Try our new research platform with insights from 80,000+ expert users
Quality Analyst at Hiup Solution
Real User
Top 10
Easy to use with a good interface and high accuracy
Pros and Cons
  • "It offers very good accuracy. You can trust the results."
  • "The solution is not easy to set it up. You need a lot of knowledge."

What is our primary use case?

I'm primarily using it for testing of the company's website.

What is most valuable?

The interface is good.

It is easy to use.

I am certified with the product and have a good understanding of it.

The usability is very good.

It offers very good accuracy. You can trust the results. 

It's good software that is great for a beginner to use.

It can scale. 

The product is stable and reliable. 

What needs improvement?

It works for me. I don't see any missing features. 

The solution is not easy to set it up. You need a lot of knowledge. I'd like to see more documentation. They need to provide more videos and more information about the solution. The website isn't as helpful as it could be. They need to provide more information and maybe provide courses to help people get the most out of it. 

For smaller organizations, the solution is expensive. 

For how long have I used the solution?

I've been using the solution for two years. 

Buyer's Guide
PortSwigger Burp Suite Professional
January 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.

What do I think about the stability of the solution?

I'd rate the stability eight out of ten. It is pretty stable. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution is very scalable. I'd rate the ability to extend ten out of ten.

Three people are using the solution.

How are customer service and support?

I do not have any experience with technical support. I had a colleague who would deal with support.

Which solution did I use previously and why did I switch?

I used to use OWASP Zap. It is a free solution. I moved to Burp as the accuracy rate was higher. We wanted something that provided correct information about errors. 

How was the initial setup?

The initial setup was a bit difficult. For a beginner, it's tough to set up. I'd rate the solution three out of ten in terms of ease of setup. There isn't proper documentation to help you through the process. 

I cannot recall how long the deployment took. I watched a lot of videos and just went ahead with eh setup myself. 

The product doesn't require any maintenance. 

What about the implementation team?

I handled the initial setup myself. I did not have any outside assistance. 

What was our ROI?

I have witnessed an ROI. It is worth the money.

What's my experience with pricing, setup cost, and licensing?

It is a bit expensive for smaller companies. If you're using it in a small company or for your own purposes, it's costly. I'd rate the cost three out of ten in terms of affordability.

I'm not sure of the exact cost of the solution as I don't directly deal with licensing. 

What other advice do I have?

I'm a customer. I'm using the professional version. It is the latest version. They always update it and provide me with the latest upgrades. 

I'd recommend the solution to others. It's very accurate and easy to use. 

I would rate the solution. Ten out of ten. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Real User
Is fast, stable, and budget-friendly, but the dashboard needs improvement
Pros and Cons
  • "PortSwigger Burp Suite does not hamper the node of the server, and it does not shut down the server if it is running."
  • "The reporting needs to be improved; it is very bad."

What is our primary use case?

We use PortSwigger Burp Suite Professional for security testing and for doing vulnerability scanning mechanisms.

How has it helped my organization?

It has partially improved the organization requirement however, The scanning mechanism is pretty slow and takes long duration to scan. Moreover, The server hangs up while scanning. 

What is most valuable?

This solution provides a very good mechanism for fixing interval time. For example, we can create a schedule, and the schedule runs on time. PortSwigger Burp Suite does not hamper the node of the server, and it does not shut down the server if it is running.

It is quite fast and easy to install as well.

It is also a budget-friendly tool.

What needs improvement?

The reporting needs to be improved; it is very bad.

The dashboard feature or the front-end of the tool does not look good and is not very creative or user-friendly. It looks complicated when we log in to the tool. It looks boring and outdated.

For how long have I used the solution?

I've been using this solution within the last 12 months.

What do I think about the stability of the solution?

Stability-wise, improvements have been made, and it is reliable.

How are customer service and technical support?

Technical support is not so easy to get a hold of. We had to learn most of the things through the documentation. However, the documentation is not readily available online. We have to create new calls for it, and we have to email them. So, if you have a problem, then it can take some time to resolve it.

Which solution did I use previously and why did I switch?

No dint use. 

How was the initial setup?

The initial setup was straightforward and took about one to two weeks.

What's my experience with pricing, setup cost, and licensing?

