It protects against zero-day vulnerabilities, like Heartbleed.
Info-Security Consultant at a financial services firm with 1,001-5,000 employees
It protects against zero-day vulnerabilities, like Heartbleed.
What is most valuable?
What needs improvement?
It's missing some zero-day patches.
For how long have I used the solution?
I've used it for a few months.
What was my experience with deployment of the solution?
No issues encountered.
Buyer's Guide
Qualys Web Application Scanning
January 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and support?
Customer Service:
It's high.
Technical Support:It's high.
Which solution did I use previously and why did I switch?
I used Rapid7 NeXpose in another shop.
How was the initial setup?
The product was already installed when I got there, I just added more scanning jobs and used the reports for remediation, etc.
Which other solutions did I evaluate?
I evaluated and selected Rapid7 NeXpose in a previous job (over QualysGuard) because the compliance department there vetoed using “an external service”. Also, we wanted to get Metasploit later.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Deputy Manager at a tech services company with 10,001+ employees
Network scanner has good reporting and coverage, but it needs manual pen testing
What is our primary use case?
Cloud hosted application, and was also accessible through mobile app.
How has it helped my organization?
Dynamic features for pen testing automation, with manual.
What is most valuable?
Network scanner has good reporting, coverage was also good. In Web scanner, dashboard was good but features were limited.
What needs improvement?
Please add manual penetration testing features.
Also I didn't like the license terms and the features were limited compared to other tools used for web applications.
For how long have I used the solution?
Trial/evaluations only.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Qualys Web Application Scanning
January 2025
Learn what your peers think about Qualys Web Application Scanning. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Security Analyst at a tech services company with 1,001-5,000 employees
Automated tools cannot find all the vulnerabilities, but this is one of the best.
What is most valuable?
WAS and being able to integrate Selenium IDE to automate the login process was most helpful.
How has it helped my organization?
Scheduling feature allows to scan on the weekends and holidays in a planned way.
What needs improvement?
Enhancing the capability to find XSS.
For how long have I used the solution?
I've used it for six months.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
No issues encountered.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
I've never had the chance to interact.
Technical Support:I've never had the chance to interact.
Which solution did I use previously and why did I switch?
This would depend on the clients' requirements.
How was the initial setup?
It's straightforward. In fact, it's one of the easiest solutions to implement.
What about the implementation team?
We used a vendor team who had good expertise.
What other advice do I have?
I would recommend this tool. Simply, go for it. The video tutorials would give an insight on the simplicity and effectiveness of the product.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Popular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Fortify on Demand
Sonatype Lifecycle
PortSwigger Burp Suite Professional
Tenable.io Web Application Scanning
Buyer's Guide
Download our free Qualys Web Application Scanning Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between OWASP Zap and Qualys?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?