

HCL AppScan and Parasoft SOAtest compete in the security and testing domain. AppScan appears to have an edge due to its superior ease of use and effective security testing features, whereas Parasoft SOAtest excels in comprehensive test scenarios and API validations.
Features: HCL AppScan offers dynamic and static scans, integration with SDLC processes, and AI-powered functionalities, making it user-friendly and efficient in reducing false positives. Parasoft SOAtest provides extensive scripting support, end-to-end testing capabilities, and supports diverse data sources, making it powerful for broad test scenarios and API validations.
Room for Improvement: HCL AppScan faces challenges with occasional crashes, false positives, and limited CI/CD integrations. Additionally, there are concerns about the quality of technical support. Parasoft SOAtest has high memory usage, complex licensing, and requires improvements in interface and integrations, with users highlighting the tool's complexity as a barrier to effective use.
Ease of Deployment and Customer Service: HCL AppScan offers flexibility with deployments across public clouds and on-premises setups. Its support is generally positive but varies by region. Parasoft SOAtest supports on-premises and hybrid cloud deployments, but users encounter challenges due to the tool's complexity. Support services are decent but face occasional criticism regarding responsiveness.
Pricing and ROI: HCL AppScan is perceived as expensive, yet it offers significant ROI compared to competitors like Veracode. Parasoft SOAtest, while costly, justifies its price with robust capabilities. The licensing can be complex but is considered worthwhile for organizations requiring extensive testing. Both products demonstrate potential for high ROI despite initial pricing concerns.
Tasks that previously took four or five minutes can now be completed in 20 to 30 seconds with the help of the tool.
We found Parasoft SOAtest to be quick in building up test patterns, allowing us to create complex tests efficiently.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
In particular use cases with numerous steps, it experiences crashes.
Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities.
It did not support enough of the protocols or cryptography formats we needed, which led us to create our own solutions.
One improvement would be to integrate it with modern technologies such as AI, so we can generate test cases by providing the details so that it can generate the structure, and later the person working can modify and enhance it.
In terms of improvements for Parasoft SOAtest, some features could be added or perhaps existing areas could be improved, such as lowering prices.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
Parasoft SOAtest is expensive, but it was acquired because the company was dissatisfied with Quick Test Pro.
We were able to identify security issues such as certificate-related issues, authentication-related issues, and weak encryption-related issues.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
The advantages include the custom tool and the extension tool where you can write scripts in different languages such as Groovy, Java, and Jython.
Parasoft SOAtest improves the quality of the application, increases security and security compliance, and it is a cost-effective tool.
Parasoft SOAtest is very good at ensuring tests don't pass or fail until they genuinely pass or fail.
| Product | Mindshare (%) |
|---|---|
| HCL AppScan | 2.6% |
| Parasoft SOAtest | 0.8% |
| Other | 96.6% |

| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 3 |
| Large Enterprise | 23 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
Parasoft SOAtest is a robust tool for automating test scenarios, supporting a range of interfaces and protocols, making it ideal for comprehensive service testing. Its adaptability in complex environments provides extensive testing capabilities for UI and API automation.
Parasoft SOAtest offers a comprehensive suite of features designed for the efficient setup of functional tests, emphasizing ease in data-driven scenarios and thorough automation. Supporting key protocols like SOAP and REST, alongside UI recording, it integrates seamlessly with Jenkins and GitHub, adding service virtualization for enhanced end-to-end testing. Users benefit from its extensibility through custom scripts, allowing broad API and web service testing. However, there are challenges in user-friendliness, with the graphical interface requiring improvements. Reporting features need enhanced clarity and customization options. Limited cryptography support and documentation necessitate improvement. Performance issues and high pricing are noted drawbacks, but its use in banking and quality enhancement demonstrates significant potential.
What are the key features of Parasoft SOAtest?Implementing Parasoft SOAtest in industries like banking allows automation of regression tests for web services in SOA architectures, supporting protocols such as ISO 8583. Companies use it to transition from manual testing to automation, integrating JSON and XML, facilitating improved application quality.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.