It's a budget-based tool, and it's a pretty decent budget tool for the mid-version of the application. It's a lower priced tool that we can rely on with good standard mechanisms. We have a yearly license.

Which other solutions did I evaluate?

Client provided product

What other advice do I have?

If you're looking for a budget-friendly tool, I would recommend PortSwigger Burp Suite Professional.

On a scale from one to ten, I would rate this tool at seven.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
PortSwigger Burp Suite Professional
January 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Senior Test Engineer II at a financial services firm with 201-500 employees
Real User
Finds vulnerabilities but is not always cost effective
Pros and Cons
  • "The feature that we have found most valuable is that it comes with pre-set configurations. They have a set of predefined options where you can pick one and start scanning. We also have the option of creating our own configurations, like how often do the applications need to be scanned."
  • "One area that can be improved, when compared to alternative tools, is that they could provide different reporting options and in different formats like PDF or something like that."

What is our primary use case?

Our use cases are to identify the vulnerabilities of OAST and the other applications we are using. 

What is most valuable?

The feature that we have found most valuable is that it comes with pre-set configurations. They have a set of predefined options where you can pick one and start scanning. We also have the option of creating our own configurations, like how often do the applications need to be scanned.

Additionally, it has good reporting and dashboards and also integrates well with other task management applications that we're using.

What needs improvement?

One area that can be improved, when compared to alternative tools, is that they could provide different reporting options and in different formats like PDF or something like that.

One more thing they can improve is that despite having a good architecture, it needs a lot of specification. So when you start a project, because it requires a high configuration, the instructor costs more than the project. So it's not cost efficient if it's a big project.

For how long have I used the solution?

We have different versions of PortSwigger Burp Suite. For the past few years we have been using a professional edition, which is a desktop application. Now we are moving to the Cloud so we explored the enterprise edition. Although we haven't implemented it yet we're already using it. Now we have a better idea how their scanners and spiders actually work.

We've had a license for the professional version for the past two years.

What do I think about the scalability of the solution?

In terms of scalability, I think they can increase the number of regions. And more importantly, it doesn't restrict based on the domains you are scanning. So even if tomorrow you suggest some working space, you can still scan the domains for the regions that you have. If you want to increase the number that you scan, you can buy some more. So scalability is not a big problem, but I think if you are scanning from your side, you have to get the license for some of those activities. That's domain based licensing.

Right now we have two or three people using it.

How are customer service and technical support?

PortSwigger Burp's technical support is all right. The issues are resolved very quickly so we don't have to wait for long. They also provide you with documentation. Just by going through the documentation we can solve many of our problems.

How was the initial setup?

The initial setup was straightforward. We can install it on a Linux machine. It was fast to set up.

What's my experience with pricing, setup cost, and licensing?

PortSwigger Burp costs around $7,000 and around $2,309 for licensing.

What other advice do I have?

On a scale of one to ten I would rate PortSwigger Burp a seven.

For it to be a 10 it would need to implement the above mentioned different formats for reporting and the interactive security testing.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Penetration Tester at a tech services company with 1,001-5,000 employees
Real User
Good interface, feature-rich, and consistently being updated
Pros and Cons
  • "With the Extender Tab, if you know how to code then you can create a plugin and add it to Burp."
  • "There is not much automation in the tool."

What is our primary use case?

I am a penetration tester at my company and PortSwigger Burp is one of the products that I use in this capacity. It is a manual testing penetration tool.

What is most valuable?

There are a lot of good features and the most valuable one varies depending on what test you are performing. They are also consistently improving and releasing new features.

Two of the most valuable features are the Extender Tab and Repeater.

With the Extender Tab, if you know how to code then you can create a plugin and add it to Burp. It's not limited to their features because we can always add or do some customization of the features.

Even if you don't know how to code, there are hundreds of third-party plugins that are available to extend the features of the product. Some of them are open-source and there are some that are provided by Burp.

The user interface is good, having been changed within the past two years.

What needs improvement?

There is not much automation in the tool.

For how long have I used the solution?

I have been using Burp Suite for between four and five years.

What do I think about the stability of the solution?

This is a very stable product. The tool is 15 years old and very mature.

What do I think about the scalability of the solution?

