No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 InsightAppSec vs Veracode comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
5th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
21
Ranking in other categories
AI Observability (23rd)
Veracode
Ranking in Dynamic Application Security Testing (DAST)
1st
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Container Security (13th), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Application Security Posture Management (ASPM) (2nd)
 

Mindshare comparison

As of September 2026, in the Dynamic Application Security Testing (DAST) category, the mindshare of Rapid7 InsightAppSec is 5.6%, up from 5.0% compared to the previous year. The mindshare of Veracode is 13.6%, down from 24.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Mindshare Distribution
ProductMindshare (%)
Veracode13.6%
Rapid7 InsightAppSec5.6%
Other80.8%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Brandi Lea - PeerSpot reviewer
Regional Information Security Analyst, Lead at a healthcare company with 10,001+ employees
Rapid risk detection has transformed how I uncover hidden vulnerabilities in new applications
Rapid7 InsightAppSec offers excellent features including a cloud-based platform that allows for detailed breakdowns of information into more digestible bits. The platform is user-friendly with a broad range of tools, although it does require quite a bit of a learning curve. It allows me to aggregate data and put it into presentations to send to executives about the security status across the entire enterprise. My favorite aspect of the user-friendly interface of Rapid7 is the primary cloud-based dashboard, which I find most useful. I love that even inside a browser, the intuitive help options are available for figuring out what things are, whether it's hovering over a particular option for insights or using right-click features that offer tools and tips on managing the vulnerabilities when found. The interface is very clean, not overly convoluted or difficult to navigate, which I do enjoy. Rapid7 has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits. The number of vulnerabilities I am discovering has improved by almost thirty seven percent in the last two years alone. Remediation especially has increased significantly because I am finding these vulnerabilities faster, and Rapid7 provides tips on how to remediate or harden against them, whether through hardening options or upgrading to better versions, which does save the company money.
reviewer2753535 - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
Integrates security into the development process and improves team collaboration
Veracode helps organizations develop software by reducing the risk of security vulnerabilities through developer enablement and applications focused on governance. You can utilize different levels of processes to achieve better performance or a more scalable service. Since I started working with it in 2022, I’ve found it to be cost-effective as well. Overall, Veracode is a user-friendly security tool. It includes features such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA). During the development phase, we can identify vulnerabilities in the application. This process occurs in the staging environment during development. When we're ready to go to production, we conduct a final check. Essentially, this tool helps identify vulnerabilities during the code development stage, including both high-level vulnerabilities and those related to open-source software composition. We utilize specific methodologies for this purpose. Additionally, it offers a feature that allows us to set up policies based on client requirements. This means we can customize the tool to meet the specific needs of our clients, ensuring that they receive the appropriate level of security in their applications. Veracode is user-friendly as well. Compared to other tools, their scans take 15 minutes or under. If you have a large scale of libraries or data, it might take longer, but based on my personal experience, the scan usually runs within fifteen minutes. For my case study using the Veracode tool, I worked on an internal project following industry standards. We used Veracode to improve our security posture and speed up the time to market by streamlining the development process. This enhanced collaboration between developers, operations, and security teams. The automated scanning process helped identify and fix vulnerabilities earlier in the development process. We maintained compliance with regulatory requirements, avoided fines, and built customer trust by integrating security into the development process. When we conduct this scan, we receive data on a list of vulnerabilities. This information improved our communication and increased transparency, which leads to better reports about the efforts being put in. This results in a more effective and efficient collaboration process, making it user-friendly for all involved. When considering costs, if we resort to manual processes, it can be time-consuming. Therefore, we utilize automated scans to identify and fix security issues. This allows us to address vulnerabilities early in the development process, as we discussed previously. This applies both to our in-house code and third-party libraries, using Software Composition Analysis (SCA) agent-based scans. In the future, we will also implement SCA agent-based scans as a separate feature within Veracode, which can help organizations avoid the expensive and time-consuming consequences of security issues. Furthermore, we have seen an increase in compliance, helping to maintain adherence to regulatory requirements and industry standards, thereby avoiding fines and reputational damage associated with noncompliance. Additionally, by integrating security into the development process, we enhance customer trust in our organization and its products.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports."
"It is a very robust solution."
"It's very easy to use and user-friendly, and it does the job."
"The product’s most valuable feature is UI. It is easy to manage and find vulnerabilities in the application."
"I would rate the technical support from Rapid7 a ten, indicating high-quality support."
"The most valuable feature of this solution is the graphical interface."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions."
"Ensures our code and system are 100% compliant."
"The most valuable feature of Veracode is the binary scan feature for auditing, which allows us to audit the software without the source code."
"Overall, it does a very good job of preventing vulnerable code from going into production."
"The one thing we really liked about Veracode when we got it was the consultation calls; that our developers are able to schedule them on their own, instead of going to a "gatekeeper." They upload their code, they have questions, they schedule it, they speak with someone on the other side who is an expert, they can speak developer-to-developers."
"The product is very good, very reliable, and they've made a lot of improvements to the dashboards and the reports."
"What I found most valuable in Veracode Static Analysis is that it categorizes security vulnerabilities."
"The integration with DevOps pipelines is seamless."
"It has the ability to scale, and the fact that it doesn't produce a lot of false positives."
 

