Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Tenable.io Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (4th)
Tenable.io Web Application ...
Average Rating
7.8
Reviews Sentiment
5.8
Number of Reviews
18
Ranking in other categories
Application Security Tools (15th)
 

Mindshare comparison

AWS WAF and Tenable.io Web Application Scanning aren’t in the same category and serve different purposes. AWS WAF is designed for Web Application Firewall (WAF) and holds a mindshare of 5.6%, down 10.8% compared to last year.
Tenable.io Web Application Scanning, on the other hand, focuses on Application Security Tools, holds 1.4% mindshare, up 1.2% since last year.
Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF5.6%
Fortinet FortiWeb7.8%
Imperva Application Security Platform7.8%
Other78.8%
Web Application Firewall (WAF)
Application Security Tools Market Share Distribution
ProductMarket Share (%)
Tenable.io Web Application Scanning1.4%
SonarQube16.9%
Checkmarx One9.9%
Other71.80000000000001%
Application Security Tools
 

Featured Reviews

Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
JP
Cyber Security Architect at a comms service provider with 10,001+ employees
Centralized license management transforms asset manipulation based on functions and improves security posture
Now that the license is centralized, it's a significant feature to manipulate assets based on their functions. It provides a centralized view from end-to-end to its assets' identities and vulnerabilities. One of the greatest features is Kubernetes. The automated scanning capability is pretty standard in the market, and Tenable's prioritization engine helps improve the security posture.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is stable."
"One common use case is using detection protection for enhancing security models in AWS. Another use case is implementing log analysis and response recovery procedures for email services."
"AWS WAF is very easy to use and configure on AWS."
"AWS WAF is a stable solution. The performance of the solution is very good."
"The most valuable feature is the addition of managed tools that help us create customizable rules. In case we want to block a particular request, we can make use of those rules."
"They filter a lot of attacks out."
"The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
"AWS WAF acts as a barrier, analyzing HTTP communications between external users and web applications."
"Tenable.io Web Application Scanning provides a detailed report, identifying functions that are complex and need to be more maintainable and readable."
"I think Tenable.io Web Application Scanning is the best option on the market at the moment."
"The solution is stable."
"It is fully automated."
"The most valuable feature is the reporting, which provides a good level of detail with respect to vulnerabilities."
"We use the tool for our websites. We have a vulnerable subdomain. The tool helps to scan it for vulnerabilities."
"The initial setup is straightforward."
"I would recommend Tenable.io Web Application Scanning to others."
 

Cons

"We must monitor and clean up the WAF manually."
"We need more support as we go global."
"They have to do more to improve, to innovate more features. They need to increase the security. It has to be more active in detecting threats."
"The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
"For now, there is no feature to protect against attack of the bad bots"
"There is room for improvement in pricing."
"The product should improve the DDoS-related features."
"In a future release I would like to see automation. There's no interaction between the applications and that makes it tedious. We have to do the preparation all over again for each of our other applications."
"Tenable.io Web Application Scanning could improve by offering faster fuzzing."
"The technical support should be improved. Currently, some attacks are detected while others are not."
"The solution's dashboards could be improved and made more user-friendly."
"They have a general dashboard for web application scanning, but the dashboards and reporting can be improved. They probably have some features in their roadmap."
"It would be great if there were a dashboard that is more user-friendly."
"The market is standard for vulnerability scanning, however, the posture can be improved through Tenable's prioritization engine."
"Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."
"The platform's technical support services could be better."
 

Pricing and Cost Advice

"The pricing should be more affordable, especially as it pertains to small clients."
"Its price is fair. There is a very fair amount that they charge. It has a pay-as-you-go model, so it pretty much depends on how much a user uses it. As per the cloud norms, the more you use, the more you pay. I would rate it a five out of ten in terms of pricing."
"AWS WAF has reasonable pricing."
"You need an additional AWS subscription for this product if you are buying a managed tool."
"There are no separate licensing costs we pay for since it is included in the plan we purchase."
"The product is moderately priced."
"The price is average."
"It's an annual subscription."
"I rate the product's pricing a four out of ten."
"The pricing is okay."
"For Tenable.io Web Application Scanning, it comes to around 6,50,000 Indian rupees, plus taxes."
"Tenable.io Web Application Scanning is expensive for small businesses."
"It follows the same licensing scheme as Tenable.io and Tenable. sc."
"The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage."
"The application is extremely affordable. There are no additional costs involved with licensing. We switched to Tenable.io Web Application Scanning from other solutions due to pricing."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
881,733 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
13%
Manufacturing Company
9%
Government
6%
Financial Services Firm
13%
Computer Software Company
10%
Government
9%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise7
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What do you like most about Tenable.io Web Application Scanning?
The most effective feature of the product is the ability to scan the entire environment.
What needs improvement with Tenable.io Web Application Scanning?
If there were a solution, I would like to see automation and an integrated remediation solution for vulnerability or patch management.
What advice do you have for others considering Tenable.io Web Application Scanning?
I do not understand what API approach means; I do not understand this term. I think Tenable.io Web Application Scanning is the best option on the market at the moment. My review rating for this pro...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
IMDEX
Find out what your peers are saying about Fortinet, F5, Imperva and others in Web Application Firewall (WAF). Updated: February 2026.
881,733 professionals have used our research since 2012.