Scalability is not an issue because it is not centrally connected. Rather, it is a per-license, user-based tool. We have more than 20 users in the company.

How are customer service and technical support?

The documentation is very good, so I have never needed to contact technical support.

How was the initial setup?

The initial setup is very straightforward and simple.

What about the implementation team?

No staff is required for maintenance.

What's my experience with pricing, setup cost, and licensing?

At $400 or $500 per license paid annually, it is a very cheap tool.

Which other solutions did I evaluate?

In comparing features, there is no real competition for this solution. There are a couple of open-source products, but there is no real competitor for the Burp Suite.

What other advice do I have?

This is a standard tool in this industry and anybody who is doing application security testing should be aware of it. My advice for anybody who is considering it is that it is very easy to install and configure, and there is lots of documentation available.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1112304 - PeerSpot reviewer
IT Manager at a manufacturing company with 10,001+ employees
Real User
A very user-friendly solution with good technical support, but it needs more advanced reporting.
Pros and Cons
  • "The way they do the research and they keep their profile up to date is great. They identify vulnerabilities and update them immediately."
  • "The biggest drawback is reporting. It's not so good. I can download them, but they're not so informative."

What is our primary use case?

We use the solution for scanning our in-house external facing website.

How has it helped my organization?

It has been provide user direct access to users scan their websites and find vulnerability in good price. Burp is one of the most extensively used tool in org to do other security based investigations. We are trying to mitigate risk using vulnerabilities identified by Burp.

What is most valuable?

The solution is very user-friendly.

The way they do the research and they keep their profile up to date is great. They identify vulnerabilities and update them immediately. 

What needs improvement?

The biggest drawback is reporting. It's not so good. I can download reports, but they're not so informative. 

For example, they are providing very good information about vulnerabilities, but when you are scanning the whole pathway, we want to see information like percentages, how much is finishing, and how much it is not, etc. If the scan fails, they should tell us when or how it stopped, if it failed, why it has failed, and how to avoid something like this from happening again. They need something more in-depth and more technical. 

I would like to have some more features, which I can play around with. It's not so flexible.

For how long have I used the solution?

I've been using the solution for more than 1 year.

What do I think about the stability of the solution?

The solution sometimes has stability problems when they have fixed or released some new package. Instability has happened to us two or three times. It was difficult because we had to implement this disaster recovery plan at that point in time. It wasn't a disaster, but the whole system does stop because of that.

What do I think about the scalability of the solution?

Easily scalable when it comes to Enterprise version. but Enterprise version itself is not as effective as pro.

How are customer service and technical support?

The technical support team is very good. They are quick at responding and they help us to resolve issues within the organization.

In the past, we had issues around connectivity while we were doing some scanning. The scanning kept getting killed somehow. The quality of the job was poor. The scan was not completed successfully, so we needed technical support to assist. It was hard to identify what the issue was and how to fix it, but they did.

Which solution did I use previously and why did I switch?


How was the initial setup?

The installation is not difficult. We only needed one person to handle the implementation. Setting up the agents may be tricky, but if a person is knowledgable, it shouldn't be an issue.

What about the implementation team?

Inhouse one

Which other solutions did I evaluate?

When we had an issue with scanning, we did look into exploring other options like OWASP Zap, Acunetix, etc. We stayed with Burp because we had it set up in our system, and then they had our scanning issue fixed.

What other advice do I have?

We use the on-premises deployment model.

I would rate the solution seven out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
RaviKumar21 - PeerSpot reviewer
Software Engineer at RadiSys
Real User
Top 20
Helps to scan APIs, set the response, and request errors
Pros and Cons
  • "PortSwigger Burp Suite Professional has an intercept tab that helps us to scan our APIs, set the response, and request errors."
  • "Scanning APIs using PortSwigger Burp Suite Professional takes a lot of time."

What is most valuable?

PortSwigger Burp Suite Professional has an intercept tab that helps us to scan our APIs, set the response, and request errors.

What needs improvement?

Scanning APIs using PortSwigger Burp Suite Professional takes a lot of time.

For how long have I used the solution?

I have been using PortSwigger Burp Suite Professional for the last six months.

What do I think about the stability of the solution?

PortSwigger Burp Suite Professional is a stable solution.

