No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point WAF (formerly CloudGuard WAF) vs GitHub Advanced Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 16, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point WAF (formerly C...
Ranking in Application Security Tools
5th
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
64
Ranking in other categories
Web Application Firewall (WAF) (5th)
GitHub Advanced Security
Ranking in Application Security Tools
12th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
12
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Application Security Tools category, the mindshare of Check Point WAF (formerly CloudGuard WAF) is 0.7%, up from 0.1% compared to the previous year. The mindshare of GitHub Advanced Security is 2.5%, down from 8.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Check Point WAF (formerly CloudGuard WAF)0.7%
GitHub Advanced Security2.5%
Other96.8%
Application Security Tools
 

Featured Reviews

Krishnakumar Mahadevan - PeerSpot reviewer
CISO at Spink Solutions Private Limited
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Devendiran Kandan - PeerSpot reviewer
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Security scanning has protected our pipelines but currently needs clearer dashboards and controls
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inline product, I'm not seeing user-friendly things in GitHub Advanced Security. Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, before building and deploying the code, we want to block or do an advanced model, but it is not supporting. During deployment, code scanning is not good. It is a little complicated. It is not a straightforward method we can complete. We need expertise to get the full benefit, and troubleshooting sometimes requires going through that. The security overview dashboard is not really clear. It's not showing centralized information; each repo is showing, but if you compare it with competitors, it is not that great. Mainly in the centralized dashboard, enterprise level needs to improve. A centralized way where we can get that overall view is needed, and we want that code scanning and blocking deployments based on security. There are AI improvements, but however, it is not so easy to configure. It is multiple windows we need to go through and make changes or configure that. A few things we need to enable going into settings, and a few things we can find out in security. One product where security means the security dashboard should cover everything, but it is going here and there in many places.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I have thousands of exposed websites and APIs. Being able to control what is happening and try to prevent any attack is the best feature."
"Check Point CloudGuard Network Security helped reduce the cost of ownership for our web application firewall by 50%."
"I would definitely recommend this solution because I do not want to implement one more traffic function as I can eliminate the firewall and use Check Point WAF (formerly CloudGuard WAF) alone, thus eliminating Layer 3 traffic directly connecting to my Web Application Firewall."
"The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively."
"Compared to other WAF solutions, Check Point WAF (formerly CloudGuard WAF) is user-friendly and very visible."
"The ability to preemptively block zero day attacks and detect hidden anomalies is exactly its advantage."
"Ease of deployment and efficiency, particularly for API security, are phenomenal."
"Check Point WAF (formerly CloudGuard WAF) helps my clients reduce total cost of ownership, and the return on investment was really high for Check Point WAF (formerly CloudGuard WAF), and it was the only product with GenAI security features compared to other WAF products."
"I have not experienced any performance or stability issues with GitHub Advanced Security."
"GitHub Advanced Security is ten out of ten scalable."
"GitHub Advanced Security is a very developer-friendly solution that is integrated within my development environment."
"The best features of GitHub Advanced Security are its flexibility and the multiple options it has compared to other tools."
"GitHub Advanced Security's secret scanning is good."
"It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part."
"Dependency scanning is a valuable feature."
"The most valuable is the developer experience and the extensibility of the overall ecosystem."
 

Cons

"It doesn't detect user activity like some of its competitors. It's not a vulnerability, but it's a legitimate activity that it doesn't detect. It only detects vulnerabilities or misconfigurations."
"When I was working with the WAF platform, there were limitations, particularly concerning compliance and reporting."
"I advise proactive threat detection intelligence offline, which can also help monitor and ensure system checks and compliances are in place."
"Check Point CloudGuard WAF's support is only available in English."
"Check Point WAF (formerly CloudGuard WAF) pricing is not as competitive as other original equipment manufacturers like Cloudflare or Array WAF."
"The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better."
"The User interface can be improved, especially for 1st time user."
"Multi-tenancy is an area where Check Point has room for improvement."
"There could be DST features included in the product."
"A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial."
"GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner."
"The reporting feature might need improvement. While it integrates seamlessly with my workflow, it doesn't provide management with oversight, such as statistics and the number of vulnerabilities."
"The deployment part of the product is an area of concern that needs to be made easier from an improvement perspective."
"There could be a centralized dashboard to view reports of all the projects on one platform."
"Maybe make it compatible with more programming languages. Have a customized ruleset where the end-user can create their own rules for scanning."
"The report limitations are the main issue."
 

Pricing and Cost Advice

"The sales team or account managers from Check Point are top-notch. As I am using other products as well, my pricing was competitive compared to others."
"Check Point CloudGuard Application Security's pricing is not friendly."
"It is not cheap, but it is worth it."
"As Infiniti customers, the pricing is manageable, as we have allowances dedicated to each Check Point product. The price is not as high compared to other options I have dealt with in the past."
"If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
"Check Point CloudGuard WAF is expensive compared to Azure WAF."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"I work for an Indian banking client. In India, companies are on a budget. The company liked Check Point very much, but it was a little bit costly compared to FortiWeb. However, it had more features compared to FortiWeb."
"The solution is expensive."
"The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
908,858 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Outsourcing Company
14%
Financial Services Firm
9%
Construction Company
9%
Financial Services Firm
16%
Computer Software Company
9%
Manufacturing Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business40
Midsize Enterprise21
Large Enterprise27
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for CloudGuard for Application Security?
It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.
What needs improvement with CloudGuard for Application Security?
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it c...
What is your primary use case for CloudGuard for Application Security?
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking fo...
What needs improvement with GitHub Advanced Security?
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inli...
What is your primary use case for GitHub Advanced Security?
I'm working with software development nowadays. As a process, we are using the dependent bot alerts and the code scanning for Java, and some of the code scanning is happening. Security secrets in c...
What advice do you have for others considering GitHub Advanced Security?
Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, ...
 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
No data available
 

Overview

 

Sample Customers

Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point WAF (formerly CloudGuard WAF) vs. GitHub Advanced Security and other solutions. Updated: August 2026.
908,858 professionals have used our research since 2012.