Try our new research platform with insights from 80,000+ expert users

Fortinet FortiWeb vs Rapid7 AppSpider comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortinet FortiWeb
Average Rating
7.8
Number of Reviews
90
Ranking in other categories
Web Application Firewall (WAF) (4th)
Rapid7 AppSpider
Average Rating
7.8
Number of Reviews
13
Ranking in other categories
Static Application Security Testing (SAST) (28th)
 

Mindshare comparison

Fortinet FortiWeb and Rapid7 AppSpider aren’t in the same category and serve different purposes. Fortinet FortiWeb is designed for Web Application Firewall (WAF) and holds a mindshare of 8.4%, up 7.4% compared to last year.
Rapid7 AppSpider, on the other hand, focuses on Static Application Security Testing (SAST), holds 0.5% mindshare, down 0.7% since last year.
Web Application Firewall (WAF)
Static Application Security Testing (SAST)
 

Featured Reviews

Kacem CHAMMALI - PeerSpot reviewer
Apr 1, 2024
Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb
The xFF, or X-Forwarded-For feature, IP reputation, and protected hostname. We can block access using the IP address, so no one can connect to our web server or website using the real IP. They need to use the FQDN instead. Even if an attacker detects the IP address, they can't connect directly to the server due to FortiWeb and the option to protect the hostname. All traffic passes through FortiWeb. Machine learning capabilities in FortiWeb: I don't use machine learning all the time. In the initial phase of FortiWeb deployment, we use the learning process to detect the traffic passing through FortiGate to our website.
Andrei Bigdan - PeerSpot reviewer
May 4, 2023
Useful vulnerability reporting data, flexible, and simple implementation
I am using Rapid7 AppSpider for vulnerability assessment The most valuable feature of Rapid7 AppSpider is the vulnerability reporting data. Additionally, the data is reported in a convenient way rather than seeing them as a PDF. We are able to generate all the reports exactly what we want in a…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of this solution is Fail-Open."
"It is easy to install and to maintain."
"It is a stable product."
"The most valuable features are support and security."
"The WAF profiles has been effective at mitigating web-based threats."
"The support is quite good."
"All the features that FortiGate contains are very suitable for our business. We work with other products in Fortinet, FortiWeb, FortiSandbox, FortiMail, and FortiCache. We use all UTM features like self-encryption, encryption, all UTM features."
"The ease of configuration is valuable. We have Azure WAF, we have OCI WAF, and we also have Cloud Armor for GCP, but their configuration isn't very easy. It's pretty simple in FortiWeb, and we can enable or configure whatever we want."
"Rapid7 AppSpider is good at managing different applications. It uses applets and generates reports to cover the PCA/GDPR compliance requirements."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
"The setup is usually straightforward."
"It scans all the components developed within a web application."
"AppSpider's most valuable feature is reporting - everything is stored in the local database so it can be sent to other machines."
"I like the ability the product has to detect vulnerabilities quickly, when it has been released in our environment, then displaying them to us."
"The initial deployment is very straightforward and simple. The product is stable if configured properly."
"What I like most about AppSpider is that it's easy to use and its automated scan gives me all the details I need to know when it comes to vulnerabilities and their solutions."
 

Cons

"The documentation for the machine learning could be better."
"It may be better if it were easier to create roles."
"A user interface or dashboard for troubleshooting is needed."
"We would like to know more about the integration with the hardware or security products, such as Gemalto, because we need to move to that point."
"They can introduce a scaled-down version for the SMB market. It would be very competitive in the environment."
"The solution is rather complicated. If you know what to do, it's not bad, but it's complicated for a first time user to configure the solution. What I'd like to improve are the custom signatures."
"The initial setup process could be improved."
"The false positives are annoying.​"
"This price of this solution is a little bit expensive."
"One of the challenges I have with AppSpider is that it gives you a lot of false positives, especially when compared to other solutions."
"The performance of the solution could improve. When I compare the speed it is slower than others on the market. There are some tricks we use to help speed up the solution."
"There are some glitches with stability, and it is an area for improvement."
"The enterprise interface is too simple. It should be more customizable."
"AppSpider could improve in the area of integration. They need to add more integration opportunities."
"AppSpider has some problems with the RAM needed while scanning."
"Implementing Rapid7 AppSpider requires scanning and self-identification mechanisms. You can add different types of authentication to each scan."
 

Pricing and Cost Advice

"The cost isn't expensive."
"The pricing is pretty good. We do pass a lot of traffic through our API servers. Something like 100 gigs of web traffic is a fair amount for reduced JSON API calls, but the cost is $50. For that peace of mind, we have thousands and thousands of customers that are protected by that $50, so it's a no-brainer."
"There's only one payment for the duration of the license. On a scale from one to five, I would rate pricing at four. I have not encountered any additional costs on my projects involving Fortinet FortiWeb."
"The pricing is in the middle. I would rate the pricing a five out of ten. It feels like a justified cost for the features."
"The license cost depends on the size of the box or the size of the solution. It can go from €200 Euros to a few hundred thousand Euros a year depending on your size."
"Cheaper than others."
"The pricing is average; the product is neither particularly expensive nor affordable."
"The price of Fortinet FortiWeb is reasonable. This is one of the key factors of why we use this solution."
"The licensing cost depends on the number of users."
"The price is pretty fair."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
814,649 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
42%
Computer Software Company
10%
Financial Services Firm
7%
Government
5%
Computer Software Company
17%
Financial Services Firm
16%
Government
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortinet FortiWeb?
The WAF profiles has been effective at mitigating web-based threats.
What is your experience regarding pricing and costs for Fortinet FortiWeb?
FortiWeb is cheaper by over ten percent compared to other solutions like Barracuda and F5.
What needs improvement with Fortinet FortiWeb?
One area that needs improvement is the handling of SaaS downtime. When there is downtime at their data center, it becomes a transit point issue for us, causing downtime in our environment as well. ...
What do you like most about Rapid7 AppSpider?
The most valuable feature of Rapid7 AppSpider is the vulnerability reporting data. Additionally, the data is reported in a convenient way rather than seeing them as a PDF. We are able to generate a...
What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor. The price of the s...
What needs improvement with Rapid7 AppSpider?
The performance of the solution could improve. When I compare the speed it is slower than others on the market. There are some tricks we use to help speed up the solution.
 

Also Known As

No data available
AppSpider
 

Learn More

 

Overview

 

Sample Customers

Lush, Barnabas Health, Options, Riverside Healthcare, Hillsbourough County Schools, Columbia Public Schools, Schiller AG
Microsoft
Find out what your peers are saying about Amazon Web Services (AWS), Microsoft, F5 and others in Web Application Firewall (WAF). Updated: October 2024.
814,649 professionals have used our research since 2012.