What other advice do I have?

PortSwigger Burp Suite Professional is a very good product. My experience with the solution has been very good.

Overall, I rate PortSwigger Burp Suite Professional an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1112304 - PeerSpot reviewer
IT Manager at a manufacturing company with 10,001+ employees
Real User
Scans any number of apps, database updates automatically; issues with high volume of scanning
Pros and Cons
  • "You can scan any number of applications and it updates its database."
  • "If we're running a huge number of scans regularly, it slows down the tool."

What is our primary use case?

There are three versions and we are using all three - community, professional and enterprise. We use the community and professional versions on premises and the enterprise version is on cloud. I'm an IT Manager. 

What is most valuable?

Burp has several good features; it's cheaper than other solutions and you can scan any number of applications and it updates its database. With the professional version, it creates a lot of applications which you can incorporate with your scanning and enable deep diving in the specific section. 

What needs improvement?

We've faced lots of challenges, including slowing down of the tool, and a lot of error messages, sometimes because of the interface. If we're running a huge number of scans regularly, I think that also slows down the tool so I'm not sure if it is good for lots of scans. I hope they will work on the amount of scans they can handle. There have been improvements in the interface and the reporting structure, but they need to do more. They have a long way to go. For now, if we use the interface directly, we need to use an integration with our web application. We're after value for money. 

For how long have I used the solution?

I've been using this solution for about 18 months. 

What do I think about the stability of the solution?

Stability depends upon the amount of scans you are running. Sometimes there are problems with the stability and it could be improved. 

What do I think about the scalability of the solution?

Scalability depends upon which of the Burp versions you're using. If you're using Pro it's not scalable because it's dedicated to one person. But when it comes to Enterprise, yes it is scalable, it's easy. 

How are customer service and technical support?

Support depends on how much you're paying. We get good support from them which we need because there are lots of issues occurring frequently. The pro version has less problems but it only takes one scan at a time, so it's good but restricting. The technical support is trying to solve the issues of stability we are having right now.

What other advice do I have?

I would recommend this solution depending on the requirements of the company. 

I would rate this solution a seven out of 10. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1966164 - PeerSpot reviewer
Cyber Security Specialist at a university with 10,001+ employees
Real User
Simple to use, informative centralized dashboard, and responsive support
Pros and Cons
  • "The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it."
  • "PortSwigger Burp Suite Professional could improve the static code review."

What is our primary use case?

PortSwigger Burp Suite Professional can be used on the cloud or on-premise.

What is most valuable?

The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it.

What needs improvement?

PortSwigger Burp Suite Professional could improve the static code review.

In an upcoming release, PortSwigger Burp Suite Professional can give some possible remedies for any issues it has discovered after a scan of an application. At this time it provides vulnerabilities, having the possible remedies would be a benefit. It would be useful for the developers, to fix the issue immediately.

For how long have I used the solution?

I have been using PortSwigger Burp Suite Professional for approximately five years.

What do I think about the stability of the solution?

The stability of PortSwigger Burp Suite Professional is good.

What do I think about the scalability of the solution?

The scalability of PortSwigger Burp Suite Professional is good, it can integrate with other platforms.

In my previous company, I worked for we had 50 people using this solution and in my current company we have approximately 500 people using it.

How are customer service and support?

We can easily reach out to PortSwigger Burp Suite Professional support by phone, email, chat option, and a ticketing option, which is very good.

I rate the support from PortSwigger Burp Suite Professional a five out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of PortSwigger Burp Suite Professional is very simple.

Which other solutions did I evaluate?

Before choosing PortSwigger Burp Suite Professional I compared other tools, such as IBM AppScan. I found that PortSwigger Burp Suite Professional was more into web application security. The solution is very helpful, easy to use, and install.  They have a free version and anybody can start within minutes.

What solution is best depends on the client size and their requirements. If the client has a large enough budget, or if they're looking for an overall feature, I would recommend PortSwigger Burp Suite Professional as the primary go-to tool. However, if they're having any specific requirements, then they will have to think about using IBM AppScan.

What other advice do I have?

I would recommend the solution to technical professionals and non-technical persons. It is easy to use.

I rate PortSwigger Burp Suite Professional a nine out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.