Try our new research platform with insights from 80,000+ expert users

Kiuwan vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Kiuwan
Ranking in Static Application Security Testing (SAST)
25th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
23
Ranking in other categories
Application Security Tools (29th)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
7th
Average Rating
7.6
Reviews Sentiment
7.5
Number of Reviews
39
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of February 2025, in the Static Application Security Testing (SAST) category, the mindshare of Kiuwan is 0.9%, down from 0.9% compared to the previous year. The mindshare of OWASP Zap is 5.0%, down from 6.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
 

Featured Reviews

Mustufa Bhavnagarwala - PeerSpot reviewer
Though a stable tool, the UI needs improvement
Kiuwan can improve its UI a little more. The user experience can be made better. Kiuwan offers a user interface that is similar to the one offered by Windows 7 or Windows 98, which I saw when I ran the tool and tried to scan the repository to find the security issues. The product's UI has certain shortcomings, where improvements are required.
Amit Beniwal - PeerSpot reviewer
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I've tried many open source applications and the remediation or correction actions that were provided by Kiuwan were very good in comparison."
"Software analytics for a lot of different languages including ABAP."
"​We use Kiuwan to locate the source of application vulnerabilities."
"Lifecycle features, because they permit us to show non-technical people the risk and costs hidden into the code due to bad programming practices."
"The most valuable feature is the time to resolution, where it tells you how long it is going to take to get to a zero-base or a five-star security rating."
"The solution has a continuous integration process."
"The most valuable feature of the solution stems from the fact that it is quick when processing and giving an output or generating a report."
"I've found the reporting features the most helpful."
"It can be used effectively for internal auditing."
"The interface is easy to use."
"The most valuable feature is scanning the URL to drill down all the different sites."
"The OWASP's tool is free of cost, which gives it a great advantage, especially for smaller companies to make use of the tool."
"You can run it against multiple targets."
"OWASP Zap is a good tool, one of my favorites for a long time, and I would recommend it."
"The API is exceptional."
"This solution has improved my organization because it has made us feel safer doing frequent deployments for web applications. If we have something really big, we might get some professional company in to help us but if we're releasing small products, we will check it ourselves with Zap. It makes it easier and safer."
 

Cons

"The solution seems to give us a lot of false positives. This could be improved quite a bit."
"The integration process could be improved. It'll also help if it could generate reports automatically. But I'm not sure about the effectiveness of the reports. This is because, in our last project, we still found some key issues that weren't captured by the Kiuwan report."
"It could improve its scalability abilities."
"I would like to see better integration with the Visual Studio and Eclipse IDEs."
"The development-to-delivery phase."
"It would be beneficial to streamline calls and transitions seamlessly for improved functionality."
"The next release should include more flexibility in the reporting."
"I would like to see additional languages supported."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"The product should allow users to customize the report based on their needs."
"It needs more robust reporting tools."
"Deployment is somewhat complicated."
"The work that it does in the limited scope is good, but the scope is very limited in terms of the scanning features. The number of things it tests or finds is limited. They need to make it a more of a mainstream tool that people can use, and they can even think about having it on a proprietary basis. They need to increase the coverage of the scan and the results that it finds. That has always been Zap's limitation. Zap is a very good tool for a beginner, but once you start moving up the ladder where you want further details and you want your scan to show more in-depth results, Zap falls short because its coverage falls short. It does not have the capacity to do more."
"The technical support team must be proactive."
"The product reporting could be improved."
"ZAP's integration with cloud-based CICD pipelines could be better. The scan should run through the entire pipeline."
 

Pricing and Cost Advice

"Nothing special. It's a very fair model."
"Kiuwan is an open-source solution and free to use."
"This solution is cheaper than other tools."
"The price of Kiuwan is lower than that of other tools on the market."
"Check with your account manager."
"I recommend contacting a sales person who will create the best plan payment plan for you, as we did."
"It follows a subscription model. I think the price is somewhere in the middle."
"We have used the freeware version. I believe Zap only has freeware."
"The tool is open source."
"The tool is open-source."
"The solution’s pricing is high."
"It's free and open, currently under the Apache 2 license. If ZAP does what you need it to do, selling a free solution is a very easy."
"This app is completely free and open source. So there is no question about any pricing."
"This solution is open source and free."
"This is an open-source solution and can be used free of charge."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
838,713 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Computer Software Company
16%
Comms Service Provider
8%
Manufacturing Company
7%
Computer Software Company
18%
Financial Services Firm
12%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Kiuwan?
The most valuable feature of the solution stems from the fact that it is quick when processing and giving an output or generating a report.
What is your experience regarding pricing and costs for Kiuwan?
I'm not entirely sure about the price and business aspects, but I assume Checkmarx might be less expensive. I think Checkmarx might offer more affordable options, especially in its smaller business...
What needs improvement with Kiuwan?
Kiuwan can improve its UI a little more. The user experience can be made better. Kiuwan offers a user interface that is similar to the one offered by Windows 7 or Windows 98, which I saw when I ran...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
 

Comparisons

 

Overview

 

Sample Customers

DHL, BNP Paribas, Zurich, AXA, Ernst & Young, KFC, Santander, Latam, Ferrovial
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Kiuwan vs. OWASP Zap and other solutions. Updated: January 2025.
838,713 professionals have used our research since 2012.