What is our primary use case?
We're a software development company. We specialize in ensuring application security for our customers. For each and every application we release, we issue a certificate explaining that the application is up to date and that all security testing has been successfully completed. In that certificate, we also mention that PortSwigger is one of the tools that we used to test the application.
Presently, we have three users. In the future, regarding product testing, I am thinking of hiring another two people, which will make us a team of five. Currently, we're releasing a lot of applications.
Primarily we have three users, but keep in mind, we only have a single environment, which we need to improve and expand.
What is most valuable?
The traffic interception capabilities are great. Spidering also produced some good results for us.
What needs improvement?
A lot of our interns find it difficult to get used to PortSwigger Burp's environment. The environment should be improved a little bit. Once you get used to it, it's fine, but it should be more simplified for newcomers. This would save us from constantly having to brief our interns.
What do I think about the stability of the solution?
The stability is good; so far, we haven't come across any bugs.
What do I think about the scalability of the solution?
We use some different tools for web application testing, like Nmap and others. If PortSwigger Burp could actually scale up for web application scanning, that would be really good. This way, instead of using different tools, we could easily rely on one tool for all testing.
How are customer service and support?
We haven't had any reason yet to contact technical support. Aside from support, they should hold consistent webinars and offer updates, briefings, and panel discussions. This would greatly enhance our knowledge.
Otherwise, the technical support is good enough. We haven't required their assistance yet, but soon we'll be needing assistance and information surrounding the latest improvements and updates.
How was the initial setup?
The initial setup can be complex. It needs to be deployed in between the traffic. They should include some case-scenarios to help, like a scenario-based briefing, that would really help and add a lot of value for the initial application tester.
What's my experience with pricing, setup cost, and licensing?
It's a very unique way of pricing. It varies depending on the type of testing you are performing. Manual testing is expensive, but as we don't have another option, it seems to be fair.
What other advice do I have?
I would definitely recommend PortSwigger Burp. I've actually recommended it to some of my colleagues, students, and interns. I'm really comfortable and happy with it; besides, there are no other products to compare it to.
On a scale from one to ten, I would give this solution a rating of eight.
If they included example scenarios and hosted educational webinars, I would give this solution a rating of ten.
In my area of expertise, I feel like it has almost everything I could possibly require at this moment. Generally, I don't come across situations like that, so I am very happy with it.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Yes, I agree with the points detailed in the review.