No more typing reviews! Try our Samantha, our new voice AI agent.

Imperva Application Security Platform vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 22, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Imperva Application Securit...
Ranking in Web Application Firewall (WAF)
1st
Average Rating
8.6
Reviews Sentiment
6.9
Number of Reviews
147
Ranking in other categories
CDN (2nd), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st), API Security (1st)
The Fastly Next-Gen WAF (po...
Ranking in Web Application Firewall (WAF)
30th
Average Rating
7.6
Reviews Sentiment
4.8
Number of Reviews
4
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 4.5%, down from 7.0% compared to the previous year. The mindshare of Imperva Application Security Platform is 7.4%, up from 7.1% compared to the previous year. The mindshare of The Fastly Next-Gen WAF (powered by Signal Sciences) is 1.2%, up from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
Imperva Application Security Platform7.4%
Cloudflare Web Application Firewall4.5%
The Fastly Next-Gen WAF (powered by Signal Sciences)1.2%
Other86.9%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
reviewer2818155 - PeerSpot reviewer
Senior Associate at a tech vendor with 10,001+ employees
Application protection has improved and reporting and dashboards still need refinement
I believe Imperva Application Security Platform should have a more interactive wizard. While the dashboard is good, it could be more eye-catching. Based on my perspective, I recommend modifying the dashboards, especially the main dashboard where I can see the traffic hit count, alerts, and other latest information. In terms of reporting, I find it challenging to create reports; in my earlier days, it was difficult. Over time, I have learned how to create reports, but it should be easier to do so. I have used other tools such as firewalls or SolarWinds, where creating a report is straightforward and does not take much time, unlike in Imperva, where I have to add many elements. Modifications in the integration aspects would also be beneficial.
reviewer2161107 - PeerSpot reviewer
Staff Engineer at a retailer with 1,001-5,000 employees
Room for improvement with user interface while competitive pricing impresses
It is managed through Infrastructure as Code, so all configurations can be managed in the code itself, which is beneficial. Because it uses rules, it is easy to set up, and we have many different sites where the configurations are straightforward. Though the UI is not very interactive, which is a downside, we can manage many things. The UI is not very intuitive and could be better. However, we manage all the configurations through code, which is easy to maintain. It has extensive anomaly detection capabilities, so the traffic is classified into several categories where thresholds can be defined and customized based on false positives and false negatives. This is advantageous because you do not need to tweak it very often. Once you set it up, an audit once a quarter would suffice. Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We extensively use the solution every day. The solution is very stable; we haven’t seen any glitches."
"For us, the key feature of Cloudflare is DDoS protection and IP hiding, especially since we are a crypto company."
"Some of the most valuable features of Cloudflare Web Application Firewall include its DNS zone setup and the zero trust policy."
"The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10."
"I have not had any issues with this solution, and I would recommend it to others who are interested in using it."
"There is a huge signature repository"
"The setup process is very simple for me."
"The initial setup process is simple."
"By using this application, the firewall is blocking every suspicious activity and event, and now we are safe with peace of mind that nobody will use malware on us or try to hack our website."
"Simplifies putting everything in code."
"It is easy to manage and expand."
"The solution has been quite stable. I have not seen any bugs at all."
"The solution is cloud-based and offers us good uptime. It has combined web and API security. Therefore, with one license, you access both application security and also API security."
"We are using Incapsula as our web application firewall and for DDoS protection, and it performs really well at its job."
"We can now quickly address the problems of our clients in an effective manner."
"Imperva Application Security Platform positively impacts us because we have a critical website, so by placing a WAF of Imperva's quality, it allows us to have visibility and granular control over the various attacks that can occur on the website."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
"The product's most valuable feature is its ability to set up the rules easily."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate."
 

Cons

"Cloudflare should update the version of the ModSecurity core rule set that they run on."
"The reporting could be improved if it were more granular."
"Cloudflare Web Application Firewall should improve visibility for a customer."
"They have some limitations with third-party integrations."
"We don't even use Cloudflare Bot Management because it's too expensive; you need to pay per request, and it's much cheaper to get one or two additional machines."
"Their documentation could be better. They don't have documentation that explains everything well. They have documentation for everything you're looking for, but they lack a single piece of documentation to tie everything together. As a new user or beginner, it took us a little bit of time to figure out how to put all these things in place."
"A key challenge arises when dealing with numerous integrations with HVAC systems. Depending on the specifics, there might be some configuration mismatches, which necessitate specific support."
"The blocked logs are difficult to read at times."
"Pricing is a challenge for most of our customers."
"In the past, I have bugs on the WAF. I've contacted Imperva about them. Future releases should be less buggy."
"Imperva always needs to adjust to new versions of cyber attacks, it needs to be faster, improve the resiliency of the software of the solution."
"It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that."
"Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
"It would be helpful to have a "recommended deployment", or even a list of basic features that should either be used or turned on by default."
"The support for the on-premises version needs improvement."
"Caching rules are really basic now and lots of space for improvement here."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
"The UI is not very intuitive and could be better."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
 

Pricing and Cost Advice

"Cloudflare Web Application Firewall is more affordable than other solutions."
"The annual licensing fee is $10,000 USD."
"We pay $210 per month for CloudFlare WAF."
"The solution's pricing option needs to be more transparent for enterprise clients."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"It is not too pricey."
"The solution is expensive."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"Imperva charges us based on bandwidth, which is better than other vendors that charge us according to data transfer."
"We have an issue with Imperva Incapsula in the Iraqi market because of the high price."
"It is a very expensive solution. The price is very high. A lot of customers tell us that they would love to use Imperva more. I have some customers who have 50 websites, but they have only 10 websites on Imperva because of the price. They would love to have all their websites running through Imperva, but they can't. They have to choose the more critical websites to protect because the price is very high. It is a very good product, but it is too expensive. If you buy a plan for 20 megabytes and you don't consume all of your 20 megabytes, it is okay, but if you consume more, you are charged for the superior traffic."
"Imperva Web Application Firewall price is higher compared to other solutions. However, everything is included in the price."
"The data packages are higher than our needs so we end up paying for data that we don't use."
"There are some licenses that you have to buy to use some features. Its price could be better. Price is always important because, at the end of the day, customers have a budget. If you can meet the budget, you can sell, and if you don't, you cannot sell."
"The license is on a yearly basis."
"Imperva Web Application Firewall's pricing is expensive."
"The pricing is 50% less than Akamai."
"The product has an affordable cost."
"Signal Sciences is pretty cheap compared to other solutions."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
900,838 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Financial Services Firm
9%
Comms Service Provider
9%
Manufacturing Company
7%
Financial Services Firm
12%
Manufacturing Company
9%
Computer Software Company
7%
Construction Company
7%
Manufacturing Company
12%
Retailer
9%
Financial Services Firm
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise25
Large Enterprise70
No data available
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
What is your experience regarding pricing and costs for Signal Sciences?
The pricing is very competitive compared to other providers. The pricing is definitely a factor in our decision-makin...
What needs improvement with Signal Sciences?
We do use it, but the UI can be improved as we mostly work through the CI/CD. It provides support, but sometimes it i...
What is your primary use case for Signal Sciences?
The CDN is for caching and The Fastly Next-Gen WAF (powered by Signal Sciences) is for protecting the servers from ma...
 

Comparisons

 

Also Known As

Cloudflare WAF
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about Imperva Application Security Platform vs. The Fastly Next-Gen WAF (powered by Signal Sciences) and other solutions. Updated: June 2026.
900,838 professionals have used our research since 2012.