Try our new research platform with insights from 80,000+ expert users

Qualys Web Application Scanning vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys Web Application Scan...
Average Rating
7.8
Reviews Sentiment
6.9
Number of Reviews
38
Ranking in other categories
Application Security Tools (13th), Static Application Security Testing (SAST) (9th)
Rapid7 InsightAppSec
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
19
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. Qualys Web Application Scanning is designed for Application Security Tools and holds a mindshare of 2.1%, up 2.0% compared to last year.
Rapid7 InsightAppSec, on the other hand, focuses on Dynamic Application Security Testing (DAST), holds 11.8% mindshare, down 12.6% since last year.
Application Security Tools
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Kelvin Oladipo - PeerSpot reviewer
User-friendly scanning provides valuable vulnerability insights, but pricing improvements are needed
Qualys Web Application Scanning ( /products/qualys-web-application-scanning-reviews ) is user-friendly, easy to understand, easy to use, and easy to deploy. Credential scanning is very effective because it goes in-depth into the system, crawling the pages, and reporting on vulnerabilities. The product helps by providing options for remediating vulnerabilities it finds, making it really useful.
Shritam Bhowmick - PeerSpot reviewer
Provides reliable applications security but needs better integration options
There are areas for improvements regarding false positives. Integration capabilities are lacking, as options for integrations with other tools such as SNOW, Jira, or other integration tools are not sufficient in Rapid7 InsightAppSec. The user interface sometimes has glitches, which may prevent appropriate results during navigation, and even when we get appropriate results, it can be impossible to export them to CSV records or download files. Regarding scalability, Rapid7 InsightAppSec is not a scalable solution for our industry due to limited integration capabilities. Rapid7 relies on another tool called InsightConnect, which requires additional investment, detracting from scalability. Another area that needs improvement is the integration of AI capabilities into the platform. Both Rapid7 InsightAppSec and InsightVM need to advance in that area. In terms of behavioral and pattern recognition, identifying complex attacks such as SQL, blind SQL, JSON, and LDAP injections often results in 94% false positives. This necessitates improvement in their behavioral-based analytics feature.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Qualys Web Application Scanning is accurate and provides minimal false positives."
"The most valuable feature of Qualys Web Application Scanning is the effective scanning that can be done."
"Qualys Web Application Scanning has multiple features like threat protection and container security scanning in one box."
"It is easy to use."
"Its most valuable features are patch management, vulnerability management, and PCI compliance."
"The most valuable features are the scheduled scanning, detailed reports, asset management, the knowledge database, and the overall product framework."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
"The templates feature is very easy. You just choose the kind of attack you want on your web application, and you run it against that template and receive a report. It's great."
"It is a very robust solution."
"It is very convenient to get reports from the tool, which offers high-level environmental statistics."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"Relatively speaking, InsightAppSec is good compared to Insight VM."
"We have seen measurable decrease in the mean time to respond to threats by 20 percent."
"I rate stability ten out of ten."
 

Cons

"I have dealt with Qualys's technical support, and any enhancements are challenging. I would rate them a five out of ten."
"The pricing does not seem to be competitive."
"In certain cases, this product does have false positives, which the company should work on."
"The software’s pricing could be improved."
"The product should allow users to upload their payloads."
"The reporting contains too many false positives."
"They should try to include business logic vulnerabilities in the scanner testing."
"Deployment can be complicated."
"There is room for improvement in the response time of customer service and support levels."
"The number of web applications we can scan is limited."
"In the future, if they can have integration with a lot of ticketing systems then it would be amazing."
"The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports."
"The product’s pricing could be flexible."
"The dynamic scanning feature has simplified and improved the security testing process. I suggest adding a SaaS feature to the solution to support scanning SaaS applications, making it more comprehensive. It would be beneficial if the solution could also scan mobile applications. It only scans web applications and should also cover mobile applications, including firmware recommendations."
"Rapid7 InsightAppSec needs improvement in detecting phishing pages."
"The reporting is definitely an aspect of the solution that's in need of some work. We found that we'd try to use widgets, but often getting them to work for us wasn't very clear. They need to be more user friendly or offer better instructions."
 

Pricing and Cost Advice

"We normally purchase an annual license."
"The product has a very good licensing model."
"There are different options available with respect to licensing."
"I rate the software’s pricing a six out of ten."
"The product pricing is fair and reasonably priced."
"From my perspective, it is a budget-friendly option."
"The product is expensive, at least initially, in comparison to other products in this category."
"Qualys has an IT-based licensing based on a yearly license, which is a good way of handling it. However, in some cases, when we do the PCI scanning, the host will not like the scanning and we lose the IT license. So, this could be improved."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"Its price is competitive. It is not expensive."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"Rapid7 InsightAppSec is cheap."
"I'm not sure how much it costs exactly, but I know it's expensive."
"The price of this product is very cheap."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
861,524 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
10%
Government
7%
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
13%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What needs improvement with Qualys Web Application Scanning?
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus ( /products/tenable-nessus-reviews ). After using the product for a year, I might have more s...
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
There are areas for improvements regarding false positives. Integration capabilities are lacking, as options for integrations with other tools such as SNOW, Jira, or other integration tools are not...
What is your primary use case for Rapid7 InsightAppSec?
Our main use case for Rapid7 InsightAppSec is to perform internal assessment of applications and external facing applications. We have a cloud engine plus on-premises engine, and we have been lever...
 

Also Known As

Qualys WAS
InsightAppSec
 

Overview

 

Sample Customers

BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about Qualys Web Application Scanning vs. Rapid7 InsightAppSec and other solutions. Updated: May 2022.
861,524 professionals have used our research since 2012.