Try our new research platform with insights from 80,000+ expert users

HCL AppScan vs PortSwigger Burp Suite Professional comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024
 

Categories and Ranking

HCL AppScan
Ranking in Application Security Tools
15th
Ranking in Static Application Security Testing (SAST)
13th
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
43
Ranking in other categories
Dynamic Application Security Testing (DAST) (1st)
PortSwigger Burp Suite Prof...
Ranking in Application Security Tools
8th
Ranking in Static Application Security Testing (SAST)
6th
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
62
Ranking in other categories
Fuzz Testing Tools (1st)
 

Mindshare comparison

As of December 2024, in the Application Security Tools category, the mindshare of HCL AppScan is 2.6%, down from 2.8% compared to the previous year. The mindshare of PortSwigger Burp Suite Professional is 1.8%, down from 2.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Gladwin Christian - PeerSpot reviewer
A useful tool to scan applications that can be easily installed
Given that we have been using HCL AppScan for many years, I think the setup process is not difficult at all. Sometimes, some issues stop or prevent my company from moving forward with the product's setup phase. We have to call HCL's support team and engage in long discussions to smoothly carry out the setup phase. In general, the product's setup phase is not difficult in our company. The solution is deployed on an on-premises model. The licenses for the solution are available only on cloud deployments nowadays. The solution is already installed in our environment. Every time a new release or software comes out from HCL, our company does a scan, which takes maybe a day or two.
Anton Krivonosov - PeerSpot reviewer
A special tool for penetration testers or security specialists to conduct security assessments
We use the solution for security assessments. It's a special tool for penetration testers or security specialists PortSwigger Burp Suite Professional is a standard tool in the security industry. It's a stable solution that has many features. You can download different plugins if you don't have…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase."
"The solution offers services in a few specific development languages."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"This is a stable solution."
"You can easily find particular features and functions through the UI."
"The most valuable feature of the solution is Postman."
"The solution is easy to use."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"The technical support from PortSwigger is excellent, managing response time and quality efficiently without any issues."
"There is no other tool like it. I like the intuitiveness and the plugins that are available."
"PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up."
"For pentesting scenarios, this is the number one tool. It can capture the request, and there are so many functions that are very good for that. For example, a black box satellite host."
"The solution has a pretty simple setup."
"The reporting part is the most valuable. It also has very good features. We use almost all of the features for different kinds of customers and needs."
"We use the solution for vulnerability assessment in respect of the application and the sites."
"Enables automation of different tasks such as authorization testing."
 

Cons

"It's a little bit basic when you talk about the Web Services. If AppScan improved its maturity on Web Services testing, that would be good."
"Improving usability could enhance the overall experience with AppScan. It would be beneficial to make the solution more user-friendly, ensuring that everyone can easily navigate and utilize its features."
"AppScan needs to improve its handling of false positives."
"The product has some technical limitations."
"​IBM Security AppScan Source is rather hard to use​."
"We would like to integrate with some of the other reporting tools that we're planning to use in the future."
"Improvement can be done as per customer requirements."
"They have to improve support."
"One thing that is not up to the mark in PortSwigger is web application testing. I found some issues with its performance and reporting. They should work on these and give us a better outcome."
"There were a lot of false positives there, and we used to spend a lot of time, like, for security reasons, reproducing those bugs for the development team to fix it."
"There needs to be better documentation provided. Currently, we need to buy books, or we need to review online some use cases from other professionals who have been using the solution to find out their experience. It is not easy to find out how to properly do a security assessment."
"The Auto Scanning features should be updated more frequently and should include the latest attack vectors."
"The reporting needs to be improved; it is very bad."
"The Initial setup is a bit complex."
"The scanner and crawler need to be improved."
"Improvement should be done as per the requirements of customers."
 

Pricing and Cost Advice

"Our clients are willing to pay the extra money. It is expensive."
"The solution is cheap."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"The price is very expensive."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
"HCL AppScan is expensive."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"With the features, that they offer, and the support, they offer, AppScan pricing is on a higher level."
"The cost is approximately $500 for a single license, and there are no additional costs beyond the standard licensing fees."
"We have one license. The price is very nominal."
"Pricing is not very high. It was around $200."
"The solution is reasonably priced."
"There are different licenses available that include a free version."
"At $400 or $500 per license paid annually, it is a very cheap tool."
"It's a lower priced tool that we can rely on with good standard mechanisms."
"It has a yearly license. I am satisfied with its price."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
817,354 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
19%
Financial Services Firm
15%
Manufacturing Company
11%
Government
10%
Computer Software Company
17%
Financial Services Firm
12%
Government
11%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
They could incorporate AI to enhance vulnerability detection and improve the product's reporting capabilities.
What is your primary use case for HCL AppScan?
We use AppScan primarily for security testing and performance monitoring across our systems.
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about PortSwigger Burp Suite Professional?
The solution helped us discover vulnerabilities in our applications.
What is your experience regarding pricing and costs for PortSwigger Burp Suite Professional?
I would rate the pricing a six out of ten. It's not as flexible here as it might be in European or American markets.
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
Burp
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Google, Amazon, NASA, FedEx, P&G, Salesforce
Find out what your peers are saying about HCL AppScan vs. PortSwigger Burp Suite Professional and other solutions. Updated: December 2024.
817,354 professionals have used our research since 2012.