

PortSwigger Burp Suite Professional and OpenText Core Application Security are competitors in the security testing market. Burp Suite seems to have the upper hand due to its affordability, strong community support, and effective testing features, making it a popular choice among cost-conscious users.
Features: PortSwigger Burp Suite Professional is known for its community support, extensive plugins, and features like Intruder and Repeater that enhance penetration testing. Its scalability and automation are notable advantages. OpenText Core Application Security is distinguished by its powerful integration capabilities, comprehensive testing features, and adaptability, though it comes at a higher cost. It supports a wide range of languages and frameworks.
Room for Improvement: PortSwigger Burp Suite Professional could improve its reporting features, reduce false positives, and enhance API security testing. Lowering RAM usage and scan time would also optimize performance. OpenText Core Application Security needs better integration with CI/CD tools, false positive management, and enhanced UI/UX. Expanding language support and pricing flexibility could broaden its user base.
Ease of Deployment and Customer Service: Both products offer on-premises and cloud deployment, with OpenText offering more hybrid options. Burp Suite is recognized for solid technical support and valuable online resources, albeit with potential response delays. OpenText provides robust service with responsive support and detailed documentation, though integration challenges can affect deployment.
Pricing and ROI: Burp Suite Professional is generally seen as affordable at $400-$500 annually per user, with a strong ROI from its accessibility and testing efficiency. Its cost-effectiveness appeals to smaller budgets. OpenText Core Application Security is perceived as expensive, yet justified by its advanced features and integration capabilities, benefiting larger deployments. Flexible licensing attempts to cater to varied needs, yet pricing could hinder smaller businesses.
There is definitive ROI if OpenText Core Application Security is deployed properly; it substantially reduces efforts in securing the solution while averting various application-related risks.
I had direct interaction with them, which facilitated how we onboarded Fortify.
Support tickets often stay open for one month to three months, which leads to customer frustration.
The technical support from OpenText is very good.
The technical support from PortSwigger is excellent.
The technical support for PortSwigger Burp Suite Professional is pretty good, and I would give it a nine.
OpenText Core Application Security is highly scalable; it is running on the cloud, and elasticity is one of the best points of a cloud environment.
If a customer wants to know the tools and the technology used for their application to scan their application, they provide less information on that.
Fortify is superior to many solutions because of its scalability and that it does not require massive compute capabilities for its SAST and sandboxing features.
OpenText Core Application Security is stable and has minimal downtime, benefitting from AWS cloud availability.
PortSwigger Burp Suite Professional is very stable.
PortSwigger Burp Suite Professional is a very stable tool, and I would rate its stability as eight out of ten.
I would say OpenText Core Application Security is not very user-friendly in terms of price; it is quite high.
It would be beneficial if Fortify could check for CVEs (Common Vulnerabilities and Exposures) in third-party libraries, which I currently use a separate dependency checker tool for.
One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together.
Perhaps they could add some automation to things, to see what we do manually, which it has the tools to do manually, and perhaps enable with a click of a button to do things automatically.
Some AI features might be added.
The dashboard of PortSwigger Burp Suite Professional could be made more user-friendly.
The pricing for PortSwigger is very cheap, and there are benefits in terms of time and cost savings.
I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.
Additionally, you can integrate Fortify in CICD pipeline, so you get real-time updates about the security issues in your pipeline.
On demand you have two levels of reports: the first from the tool, which is the same as we can get from Fortify on-premises, and a next level reporting made by experts from OpenText, leading to a more condensed and precise report as level three.
The integration of OpenText Core Application Security with existing systems for security operations benefits us by providing vulnerability management and quality gates; without both, we will always have vulnerable applications running for our customers.
The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency.
One of the best things in PortSwigger Burp Suite Professional is that it has its own browser.
I especially value the features for penetration testing.
| Product | Mindshare (%) |
|---|---|
| PortSwigger Burp Suite Professional | 3.1% |
| OpenText Core Application Security | 3.1% |
| Other | 93.8% |

| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 8 |
| Large Enterprise | 45 |
| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 14 |
| Large Enterprise | 35 |
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
PortSwigger Burp Suite Professional is a vital tool for cybersecurity experts, valued for features like Intruder and Repeater, and offering strong automation for effective vulnerability detection and web security.
PortSwigger Burp Suite Professional aids organizations in conducting comprehensive application security testing. With functions like scanning, proxy setup, and numerous plugins, it provides essential support for vulnerability assessments and penetration testing. Despite needing improvements in reporting, false positive reduction, and scanning speed, it remains adaptable for different security operations through its automation, extensive community support, and regular updates. Licensing and pricing flexibility are considerations, alongside API security enhancements and documentation improvements. Widely used for intercepting and scanning web applications pre-launch, it supports compliance testing while offering tools for request replaying, traffic manipulation, and brute forcing.
What are the key features of PortSwigger Burp Suite Professional?In industries like finance and healthcare, PortSwigger Burp Suite Professional is implemented to enhance application security frameworks. It provides critical insights for regulatory compliance and risk management. The tool's adaptability supports organizations in routinely identifying and addressing vulnerabilities, ensuring robust protection against potential threats and facilitating secure application launches.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.