No more typing reviews! Try our Samantha, our new voice AI agent.

Salt Security vs Tenable Nessus comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Salt Security
Average Rating
7.0
Reviews Sentiment
9.0
Number of Reviews
2
Ranking in other categories
API Security (7th), AI Security (41st)
Tenable Nessus
Average Rating
8.4
Reviews Sentiment
6.0
Number of Reviews
88
Ranking in other categories
Vulnerability Management (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Salt Security is designed for API Security and holds a mindshare of 7.0%, down 13.0% compared to last year.
Tenable Nessus, on the other hand, focuses on Vulnerability Management, holds 4.1% mindshare, down 9.5% since last year.
API Security Mindshare Distribution
ProductMindshare (%)
Salt Security7.0%
Imperva Application Security Platform9.6%
Akamai API Security7.4%
Other76.0%
API Security
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Tenable Nessus4.1%
Wiz5.0%
Qualys VMDR4.2%
Other86.7%
Vulnerability Management
 

Featured Reviews

TV
Sr Investigation Specialist at Ifood
Improved API visibility has revealed sensitive data exposures and supports faster remediation
Alert tuning can require some time depending on API volume. Some findings need internal validation before actioning. The collaboration flows between security and engineering teams could be expanded further. While the solution was straightforward to set up and gave me the visibility that I needed, it has to improve some details and features to achieve a perfect rating.
MohammedJaffir - PeerSpot reviewer
Founder at Cipheroot
Has enabled me to reduce false positives and perform deep credential auditing with seamless integrations
I mostly use the configuration audit feature for the audit configuration as a scan policy, and I will use it for credential audit, which helps me scan credentials access such as local administrator or root access, performing a deeper and more accurate check of local configuration settings and file systems, making it a highly recommended feature. Regarding integration capabilities, we can integrate Tenable Nessus with SIM tools such as Splunk, IBM QRadar, and Azure Sentinel, as well as with ticketing systems such as ServiceNow, Jira, and Slack. There is no complexity as it is very easy to integrate everything. In terms of the reporting feature, while vulnerability scanning can throw some false positives, Tenable Nessus has very few, achieving a reduction of 75% to 80% false positives with manual analysis needed. We can generate standard Nessus reports that typically include host summaries and vulnerabilities by host and plugin, alongside solutions and remediation recommendations. The main benefits I get from Tenable Nessus are complete asset inventory and comprehensive attack surface management, allowing us to prioritize vulnerabilities based on risk, focusing on true risk and threat path analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Salt Security gave me much better visibility into API risk, helping me identify exposed endpoints, misconfigured APIs, and sensitive data flowing through APIs that required additional controls, and it has become an important part of my API security program."
"It's really great. I would rate the stability a nine out of ten. I haven't encountered any instability issues."
"Salt Security gives you visibility of all your APIs, identifies API security issues, and immediately alerts you of attacks."
"I like its ease of use. It has the script that is pre-built in it, and you just got to know which ones you're looking for."
"It's scalable."
"The solution can scale well."
"Personally, I think Nessus is quite a good product."
"The most valuable feature of Tenable Nessus is real-time monitoring."
"Nessus is good at finding out what nodes you have in place. It will then provide you a report, by node, of what the vulnerabilities are. It does it quickly and stealthfully."
"To me, that was a better selling point because it was real: it wasn't demo data, it was our own network showing, "Hey, we're vulnerable because of this, and here's the tool that did it," which got us the buy-in we needed from upper management."
"For me, the key value is the ease of use and integration with SIEMs because it has built-in integrations with IBM QRadar and others."
 

Cons

"The integration part could be a bit extended."
"The setup cost was acceptable, but adding additional APIs was actually quite expensive."
"The integration part could be a bit extended."
"We operate in small and medium enterprises and for them, Nessus is becoming expensive."
"From my point of view the solution basically is not for the big enterprise."
"The features are limited when it comes to scanning network devices for vulnerabilities."
"It would be better if they had application-level support for mobile devices. They don't have anything to scan mobile devices. Tenable Nessus doesn't have a mobile application vulnerability assessment. I also have issues with the false positive rates. The product has limited features."
"We would like to have the option of using the solution for the cloud as well as on-premises with the same license at the same time. That would be very helpful."
"Tenable Nessus could include a broader range of IT assets."
"The solution should be able to support more devices."
"One area that has room for improvement is the reporting. I'm preparing reports for Windows and Linux machines, etc. Currently, I'm collecting three or four reports and turning them into one report. I don't know if it is possible to combine all of them in one report, but that would be helpful."
 

Pricing and Cost Advice

Information not available
"Nessus is affordable, but its licensing model could be improved with more flexibility for adding assets."
"We pay approximately $2,500 on a yearly basis."
"Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly. The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job."
"The product pricing is dynamic and varies based on the specific needs of each project and customer."
"This solution is affordable."
"The price of the solution is reasonable."
"The solution has a single price for unlimited assets."
"We paid about six thousand dollars per license."
report
Use our free recommendation engine to learn which API Security solutions are best for your needs.
896,387 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Manufacturing Company
12%
Financial Services Firm
11%
Construction Company
8%
Financial Services Firm
10%
Manufacturing Company
10%
Government
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise19
Large Enterprise35
 

Questions from the Community

Ask a question
Earn 20 points
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. You can easily prioritize vulnerabilities using attacker analytics. Overall, Rapid...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of the program is such that if a company should desire to handle the installation t...
What is your experience regarding pricing and costs for Tenable Nessus?
Based on my experience, the pricing for Tenable Nessus is somewhat higher, but customers still want to pay for it, so it remains acceptable. The annual price increase of six to seven percent could ...
 

Also Known As

Salt Security API Protection Platform
No data available
 

Overview

 

Sample Customers

Appsflyer, Armis, City National Bank, Coralogix, Finastra, Gett, Honeybook, Payoneer
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about Akamai, Imperva, Orca Security and others in API Security. Updated: May 2026.
896,387 professionals have used our research since 2012.