot reviewer
A stable solution that can be used for infrastructure vulnerability scanning and web application scanning
Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly. Compared to other solutions like Tenable and Rapid7, you need to navigate a lot to get the actual results out of Qualys Web Application Scanning. If I have to search for one thing within the entire console, I have to look for it randomly. It's not very easy and very comfortable to find something. Overall, it's a very good solution, but it will be very good if the tool is more user-friendly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a well-known platform for doing dynamic application scanning."
"The feature that has been most influential in identifying vulnerabilities is its ability to crawl the website, understand the structure, and analyze the network packets sent and received."
"Reporting, centralized dashboard, and bird's eye view of all vulnerabilities are the most valuable features."
"The user interface is ok and it is very simple to use."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"Fortify WebInspect is a scalable solution, it is good for a lot of applications."
"The most valuable feature is the static analysis."
"When we are integrating it with SSC, we're able to scan and trace and see all of the vulnerabilities. Comparison is easy in SSC."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"The Qualys Web Application Scanning solution offers a single comprehensive console and consolidated reporting, covering all aspects from on-prem to cloud and compliance, etcetera."
"Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
"We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
"The tool links vulnerabilities with DDIs and gives a complete overview of the application. The continuous monitoring capability is good."
"It is a very stable solution."
"It is a good product for website penetration testing to detect vulnerabilities."
"With our vulnerabilities under control, it's putting our services in compliance and minimizing our risk for exposure."
 

Cons

"A localized version, for example, in Korean would be a big improvement to this solution."
"We have had a problem with authentification."
"The initial setup was complex."
"The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"Not sufficiently compatible with some of our systems."
"There are some file extensions, like .SER, that Fortify WebInspect doesn't scan."
"I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
"The solution needs to adjust its pricing. They should make it more affordable."
"The product should allow users to upload their payloads."
"In terms of the Policy Compliance model which they currently have, not all the platforms are being covered. If they could improve on the Policy Compliance model, since there are policies which are benchmarked against it, this will be helpful for us."
"I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus."
"It is unclear how to build automation on Qualys. We do some automation, but not fully, because working is difficult."
"The software’s pricing could be improved."
"There could be better management and faster scanning."
"In certain cases, this product does have false positives, which the company should work on."
 

Pricing and Cost Advice

"Fortify WebInspect is a very expensive product."
"This solution is very expensive."
"It’s a fair price for the solution."
"The pricing is not clear and while it is not high, it is difficult to understand."
"The price is okay."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"The product is expensive, at least initially, in comparison to other products in this category."
"Qualys Web Application Scanning's pricing is a bit expensive compared to other solutions available in the market."
"Try the free trial of the product to understand the basic working mechanisms.​"
"It is an expensive platform."
"Pricing was reasonable and competitive. It was not too far above the other products."
"Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved."
"The product pricing is fair and reasonably priced."
"From my perspective, it is a budget-friendly option."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
848,253 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Government
14%
Computer Software Company
14%
Manufacturing Company
12%
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
10%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
Fortify WebInspect can be a bit expensive. However, considering its stability and reliability in meeting current standards, the cost is justified. Still, making the cost more affordable for multipl...
What needs improvement with Fortify WebInspect?
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of...
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What needs improvement with Qualys Web Application Scanning?
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus ( /products/tenable-nessus-reviews ). After using the product for a year, I might have more s...
 

Also Known As

Micro Focus WebInspect, WebInspect
Qualys WAS
 

Overview

 

Sample Customers

Aaron's
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about Fortify WebInspect vs. Qualys Web Application Scanning and other solutions. Updated: May 2022.
848,253 professionals have used our research since 2012.