Try our new research platform with insights from 80,000+ expert users

PortSwigger Burp Suite Professional vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

PortSwigger Burp Suite Prof...
Average Rating
8.6
Reviews Sentiment
7.9
Number of Reviews
63
Ranking in other categories
Application Security Tools (9th), Static Application Security Testing (SAST) (6th), Fuzz Testing Tools (1st)
Rapid7 InsightAppSec
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
17
Ranking in other categories
Dynamic Application Security Testing (DAST) (4th)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. PortSwigger Burp Suite Professional is designed for Application Security Tools and holds a mindshare of 2.0%, up 2.0% compared to last year.
Rapid7 InsightAppSec, on the other hand, focuses on Dynamic Application Security Testing (DAST), holds 11.9% mindshare, down 13.2% since last year.
Application Security Tools
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Anuradha.Kapoor Kapoor - PeerSpot reviewer
Offers efficient scanning of entire websites but presence of false positive bugs, leading to time-consuming efforts in distinguishing real bugs from false alarms
We have found that so many times, false positive bugs are there, and then we spend a lot of time basically separating them from real bugs. So that's the reason we are looking for some other tool. So we were in discussion with Acunetix. Therefore, the false positive rate is, like, something that we would like to improve. What we are looking for is if this false positive rate goes down because we were OWASP Zap tool users, which was free anyway. But there were a lot of false positives there, and we used to spend a lot of time, like, for security reasons, reproducing those bugs for the development team to fix it. So then we thought, okay, why not we go with the tool? Even if it is not very expensive. But still, every year, we have to renew the license. And we got this tool. Again, we found that in this tool also, even if it is less, there are still a lot of false positive bugs out there. So we again have to spend so much time. So we hired a security tester, who was basically using Acunetix in his previous company for almost three years, and then you said that in that scanning is very slow. The scanning is also slow. Like, sometimes the site scan takes eight hours, six to eight hours. Yeah. And whereas in Acunetix, it took three to four hours. And plus, there are no false positives. I'm not saying none but there's very little. But here, the rate sometimes is very high. These are the two features I think we would like to improve further.
Krzysztof Witko - PeerSpot reviewer
Automated authorization streamlines security processes
The previous product, AppSpyder, had a virtual patching module where we could generate patches for third-party web application firewalls, such as Imperva or F5. Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version. Virtual patching could help protect web pages shortly after finishing the scan process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The extension that it provides with the community version for the skills mapping is excellent."
"We use the solution for vulnerability assessment in respect of the application and the sites."
"The solution helped us discover vulnerabilities in our applications."
"It is useful for scanning and tracing activities."
"The technical support from PortSwigger is excellent, managing response time and quality efficiently without any issues."
"The solution is quite helpful for session management and configuration."
"The solution has a pretty simple setup."
"It offers very good accuracy. You can trust the results."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"It's very easy to use and user-friendly. It does the job."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"Relatively speaking, InsightAppSec is good compared to Insight VM."
"In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions."
"The solution is stable."
"I would rate the technical support from Rapid7 a ten, indicating high-quality support."
 

Cons

"The pricing of the solution is quite high."
"The Auto Scanning features should be updated more frequently and should include the latest attack vectors."
"The solution lacks sufficient stability."
"As with most automated security tools, too many false positives."
"If we're running a huge number of scans regularly, it slows down the tool."
"I would like to see a more optimized solution, as it currently uses a lot of CPU power and memory."
"The number of false positives need to be reduced on the solution."
"Scanning needs to be improved in enterprise and professional versions."
"I required a solution to manage on-premises, but I was not as satisfied as expected."
"There is room for improvement in the response time of customer service and support levels."
"Rapid7 InsightAppSec needs improvement in detecting phishing pages."
"I would like more details of what the product can do."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
"We get a lot of false positives during the tests."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange. They need to work a little bit more on their interface to make it more understandable. The interface is the only problem. I'm using Rapid7, which is very intuitive. There are other applications available in the market with a better interface. They can include more techniques or options to test different types of security because the templates are limited. It would be great to see them follow the MITRE ATT&CK framework or what is there in tools like Veracode and Synopsys."
"The reporting is definitely an aspect of the solution that's in need of some work. We found that we'd try to use widgets, but often getting them to work for us wasn't very clear. They need to be more user friendly or offer better instructions."
 

Pricing and Cost Advice

"The solution used to be expensive. However, they have reduced the price to approximately $400.00 which is reasonable."
"For a country such as Sri Lanka, the pricing is not reasonable."
"It is expensive for us in Brazil because the currency exchange rate from a dollar to a Brazilian Real is quite steep."
"We pay a yearly licensing fee for the solution, which is neither cheap nor expensive."
"Our licensing cost is approximately $400 USD per year."
"There is no setup cost and the cost of licensing is affordable."
"PortSwigger Burp Suite Professional is an expensive solution."
"There are different licenses available that include a free version."
"I'm not sure how much it costs exactly, but I know it's expensive."
"Rapid7 InsightAppSec is cheap."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"The price of this product is very cheap."
"Its price is competitive. It is not expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
842,388 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
13%
Government
12%
Manufacturing Company
7%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
12%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about PortSwigger Burp Suite Professional?
The solution helped us discover vulnerabilities in our applications.
What is your experience regarding pricing and costs for PortSwigger Burp Suite Professional?
The pricing for Burp Suite Professional is not very high, however, it could be more flexible for clients.
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports. It would be beneficial if there were an option for customers to customize reports to include ...
What is your primary use case for Rapid7 InsightAppSec?
We primarily use Rapid7 InsightAppSec for application security within our organization. We perform penetration testing on our in-house-built, Java-based web applications to comply with regulatory s...
 

Also Known As

Burp
InsightAppSec
 

Overview

 

Sample Customers

Google, Amazon, NASA, FedEx, P&G, Salesforce
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about PortSwigger Burp Suite Professional vs. Rapid7 InsightAppSec and other solutions. Updated: May 2022.
842,388 professionals have used our research since 2012.