We are a consulting firm and we provide implementation and deployment of solutions to our customers.
I am very much impressed by the whole technology.
This tool is really fast and the information that they provide on vulnerabilities is pretty good.
The UI is good and it is really easy to use.
With respect to the algorithm that Netsparker is running, they don't really provide the proof of concept up to the level that we need, here in the organization. Specifically, because the tool is running the scan and exploiting the read-only version, it doesn't prove to the customer that the exploit is genuine. We have to perform this manually, but it is difficult to prove to the concerned team, whether it is the development team, the remediation team, or the security team.
Right now, they are missing the static application security part, especially web application security. If they can integrate a SaaS tool with their dynamic one then it would be really helpful.
I have been working with Netsparker for several months.
We have not experienced any bugs or glitches, so it seems stable.
Scalability-wise, it is pretty good.
We have been engaged with the local partner and we get a good level of support.
We also use Micro Focus Fortify and I have not had a chance to compare the scans, but I prefer the interface and ease of use with Netsparker. It is really easy to configure and deploy, as well as communicate this to the client.
The initial setup was not a problem for me, as I have been using these security tools for a while.
Overall, I am satisfied with Netsparker. However, I cannot say at this point that I would recommend it because although it is good, I will now be using it as a benchmark for evaluating other products.
I would rate this solution an eight out of ten.