Try our new research platform with insights from 80,000+ expert users

HCL AppScan vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

HCL AppScan
Ranking in Dynamic Application Security Testing (DAST)
1st
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
43
Ranking in other categories
Application Security Tools (14th), Static Application Security Testing (SAST) (10th)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
4th
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of HCL AppScan is 16.3%, down from 27.2% compared to the previous year. The mindshare of Rapid7 InsightAppSec is 12.2%, down from 13.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Rishi Anupam - PeerSpot reviewer
A stable and scalable scanning solution with good reporting feature
The solution is used for the vulnerabilities scan on the network side The reporting part is the most valuable feature. The penetration testing feature should be included. I have been using the solution for four years. It is a stable solution. I rate it seven out of ten. It is a scalable…
Krzysztof Witko - PeerSpot reviewer
Automated authorization streamlines security processes
The previous product, AppSpyder, had a virtual patching module where we could generate patches for third-party web application firewalls, such as Imperva or F5. Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version. Virtual patching could help protect web pages shortly after finishing the scan process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"AppScan is stable."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"You can easily find particular features and functions through the UI."
"It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
"The most valuable feature of the solution is Postman."
"It was easy to set up."
"It has certainly helped us find vulnerabilities in our software, so this is priceless in the end."
"I rate stability ten out of ten."
"When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports."
"Dynamic application security scanning provides predefined templates and supports customization. The ability to scan external and internal applications, including on-premises ones, is precious. Additionally, it is a cloud platform, so we don't need to deploy servers or resources. This makes it time-efficient and cost-effective."
"It is a very robust solution."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"We have seen measurable decrease in the mean time to respond to threats by 20 percent."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"Rapid7 InsightAppSec helps us in both regulatory compliance and in strengthening our security posture."
 

Cons

"The solution could improve by having a mobile version."
"It has crashed at times."
"​IBM Security AppScan Source is rather hard to use​."
"The solution often has a high number of false positives. It's an aspect they really need to improve upon."
"Sometimes it doesn't work so well."
"They could add a software component analysis tool."
"In future releases, I would like to see more aggressive reports. I would also like to see less false positives."
"We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices."
"The product’s pricing could be flexible."
"The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
"They should add more features. I would like to see them do a little more on static analysis and also interactivity analysis. Currently, it does very basic static analysis. It could do a little more static analysis, which is something that would help. A lot more interactivity analysis should also be there. It should basically look at security during interactivity."
"We get a lot of false positives during the tests."
"In the future, if they can have integration with a lot of ticketing systems then it would be amazing."
"Rapid7 InsightAppSec needs improvement in detecting phishing pages."
"The only concern I have with Rapid7 is that it does not provide enough information about vulnerabilities within AppSec."
 

Pricing and Cost Advice

"Pricing was the main reason that we went ahead with this solution as they were the lowest in the market."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"HCL AppScan is expensive."
"The tool was expensive."
"AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost."
"Our clients are willing to pay the extra money. It is expensive."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"I'm not sure how much it costs exactly, but I know it's expensive."
"Rapid7 InsightAppSec is cheap."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"The price of this product is very cheap."
"Its price is competitive. It is not expensive."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
847,862 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Financial Services Firm
14%
Government
11%
Manufacturing Company
9%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
12%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
There is room for improvement in Rapid7 InsightAppSec by giving clients the ability for extra columns on reports and enabling the extraction of remediation reports into a CSV format. Currently, the...
What is your primary use case for Rapid7 InsightAppSec?
Our primary use case for Rapid7 InsightAppSec ( /products/rapid7-insightappsec-reviews ) is to scan for vulnerabilities on our APIs and UIs. We provide this service while being based at a client lo...
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
InsightAppSec
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about HCL AppScan vs. Rapid7 InsightAppSec and other solutions. Updated: March 2025.
847,862 professionals have used our research since 2012.