We are using the latest version and are in the process of upgrading it.
Chief Info Sec Engineer at Sri Lanka CERT
An easy to install solution for vulnerability assessment
Pros and Cons
- "We use the solution for vulnerability assessment in respect of the application and the sites."
- "We wish that the Spider feature would appear in the same shape that it does in previous versions."
What is our primary use case?
What is most valuable?
We use the solution for vulnerability assessment in respect of the application and the sites. We use the intruder part, which is essentially the Proxy part, to check whether any brute-force attacks can be undertaken.
What needs improvement?
We wish that the Spider feature would appear in the same shape that it does in previous versions.
I believe we have developmental tools such Accuratix. It would be nice if the report that was accepted upon scanning would highlight all the weaknesses from the perspective of my application.
For how long have I used the solution?
We have been using PortSwigger Burp Suite Professional for the last three years.
Buyer's Guide
PortSwigger Burp Suite Professional
January 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
What do I think about the stability of the solution?
We have had no issues with the stability.
What do I think about the scalability of the solution?
As we only have a couple of licenses, we have not encountered any issues concerning the scalability.
How are customer service and support?
The technical support is all right.
This said, we have requested support on a couple of occasions, specifically one concerning training relating to the new features and add-ons coming onto the application, and this is still outstanding.
How was the initial setup?
The initial setup is not very complex. Rather, it is easy and straightforward.
What's my experience with pricing, setup cost, and licensing?
For a country such as Sri Lanka, the pricing is not reasonable.
What other advice do I have?
There are around 10 people using the solution in our organization.
I don't have any advice off the cuff. When it comes to the web crawling features, it does not need to be in the same shape as before, but it would be nice if it allowed us to index associated things in the manner that we did so in the past.
I rate PortSwigger Burp Suite Professional as a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security consultant at a manufacturing company with 10,001+ employees
The active scanner provides a very accurate security audit
Pros and Cons
- "The active scanner, which does an automated search of any web vulnerabilities."
- "As with most automated security tools, too many false positives."
What is our primary use case?
The primary use case is generally for security compliance on web applications. We provide services to our customers with Burp both on-prem and on cloud. I'm a solutions consultant and we are customers of PortSwigger Burp.
What is most valuable?
Their flagship feature would be the active scanner, which carries out an automated look up of any web vulnerabilities reflecting over to one of the main compliance standards, like OWASP. This provides an accurate security audit for their web applications.
What needs improvement?
One downside of the solution would be their false positive checks. As with most automated security tools, there is still a high false positive issue. Hopefully they will be able to improve on that in the future. It would also be helpful if the solution had the capability of handling larger reports. Another area of improvement would be to have a customizable dashboard. It's currently restricted now to their own interface. If you want to utilize the other features available in their API documentation, then you have to write some code yourself. It would be great if their interface could be somewhat customizable.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
The stability of the solution is generally fine.
What do I think about the scalability of the solution?
The solution is easily scalable, depending on licensing of course. For example, on the cloud set up, you can easily scale the agents and such. But in terms of bandwidth, maybe when it comes to their reporting feature, there are some limitations with the detail that can be downloaded from the report. I've found that the system can crash if you try to download a report with many details.
How was the initial setup?
In my opinion the initial setup is pretty straightforward. The workflow is easy to understand and they have a lot of documentation on how to perform many of the key tasks.
What's my experience with pricing, setup cost, and licensing?
I believe the price is good where it's at right now. They have a very competitive price point although recently they've been incrementally increasing in price. It's still competitive.
What other advice do I have?
I would definitely recommend PortSwigger as a primary tool for auditing any open vulnerabilities of anything related to web applications.
I would rate this product an eight out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
PortSwigger Burp Suite Professional
January 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Senior Cyber Security Analyst at a tech services company with 501-1,000 employees
Used to intercept requests and scan applications
Pros and Cons
- "The most valuable feature of PortSwigger Burp Suite Professional is the Burp Intruder tool."
- "The solution’s pricing could be improved."
What is our primary use case?
I use the solution to intercept requests and scan applications.
What is most valuable?
The most valuable feature of PortSwigger Burp Suite Professional is the Burp Intruder tool.
What needs improvement?
The solution’s pricing could be improved.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Professional for around two to three years.
What do I think about the stability of the solution?
We have not faced any issues with the solution’s stability.
What do I think about the scalability of the solution?
Over 500 people are using the solution in our organization.
How was the initial setup?
The solution’s initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
PortSwigger Burp Suite Professional is an expensive solution.
What other advice do I have?
I would recommend the solution to other users. Using PortSwigger Burp Suite Professional for the first time is not easy, but you can use it easily after using a demo version. The solution's Intruder tool has helped improve our security testing efficiency. The solution's Repeater tool has helped us with testing for web vulnerabilities.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Director at a consultancy with 10,001+ employees
Offers good application security features and is reasonably priced
Pros and Cons
- "The most valuable feature is the application security. It also has a reasonable price."
- "The Burp Collaborator needs improvement. There also needs to be improved integration."
What is most valuable?
The most valuable feature is the application security. It also has a reasonable price.
