Try our new research platform with insights from 80,000+ expert users
PortSwigger Burp Suite Professional Logo

PortSwigger Burp Suite Professional pros and cons

Vendor: PortSwigger
4.3 out of 5
Badge Ranked 1

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

PortSwigger Burp Suite Professional is highly valued for its ability to automatically and accurately detect vulnerabilities, with special appreciation for the Burp Scanner and Burp Intruder features.
The extensions available through Burp Extender are considered very good, offering options for additional plugins and enabling highly customizable scanning processes.
The automated scanning capabilities are especially useful, as they address the needs of many customers, providing a reliable method for vulnerability assessment while maintaining accuracy and reducing false positives.
The intercepting feature and the ability to manually intervene for API testing provide significant advantages in identifying and fixing vulnerabilities efficiently.
Burp Suite Professional provides excellent technical support, with users rating it ten out of ten for its efficient management of response time and quality.

CONS

PortSwigger Burp Suite Professional requires better reporting options and more informative reports.
The number of false positives is high and needs to be reduced.
It uses a substantial amount of CPU power and memory which affects performance.
API security testing and integration, especially with CI/CD processes, need improvement.
The pricing is considered high by users, particularly in international markets.
 

PortSwigger Burp Suite Professional Pros review quotes

it_user704997 - PeerSpot reviewer
Senior Information Security Analyst at a tech services company with 10,001+ employees
Dec 19, 2017
I personally love its capability to automatically and accurately detect vulnerabilities. So, I would say it is the Burp scanner that is THE most powerful, valuable, and an awesome feature.
Securitydbe0 - PeerSpot reviewer
Security Analyst at a tech services company with 201-500 employees
Feb 3, 2019
"The product is very good just the way it is; It has everything already well established and functions great. I can't see any way for this current version to be improved."
it_user787785 - PeerSpot reviewer
Senior Security Engineer at a insurance company with 10,001+ employees
May 16, 2019
This tool is more accurate than the other solutions that we use, and reports fewer false positives.
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,986 professionals have used our research since 2012.
IB
Security Specialist at Alfa-A IT
May 29, 2019
This solution has helped a lot in finding bugs and vulnerabilities, and the scanner is good enough for simple web apps.
reviewer939417 - PeerSpot reviewer
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees
Jun 6, 2019
Some of the extensions, available using Burp Extender, are also very good and we have found issues by using them.
Jul 7, 2019
BurpSuite helps us to identify and fix silly mistakes that are sometimes introduced by our developers in their coding.
VN
Director - Head of Delivery Services at Ticking Minds Technology Solutions Pvt Ltd
Jan 2, 2020
Once I capture the proxy, I'm able to transfer across. All the requested information is there. I can send across the request to what we call a repeater, where I get to ready the payload that I send to the application. Put in malicious content and then see if it's responding to it.
RO
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
Aug 19, 2019
The Spider is the most useful feature. It helps to analyze the entire web application, and it finds all the passes and offers an automated identification of security issues.
reviewer1112304 - PeerSpot reviewer
IT Manager at a manufacturing company with 10,001+ employees
Jan 22, 2020
The way they do the research and they keep their profile up to date is great. They identify vulnerabilities and update them immediately.
reviewer1261914 - PeerSpot reviewer
AVP - Software Quality Assurance at a tech services company with 201-500 employees
Jan 19, 2020
The suite testing models are very good. It's very secure.
 

PortSwigger Burp Suite Professional Cons review quotes

it_user704997 - PeerSpot reviewer
Senior Information Security Analyst at a tech services company with 10,001+ employees
Dec 19, 2017
The one feature that I would like to see in Burp is active scanning of REST based web services. A lot of organizations are providing APIs to access their services to support different business models like SaaS. Scanning these APIs is still a challenge for many security product companies.
Securitydbe0 - PeerSpot reviewer
Security Analyst at a tech services company with 201-500 employees
Feb 3, 2019
The Initial setup is a bit complex.
it_user787785 - PeerSpot reviewer
Senior Security Engineer at a insurance company with 10,001+ employees
May 16, 2019
There is a lot to this product, and it would be good if when you purchase the tool, they can provide us with a more extensive user manual.
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,986 professionals have used our research since 2012.
IB
Security Specialist at Alfa-A IT
May 29, 2019
The scanner and crawler need to be improved.
reviewer939417 - PeerSpot reviewer
IT Auditor & Compliance Officer at a tech vendor with 51-200 employees
Jun 6, 2019
I would like to see a more optimized solution, as it currently uses a lot of CPU power and memory.
Jul 7, 2019
The Auto Scanning features should be updated more frequently and should include the latest attack vectors.
VN
Director - Head of Delivery Services at Ticking Minds Technology Solutions Pvt Ltd
Jan 2, 2020
The biggest improvement that I would like to see from PortSwigger that today many people see as an issue in their testing. There might be a feature which might be desired.
RO
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
Aug 19, 2019
The number of false positives need to be reduced on the solution.
reviewer1112304 - PeerSpot reviewer
IT Manager at a manufacturing company with 10,001+ employees
Jan 22, 2020
The biggest drawback is reporting. It's not so good. I can download them, but they're not so informative.
reviewer1261914 - PeerSpot reviewer
AVP - Software Quality Assurance at a tech services company with 201-500 employees
Jan 19, 2020
The solution doesn't offer very good scalability.