Try our new research platform with insights from 80,000+ expert users

Check Point CloudGuard Code Security vs Fortify WebInspect comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 7, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point CloudGuard Code...
Ranking in DevSecOps
7th
Average Rating
8.4
Reviews Sentiment
7.5
Number of Reviews
12
Ranking in other categories
Data Loss Prevention (DLP) (12th)
Fortify WebInspect
Ranking in DevSecOps
8th
Average Rating
7.2
Reviews Sentiment
6.8
Number of Reviews
21
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd)
 

Mindshare comparison

As of May 2025, in the DevSecOps category, the mindshare of Check Point CloudGuard Code Security is 1.6%, up from 1.1% compared to the previous year. The mindshare of Fortify WebInspect is 7.1%, down from 11.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
DevSecOps
 

Featured Reviews

Nagendra Nekkala. - PeerSpot reviewer
Good security and functionality with helpful support
The security on offer is great. It's secure in terms of testing all the workloads. We can test across any workload or multiple clouds. It offers unified prevention. It also offers posture management by verifying proper scanning. We use the GSL builder. It's easy to write customer rules or policies using it. Of course, you do need proper training on the product first. It takes around one week to get trained. We've been able to reduce human error, and you can build the rules for better coverage. It provides functionality across cloud providers. The solution helps us save time. We've reduced the amount of time spent by 25%. Its unified security management console is a very complete dashboard. We can see all security threats and can gain visibility into what is happening. We have access to automation and can monitor the security of IT systems. The product offers role-based access control so that we can set up different privileges for admin users. Cloud Guard Spectrum is good for automating our organization's security across assets, workloads, and multiple clouds. With it, we have advanced pre-prevention across the cloud security network. It works for on-premises also. We can easily determine our organization's security posture. It will ensure my application's availability time across the enterprise. Network security helped us reduce our compliance and audit activities. We've saved about 20% of our time. Having a cloud detection response helps to very quickly identify security threats in our environment. It's automated so it saves us time. That way, people can work on other projects. On any given day, we're spending 20% less time in general worrying about detection and response. Our security operations are saving a lot of time using a unified platform.
Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Compared to what we used before, it's helping us to be more efficient in managing our traffic."
"We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than five minutes in such events."
"Its fastest and most outstanding characteristic is ensuring a development line that will not lead to applying applications or code development."
"Check Point CloudGuard Code Security helps to improve the code security of our company, generating rapid and complete assessments to be able to make decisions for improvements."
"Automation has helped a lot to identify and automatically execute policies, rules, and blocks due to its machine learning."
"The data center security system has provided real-time analytics on performance and data configuration processes."
"Knowing what measures we must take allows us to reduce costs associated with security in the cloud by providing early identification of a risk or a possible security breach."
"Having a cloud detection response helps to very quickly identify security threats in our environment."
"Good at scanning and finding vulnerabilities."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
"The solution's technical support was very helpful."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"Guided Scan option allows us to easily scan and share reports."
"The accuracy of its scans is great."
"It's a well-known platform for doing dynamic application scanning."
"It is scalable and very easy to use."
 

Cons

"They could include web functionalities such as sandboxing."
"I am satisfied with the performance and results enhanced by this product since we deployed it."
"This is a highly technical solution for users who do not have security experience. It requires specialized knowledge of configurations to use it correctly."
"It is generally difficult to find documentation about the product, and there is relatively little to find."
"I would like this solution to be extended to cellular devices or tablets."
"The solution should improve false-positives."
"There are a lot of opportunities for how they can use their technology to do more. That would be more like sensitive data discovery and other things besides Git Repos, but then you are expanding the scope of what necessarily their product is."
"The costs are not transparent."
"I would like WebInspect's scanning capability to be quicker."
"The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate."
"Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environment."
"It requires improvement in terms of scanning. The application scan heavily utilizes the resources of an on-premise server. 32 GB RAM is very high for an enterprise web application."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"We have often encountered scanning errors."
"We have had a problem with authentification."
 

Pricing and Cost Advice

"It is extremely affordable and high value for cost."
"It’s a fair price for the solution."
"Fortify WebInspect is a very expensive product."
"The price is okay."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"The pricing is not clear and while it is not high, it is difficult to understand."
"This solution is very expensive."
report
Use our free recommendation engine to learn which DevSecOps solutions are best for your needs.
851,491 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
30%
Financial Services Firm
13%
Manufacturing Company
11%
Government
10%
Financial Services Firm
17%
Government
14%
Computer Software Company
13%
Manufacturing Company
12%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Spectral?
We have had a number of real events where developers accidentally made commits of API keys, and we were able to detect and begin response actions in minutes. We had the API key revoked in less than...
What needs improvement with Spectral?
The solution should improve vulnerability in-depth, false-positive reduction, integration with other tools, performance optimization, and the user interface.
What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
The price of Fortify WebInspect is high, with the cost depending on the number of virtual users. It is approximately 25% higher than other solutions.
What needs improvement with Fortify WebInspect?
The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate. The cost of the license depends on the number of virtual users and, in comparison to...
 

Also Known As

Spectral
Micro Focus WebInspect, WebInspect
 

Overview

 

Sample Customers

Doddle, Bangalore International Airport, Grupo financiero ACOBO, DigitalTrack
Aaron's
Find out what your peers are saying about Check Point CloudGuard Code Security vs. Fortify WebInspect and other solutions. Updated: April 2025.
851,491 professionals have used our research since 2012.