It has an end product and a repeater. Other solutions don't offer options like these.
What needs improvement?
The Burp Collaborator needs improvement. There also needs to be improved integration.
For how long have I used the solution?
I have been using PortSwigger Burp for the past six years.
What do I think about the stability of the solution?
It's not so stable. Some of the security aspects aren't so stable.
What do I think about the scalability of the solution?
Burp is scalable.
We have around 150 users using Burp at my company. We use it daily.
How are customer service and technical support?
I haven't needed to contact their technical support.
How was the initial setup?
The initial setup is simple. It only takes two to three minutes.
What about the implementation team?
We are consultants so we do the implementation ourselves.
It only requires one person for the implementation and maintenance.
What's my experience with pricing, setup cost, and licensing?
It costs 39,000 including taxes per year.
What other advice do I have?
I would recommend this solution to somebody considering Burp.
I would rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder and Director at a financial services firm with 1-10 employees
Great reporting with good crawling capability and offers a simple setup
Pros and Cons
- "The solution has a pretty simple setup."
- "The pricing of the solution is quite high."
What is our primary use case?
We primarily use the solution for security testing - specifically for web-application security.
What is most valuable?
The crawling capability is excellent.
The product has very good reporting capabilities. They give you multiple reporting options.
The solution has a variety of different extensions that you can use.
The solution has a pretty simple setup.
What needs improvement?
The pricing of the solution is quite high. It would be ideal for the customers if they could lower the costs involved in their subscription.
We have new tools in R language programming platforms that are coming up. The solution needs to ensure its compatible with that language.
For how long have I used the solution?
I've been using the solution for about two years at this point.
What do I think about the stability of the solution?
We use this solution every day. I don't have any issues with the solution. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
I'm a consultant. I tend to use the tool for my clients. I only have one license on my computer. I don't need to scale the product.
The solution is scalable, however. There's a different version for that aspect. You have Community, Professional, and Enterprise editions. Each has different capabilities.
How are customer service and technical support?
The solution offers good support services. There's also the product team that can assist. Overall, I've been happy with the level of service I've received.
Which solution did I use previously and why did I switch?
I've worked with other solutions, such as Acutenix. As a consultant, I always have two to three tools for running and validating for testing. There is no plus or minus to each tool, really. The process itself would be more like using multiple tools to find out whether it appears in all the tools or not.
How was the initial setup?
The initial setup is not overly complex. It's easy and straightforward. A company shouldn't have any issues with the implementation process.
The deployment takes a maximum of an hour, actually. If you have to configure some prerequisites, it is one hour tops. There are advanced setups, however, how advanced the implementation depends on the client environment. If a company has an advanced setup, it could take some time.
Ultimately, the solution is installed directly onto my laptop.
The maintenance process is pretty minimal. The yearly subscription keeps everything updated. They will notify you if there is an upgrade that needs to be addressed.
What's my experience with pricing, setup cost, and licensing?
The pricing of the solution is quite high. Costs are based on their subscription model. The pricing affects whether a client will engage with me and the solution or not. It could be a deal-breaker. Budgets are often tight.
What other advice do I have?
The solution has an annual subscription model, and therefore you'll have to keep updating the new version. It's part of the package. They release a new version and that is covered under your subscription.
I'm a consultant. I buy tools from multiple vendors. I provide development assessment services for my clients.
This is one more product in the suite of tools or applications, which are used for testing. Anyone at any sized company could use this solution.
I'd recommend this solution. It's one more tool to have in your bag.
I would rate the solution at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Consultant
Cyber Security Specialist at a university with 10,001+ employees
Intruder and automatic scanning features help secure our internal applications pre-production
Pros and Cons
- "The most valuable features are Burp Intruder and Burp Scanner."
- "There should be a heads up display like the one available in OWASP Zap."
What is our primary use case?
This is a solution for which I provide services to our customers and I also use it personally.
As part of our organization, we build internal applications. Before they are put into production, we run a suite of security tests to ensure that our applications are not vulnerable to any known issues. We use PortSwigger Burp for testing, as well as OSASP Zap. We do similar tests in multiple tools to make sure that we cover the entire set of use cases.
I have this solution deployed as one user on a single machine, which is used by a designated security tester.
What is most valuable?
The most valuable features are Burp Intruder and Burp Scanner.
The automatic scanning feature is helpful.
What needs improvement?
The interface for the automatic scan can be improved because it is easy for technical users, but the business users have trouble with it. There is documentation but the interface should be more user-friendly.
There should be a heads up display like the one available in OWASP Zap. I think that it would be a very good addition.
For how long have I used the solution?
I have worked with PortSwigger Burp for about ten years.
What do I think about the stability of the solution?
This solution is stable and we have had no major problems.
What do I think about the scalability of the solution?
We have had no issues with scalability, although we are using a standalone installation with only a single user. We may expand usage in the future.
Which solution did I use previously and why did I switch?
We also have OWASP Zap and we continue to use these two tools.
Zap has a heads up display within its own browser, which is a very good feature. Zap is also completely free, whereas Burp has a free version but it also has licenses available.
For the most part, we use open-source solutions, which are free of charge.
