Try our new research platform with insights from 80,000+ expert users

GitHub vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 29, 2024
 

Categories and Ranking

GitHub
Ranking in Application Security Tools
7th
Average Rating
8.8
Reviews Sentiment
7.5
Number of Reviews
92
Ranking in other categories
Version Control (3rd)
Qualys Web Application Scan...
Ranking in Application Security Tools
13th
Average Rating
7.8
Reviews Sentiment
7.4
Number of Reviews
35
Ranking in other categories
Static Application Security Testing (SAST) (12th)
 

Mindshare comparison

As of December 2024, in the Application Security Tools category, the mindshare of GitHub is 0.8%, down from 0.9% compared to the previous year. The mindshare of Qualys Web Application Scanning is 1.9%, down from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

AjayKrishna - PeerSpot reviewer
Reduces project delivery times and costs
I think one area where GitHub could improve is its search and navigation functionality within repositories. For example, we use IDEs like IntelliJ or Visual Studio Code when developing code. These IDEs allow us to easily navigate from one piece of code to another file where a method is being called. It would be really helpful if the solution could add this navigation feature. It would allow us to move from one class file to another more easily, helping us search quicker and follow the code flow completely within GitHub. This would be more convenient than having to import the code into our local IDE to look at the code flow and navigate through it. Adding this kind of IDE-like navigation within the tool would make the user experience more seamless and efficient.
SubhajitAich - PeerSpot reviewer
A stable solution that can be used for infrastructure vulnerability scanning and web application scanning
Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly. Compared to other solutions like Tenable and Rapid7, you need to navigate a lot to get the actual results out of Qualys Web Application Scanning. If I have to search for one thing within the entire console, I have to look for it randomly. It's not very easy and very comfortable to find something. Overall, it's a very good solution, but it will be very good if the tool is more user-friendly.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"GitHub provides enough storage for uploading the source code."
"GitHub is easy, secure, and widely documented."
"Our code is secure."
"You can get the differences, history of changes, and version control for various pull requests."
"The most valuable features are GitHub are the standard features, they are very useful."
"GitHub provides good time reduction and this is what I value the most."
"The most valuable features are GitHub Actions for triggering workflows, GitHub Secrets for saving credentials without needing a third-party service, and the UI for identifying errors in the code when we commit."
"Has great integration with third-party tools."
"​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​"
"Licensing is the most valuable. Qualys provides the best licensing for companies. It is the best product for the development purposes of web applications. The product has a lot of integrations."
"The interface is user-friendly and easy to understand."
"Automated scanning has significantly improved our web application security management by reducing manual work."
"It scans web applications to identify vulnerabilities during deployment."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"It works with many different products."
 

Cons

"I would want to see some form of code security scanning implemented."
"The onboarding process could be simplified."
"There can be conflict issues when two developers work on the same file or line of code, and it would be great to see that improved, possibly with an AI solution."
"It is difficult to merge a code or restore it to an older version."
"There could be some improvements related to the automation of certain processes, especially with the integration of artificial intelligence."
"Our firewall was blocking cloning and downloading with SSH."
"The user interface on GitLab is better."
"I would like to see some AI functionality included in GitHub, similar to the features seen in GitLab, to enhance productivity."
"The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."
"When comparing this solution to Veracode, Veracode has good interactive features and gives a clear understanding of what the vulnerabilities are, which error line of the vulnerability is on and what can be done. It gives interactive features, whereas this solution does not give a clear understanding of where or how to fix the problem."
"The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes."
"The support could be faster."
"There should be better visibility into the application."
"The virus code updates are not frequent enough."
"We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."
"They should try to include business logic vulnerabilities in the scanner testing."
 

Pricing and Cost Advice

"GitHub is an open-source application. It's free to use."
"My company purchased it. Before, we used to receive the free version, but then they purchased some of the features."
"GitHub is a cost-effective solution."
"You don't have to pay for a license if you are using the free version."
"We have an enterprise licensing agreement, and I am not part of the finance department so I can't say how much it costs."
"The price of this solution is reasonable."
"I think, in terms of price, GitHub is okay compared to other tools."
"I use the free version of GitHub."
"We normally purchase an annual license."
"Pricing was reasonable and competitive. It was not too far above the other products."
"Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved."
"The product has a very good licensing model."
"The product pricing is fair and reasonably priced."
"We are on an annual license for the solution and the pricing could be more affordable."
"It is an expensive platform."
"The cost is $30,000 USD for one year to cover WAS (Web Application Security) and the VM (Virtual Machine) security in a company with 200 employees."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
824,053 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
12%
Financial Services Firm
12%
Computer Software Company
12%
University
7%
Computer Software Company
16%
Financial Services Firm
16%
Manufacturing Company
10%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about GitHub?
The control is the most valuable feature as developers can work on a single code.
What is your experience regarding pricing and costs for GitHub?
I'm not aware of the costs associated with GitHub. I simply appreciate its efficiency in managing code and collaborating with team members.
What needs improvement with GitHub?
I would like to see some AI functionality included in GitHub, similar to the features seen in GitLab, to enhance productivity. Additionally, offering limited free access to features like Copilot co...
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What needs improvement with Qualys Web Application Scanning?
One area for improvement is the user interface. The new UI, which was recently upgraded, feels more complex and less user-friendly than the old version. However, as we continue to use it, we antici...
 

Also Known As

No data available
Qualys WAS
 

Learn More

 

Overview

 

Sample Customers

Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about GitHub vs. Qualys Web Application Scanning and other solutions. Updated: December 2024.
824,053 professionals have used our research since 2012.