

In the category of cybersecurity tools, Checkmarx One and PortSwigger Burp Suite Enterprise Edition are prominent contenders. Checkmarx One appears to have the advantage due to its comprehensive language support and static scanning features, though Burp Suite shines in dynamic web application security.
Features: Checkmarx One provides comprehensive code scanning without needing compilation, extensive language support, and precise vulnerability identification. It integrates with common repository formats and supports customizable rules. PortSwigger Burp Suite Enterprise Edition excels in dynamic scanning, ease of use, and extensibility through numerous extensions, focusing primarily on web application security and automated scans.
Room for Improvement: Checkmarx One should address false positives, expand language support, and improve user integration and dashboard functionality. Enhancements in its setup complexity and cloud scalability are also needed. PortSwigger Burp Suite Enterprise Edition should improve stability, decrease false positives, and enhance SAST and mobile security scanning to increase competitiveness.
Ease of Deployment and Customer Service: Checkmarx One offers deployment options across private, public, and on-premises environments, with commendable customer service praised for quick responses. PortSwigger Burp Suite focuses on on-premises deployment and provides solid support but lacks cloud deployment flexibility.
Pricing and ROI: Checkmarx One is perceived as high cost with a complex licensing model, yet its broad features justify the investment for enhanced security. PortSwigger Burp Suite offers more economical licensing options, including a professional edition, which appeals to smaller firms, though it's considered slightly high-priced for smaller setups.
| Product | Mindshare (%) |
|---|---|
| Checkmarx One | 15.0% |
| PortSwigger Burp Suite Enterprise Edition | 4.0% |
| Other | 81.0% |

| Company Size | Count |
|---|---|
| Small Business | 32 |
| Midsize Enterprise | 9 |
| Large Enterprise | 46 |
| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 2 |
| Large Enterprise | 7 |
Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
PortSwigger Burp Suite Enterprise Edition is a comprehensive tool for web application security testing, emphasizing ease of use for dynamic scanning and vulnerability assessments. Its automation capabilities enhance efficiency and insights into API, web, and mobile app security.
PortSwigger Burp Suite Enterprise Edition is designed for vulnerability assessment, web app security testing, and dynamic application scanning. It enables teams to perform thorough assessments through automated brute force and active scanning features. With extensions, CI/CD integration, and automation, it provides a scalable environment, supporting manual and automated testing seamlessly. Users benefit from effective network call logging, vulnerability interception, and customizable scripting. Organizations from sectors such as IT services and medical equipment rely on it for penetration testing and application auditing, benefiting from its frequent improvements and integration capabilities.
What are the key features of PortSwigger Burp Suite Enterprise Edition?In sectors like medical devices and IT services, PortSwigger Burp Suite Enterprise Edition is integral for penetration testing and compliance verification. Teams use it for manual and automated testing in web and mobile applications, assessing APIs and interpreting network calls to enhance security and certification processes.
We monitor all Dynamic Application Security Testing (DAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.