No more typing reviews! Try our Samantha, our new voice AI agent.

GitHub vs HCL AppScan comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
3.2
GitHub enhances productivity and reduces costs by streamlining branch management, improving code quality, and facilitating efficient releases.
Sentiment score
1.7
HCL AppScan enhances architecture with fewer errors and improved security, achieving 50% return and 20% cost savings.
Using GitHub reduces, on average, one to two hours of time daily for making things ready, so it has very good metrics.
Senior Software Engineer at a consultancy with 10,001+ employees
 

Customer Service

Sentiment score
5.1
GitHub support varies; community resources and documentation often suffice, but direct support experiences differ in speed and consistency.
Sentiment score
5.6
HCL AppScan's support is responsive with mixed reviews, facing regional challenges and lagging behind competitors like Veracode.
The technical support from GitHub is generally good, and they communicate effectively.
Senior DevOps Engineer at Simplify3x Software Private Limited
Some forums help you get answers faster since you just type in your concern and see resolutions from other engineers.
Quality Assurance Analyst at a tech services company with 51-200 employees
I have not used GitHub's technical support extensively because there are many resources and a robust knowledge base available due to the large user community.
Platform Engineer at a recreational facilities/services company with 1,001-5,000 employees
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
There is still room for improvement when it comes to the speed of response.
Founder Director at Techsa Services
 

Scalability Issues

Sentiment score
7.0
GitHub effortlessly scales for organizations of all sizes, handling large projects and users without performance concerns.
Sentiment score
3.9
HCL AppScan is scalable yet varies by license, integration issues, infrastructure compatibility, and CI/CD pipeline design effectiveness.
We have never had a problem with scalability, so I would rate it at least eight to nine.
Consultant at a comms service provider with 10,001+ employees
GitHub is more scalable than on-prem solutions, allowing for cloud-based scaling which is beneficial for processing large workloads efficiently.
Platform Engineer at a recreational facilities/services company with 1,001-5,000 employees
I can easily give updates from VS Code and commit messages directly to the GitHub repository by just using Git commands.
Full Stack Developer at Sri Krishna Arts and Science
 

Stability Issues

Sentiment score
8.2
GitHub is stable, reliable, and highly rated, with minimal performance issues and quick resolution of occasional connectivity problems.
Sentiment score
7.2
HCL AppScan is stable and reliable, with minor hardware issues, improved by recent upgrades enhancing performance and stability.
If a skilled developer uses it, it is ten out of ten for stability.
Lead Software Engineer at The 5 Chairs
It provides a reliable environment for code management.
Senior DevOps Engineer at Simplify3x Software Private Limited
GitHub is mostly stable, but there can be occasional hiccups.
Platform Engineer at a recreational facilities/services company with 1,001-5,000 employees
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
Founder Director at Techsa Services
 

Room For Improvement

GitHub requires better usability, tool integration, project management, speed, security, documentation, merging, automation, storage, stability, and user interface.
HCL AppScan requires improvements in vulnerability detection, usability, integration, performance, support, pricing, and language/codebase compatibility to stay competitive.
When working with the CI/CD pipeline and somebody is writing the workflow file, it would be best to include the AI feature so if they write incorrect code, it will notify me about it in the same dashboard, eliminating the need to use third-party tools to review the file.
AWS & Azure Engineer at a media company with 11-50 employees
I am providing this feedback for Copilot because it seems more widespread and more companies allow it rather than Amp, and it would be beneficial if they catch up with Amp on this capability.
Senior Software Engineer at a tech services company with 501-1,000 employees
Security could make GitHub better. OWASP Top Ten security advisors could be integrated on GitHub, and it could provide checks and advice.
Software Development Manager at ANADOLU AGENCY
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
Founder Director at Techsa Services
 

Setup Cost

GitHub provides reasonable pricing and flexibility for enterprises, though improvements are needed for international markets and licensing complexities.
HCL AppScan is considered expensive but cost-effective, with varied pricing opinions influenced by its premium features and discounts.
I have not encountered any initial setup cost for that.
Full Stack Developer at Sri Krishna Arts and Science
Normally, GitHub is not expensive, but it would be welcome if it reduces costs for developing countries.
Lead Software Engineer at The 5 Chairs
The pricing of GitHub is reasonable, with the cost being around seven dollars per user per month for private repositories.
QA Manager at Next Solutions
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
 