How was the initial setup?
The initial setup is simple and very straightforward. We were not setting up a server, so it took perhaps five minutes to get up to speed and begin using it.
What's my experience with pricing, setup cost, and licensing?
There are different licenses available that include a free version.
What other advice do I have?
We do have problems with some of the add-ons that we install from the marketplace. They may not be available or out of support, so when you want to install them, they are not there.
This is a very nice tool and anybody can use it, from beginner to expert level. There are some simple and straightforward settings with documentation that is very clear. If you follow the steps you can easily get up to speed within five minutes for a single user.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
A low cost security solution that identifies issues quickly but could offer better integration
Pros and Cons
- "The Spider is the most useful feature. It helps to analyze the entire web application, and it finds all the passes and offers an automated identification of security issues."
- "The number of false positives need to be reduced on the solution."
What is our primary use case?
The primary use case is security for the development lifecycle. We use the application for security testing.
How has it helped my organization?
The solution helps to identify security issues quickly.
What is most valuable?
The Spider is the most useful feature. It helps to analyze the entire web application and it finds all the passes and offers an automated identification of security issues.
What needs improvement?
The number of false positives needs to be reduced on the solution.
I'm not sure whether some features need to be added because the product has a specific toolset, and if I do need some additional features, currently I get them in different security products. The solution, however, could better integrate with various other tools.
For how long have I used the solution?
I've been using the solution for three years.
What do I think about the stability of the solution?
The solution is very stable.
What do I think about the scalability of the solution?
The solution is not designed to be scalable. You have an individual license, and I use it individually.
How are customer service and technical support?
I have not needed to use the solution's technical support.
Which solution did I use previously and why did I switch?
Before Burp I was manually proxying the data myself. I have experience making my own tools for security assessment. Burp is pretty convenient, and it's one of the most popular tools, which is why I began using it.
I also use Wireshark, which is pretty effective too.
How was the initial setup?
The initial setup was straightforward.
What about the implementation team?
We implemented the solution ourselves.
What's my experience with pricing, setup cost, and licensing?
Licensing is paid on a yearly basis. The yearly cost is about $300.
What other advice do I have?
For application security testing, I would suggest Burp. It's probably the leader in this area. It's just like analog tools such as OWASP ZAP, which is open-source. OWASP ZAP is still not as effective as Burp is.
The solution helps to find different security issues, and it helps identify many, many security issues quickly, and that's what makes it such a useful tool.
I would rate the solution seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Works
Proactively assess our in-house software for vulnerabilities in advance of public release
Pros and Cons
- "BurpSuite helps us to identify and fix silly mistakes that are sometimes introduced by our developers in their coding."
- "The Auto Scanning features should be updated more frequently and should include the latest attack vectors."
What is our primary use case?
We use this solution for the security assessment of web applications before their release to the internet. The security assessment team uses this product to identify vulnerabilities and vulnerable code that developers may introduce. We host all of the beta applications in our internal web servers and then the security team starts assessments when the development freezes.
How has it helped my organization?
In the early years, we did not check our web applications for security vulnerabilities before releasing them to customers. Since we began this practice for every application, our clients are really happy and value our work.
BurpSuite helps us to identify and fix silly mistakes that are sometimes introduced by our developers in their coding.
What is most valuable?
The auto scanning feature provides really good details about issues that it finds.
Crawling web applications using Burp Spider, Target Site Map, automating customized attack with Burp Intruder, and manipulating parameters with Burp Repeater are the most useful and used features.
What needs improvement?
The Auto Scanning features should be updated more frequently and should include the latest attack vectors.
It would be really helpful if the issue details contained example recommendations on how to fix the issues identified, or perhaps point to external recommendations for reference.
For how long have I used the solution?
I have been using this solution for more than five years.
What do I think about the stability of the solution?
I have never had issues running this application, so I would say it is stable.
What do I think about the scalability of the solution?
Scalability is very simple and easy.
How are customer service and technical support?
We have not needed to contact technical support, although there is a very big community of users.
Which solution did I use previously and why did I switch?
Prior to this solution, we used various open-source or free applications. We wanted to streamline and improve productivity by standardizing the products that we use.
How was the initial setup?
The initial setup of this solution is very straightforward and easy.
What about the implementation team?
We performed the deployment in-house. There were no complicated steps.
What was our ROI?
Our ROI is above two hundred percent.
What's my experience with pricing, setup cost, and licensing?
There is no setup cost and the cost of licensing is affordable.
Which other solutions did I evaluate?
We tested all of the free apps and could not find a stable all-in-one solution other than BurpSuite.
What other advice do I have?
All application development organizations should purchase BurpSuite and train their developers on how to use this solution to identify security flaws. This will help to ensure that the applications released to the public internet will have better protection from malicious attackers.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Fuzz Testing ToolsPopular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Fortify on Demand
Sonatype Lifecycle
Qualys Web Application Scanning
Tenable.io Web Application Scanning
Contrast Security Assess
Digital.ai Application Security
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is OWASP Zap better than PortSwigger Burp Suite Pro?
- What is the biggest difference between OWASP Zap and PortSwigger Burp?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?