

HCL AppScan and PortSwigger Burp Suite Professional compete in the application security space. HCL AppScan appears to have an edge with its robust static and dynamic testing features, while Burp Suite excels in flexibility and community support, making it ideal for penetration testing.
Features: HCL AppScan is notable for its API integration, SaaS support, and QR code scanning. It is designed to integrate effectively with the SDLC, emphasizing security throughout development. Burp Suite, on the other hand, features a powerful active scanner, robust manual tools, and extensive extension capabilities through its active user community, providing customization options and tools for penetration testing.
Room for Improvement: HCL AppScan needs to reduce false positives, simplify CI/CD integration, and expand language coverage. Users also request more comprehensive dashboards and quicker technical support. Burp Suite requires better integration capabilities, improved API support, and an enhancement in automation and reporting features. New users often find its complexity challenging, necessitating ease-of-use improvements.
Ease of Deployment and Customer Service: HCL AppScan offers flexibility across public clouds, hybrid, and on-premises environments but has mixed customer service reviews, especially post-IBM transition. Burp Suite is primarily used on-premises and generally receives fewer customer service complaints but struggles with cloud expansion. Both products could improve technical support responsiveness and regional resource allocation.
Pricing and ROI: HCL AppScan is viewed as expensive but still offers significant value by reducing vulnerabilities and achieving cost savings over time. Despite its higher price, users find its ROI satisfactory. Burp Suite is considered more affordable with competitive pricing that appeals to smaller businesses. It is seen as cost-efficient, delivering excellent ROI and providing a budget-friendly option for penetration testing.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
The technical support from PortSwigger is excellent.
The technical support for PortSwigger Burp Suite Professional is pretty good, and I would give it a nine.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
PortSwigger Burp Suite Professional is very stable.
PortSwigger Burp Suite Professional is a very stable tool, and I would rate its stability as eight out of ten.
Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities.
Perhaps they could add some automation to things, to see what we do manually, which it has the tools to do manually, and perhaps enable with a click of a button to do things automatically.
Some AI features might be added.
The dashboard of PortSwigger Burp Suite Professional could be made more user-friendly.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
The pricing for PortSwigger is very cheap, and there are benefits in terms of time and cost savings.
I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.
We were able to identify security issues such as certificate-related issues, authentication-related issues, and weak encryption-related issues.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency.
One of the best things in PortSwigger Burp Suite Professional is that it has its own browser.
I especially value the features for penetration testing.
| Product | Mindshare (%) |
|---|---|
| PortSwigger Burp Suite Professional | 3.4% |
| HCL AppScan | 2.3% |
| Other | 94.3% |

| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 14 |
| Large Enterprise | 35 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
PortSwigger Burp Suite Professional is a vital tool for cybersecurity experts, valued for features like Intruder and Repeater, and offering strong automation for effective vulnerability detection and web security.
PortSwigger Burp Suite Professional aids organizations in conducting comprehensive application security testing. With functions like scanning, proxy setup, and numerous plugins, it provides essential support for vulnerability assessments and penetration testing. Despite needing improvements in reporting, false positive reduction, and scanning speed, it remains adaptable for different security operations through its automation, extensive community support, and regular updates. Licensing and pricing flexibility are considerations, alongside API security enhancements and documentation improvements. Widely used for intercepting and scanning web applications pre-launch, it supports compliance testing while offering tools for request replaying, traffic manipulation, and brute forcing.
What are the key features of PortSwigger Burp Suite Professional?In industries like finance and healthcare, PortSwigger Burp Suite Professional is implemented to enhance application security frameworks. It provides critical insights for regulatory compliance and risk management. The tool's adaptability supports organizations in routinely identifying and addressing vulnerabilities, ensuring robust protection against potential threats and facilitating secure application launches.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.