Valuable Features

GitHub excels in version control, collaboration, integration, and automation, offering a user-friendly, secure, and efficient development environment.
HCL AppScan detects vulnerabilities, integrates with agile processes, offers scalability, user-friendly features, and AI-enhanced rapid scanning for security.
The pull request facility for code review.
QA Manager at Next Solutions
GitHub Actions allow for creating multiple jobs that run in different stages such as build, test, and deploy, which enable better visibility and control over the deployment pipeline.
Senior DevOps Engineer at Simplify3x Software Private Limited
For branching, it works well, especially in an agile environment.
Quality Assurance Analyst at a tech services company with 51-200 employees
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
Founder Director at Techsa Services
 

Categories and Ranking

GitHub
Ranking in Application Security Tools
4th
Average Rating
8.8
Reviews Sentiment
6.5
Number of Reviews
102
Ranking in other categories
Version Control (2nd), Agile and DevOps Services (2nd)
HCL AppScan
Ranking in Application Security Tools
23rd
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
44
Ranking in other categories
Static Application Security Testing (SAST) (18th), Dynamic Application Security Testing (DAST) (7th)
 

Mindshare comparison

As of August 2026, in the Application Security Tools category, the mindshare of GitHub is 2.7%, up from 0.9% compared to the previous year. The mindshare of HCL AppScan is 2.3%, down from 2.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
GitHub2.7%
HCL AppScan2.3%
Other95.0%
Application Security Tools
 

Featured Reviews

Abdulmunafz Mct - PeerSpot reviewer
Full Stack Developer at Sri Krishna Arts and Science
Daily workflows have become streamlined as I manage projects, learn from clones, and host sites
The thing that has frustrated me is sometimes when I push using a Git command, I need to force the push, which is the main thing. The setup is frustrating because GitHub could add a repository with pre-installed packages or something since I need to install packages in VS Code before pushing and maintain it in the codebase. Git packages need to be installed manually, and if that was already in a GitHub repository, that would be much better. GitHub packages can be installed previously for the project upon the project requirement, and that is the thing I wanted to add here. That would be good. According to governance and security, I recently heard about some security issues in GitHub. I think that could be centralized and should consider those security issues and clear them. The AI capabilities there include Copilot or something else. I recently heard about security issues, but I do not know about it clearly. However, if security has been more tightened, it will be better.
Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Has improved identification of encryption and authentication issues across cloud and on-prem applications
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interface. However, there is one feature called SCA, which stands for Software Composition Analysis, that could be improved. When I'm doing an application scan, HCL AppScan has the ability to generate information about what components are in use. For example, if I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present. I would like to see more detailed reports from the tool. Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities. For instance, I could identify that I had the Log4j vulnerability and know that I need to fix my application accordingly. If they add the features I'm describing, I would consider giving them a higher rating. However, I've only been experienced with the product for three months.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
908,800 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Outsourcing Company
9%
Marketing Services Firm
8%
Manufacturing Company
7%
Financial Services Firm
10%
Manufacturing Company
9%
Government
8%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business43
Midsize Enterprise14
Large Enterprise55
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise31
 

Questions from the Community

What is your experience regarding pricing and costs for GitHub?
I have been using GitHub for free, and recently I got a free education offer, such as educational resources. I believe it is GitHub Pro or something similar. I have been using the educational offer...
What needs improvement with GitHub?
The thing that has frustrated me is sometimes when I push using a Git command, I need to force the push, which is the main thing. The setup is frustrating because GitHub could add a repository with...
What is your primary use case for GitHub?
I use GitHub for maintaining repositories, as it is easy to maintain freelance projects and to store college projects. I will be using it for hosting by providing a GitHub link. For one of my freel...
What needs improvement with HCL AppScan?
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interf...
What is your primary use case for HCL AppScan?
I'm currently working with BigFix and HCL AppScan. At least three people in my company are using HCL AppScan. Since we are a reseller, we run it in both lab environments and live production applica...
What is your experience regarding pricing and costs for HCL AppScan?
AppScan is considered more cost-effective than Veracode, although I have not updated the exact pricing details. Companies often choose based on budget constraints, with Veracode being on the higher...
 

Comparisons

 

Also Known As

No data available
IBM Security AppScan, Rational AppScan, AppScan
 

Overview

 

Sample Customers

Dominion Enterprises, NASA, Braintree, SAP, CyberAgent
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Find out what your peers are saying about GitHub vs. HCL AppScan and other solutions. Updated: August 2026.
908,800 professionals have used our research since 2012.