Cons

"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange. They need to work a little bit more on their interface to make it more understandable. The interface is the only problem. I'm using Rapid7, which is very intuitive. There are other applications available in the market with a better interface. They can include more techniques or options to test different types of security because the templates are limited. It would be great to see them follow the MITRE ATT&CK framework or what is there in tools like Veracode and Synopsys."
"There is room for improvement in the response time of customer service and support levels."
"The reporting is definitely an aspect of the solution that's in need of some work. We found that we'd try to use widgets, but often getting them to work for us wasn't very clear. They need to be more user friendly or offer better instructions."
"We'd like to see integrations with WAF solutions."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
"I required a solution to manage on-premises, but I was not as satisfied as expected."
"I would like more details of what the product can do."
"The interface is one thing I find a little challenging. Veracode's interface feels a little outdated compared to other solutions, and it could be modernized. I'm mostly happy with the features, but Vercaode could add Docker image scanning."
"CA still has some difficulties integrating the Veracode team in their support services."
"Veracode's ease of use could be improved. I would also like to see more online videos and tutorials that could help us understand the product better. It would also be helpful if Veracode created a certification program for DevSecOps staff to learn about their product and get certified. This kind of training would raise the company's profile within the industry."
"I would like to see them provide more content in the developer training section."
"There are times when certain modules cannot be scanned automatically, requiring us to manually select these modules and initiate the scanning process on our side."
"It would be nice if Veracode were bundled with some preferred vendors like Salesforce and offered at a discount."
"Their documentation is awful and their response time wasn't ideal."
"There should be more APIs, especially in SCA, to get some results or automate some things."
 

Pricing and Cost Advice

"Rapid7 InsightAppSec is cheap."
"The price of this product is very cheap."
"I'm not sure how much it costs exactly, but I know it's expensive."
"Its price is competitive. It is not expensive."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"It's too expensive for the European market. That is why, in a big bank with 400 applications, we are able to use it only for 10 of them. But the other solutions are also expensive, so it wasn't a differentiator."
"I don't really get too involved in the cost sides of things that's in my job, I'm more of a technical focus, but I have heard from my manager and a couple other people that the solution is quite expensive."
"Veracode's pricing is competitive."
"There is a fee to scale up the solution which I consider expensive."
"Pricing/licensing is complicated."
"We're very comfortable with their model. We think they're a good value. We worked very closely with Veracode on understanding their license model, understanding what comprises the fee and what does not. With their assistance in design, we decomposed our application in a way where we are scanning a very significant amount of code without wasting their capacity and generating redundant reported issues. You scan in profiles, per se. And we work with them, in their offices, to design the most effective approach. So the advice I would have for customers is, you can get up and live fast, but work closely with Veracode to refine the method you use for scanning and the way you compile the applications. There's a concept called entry-point scanning, and that's probably not used well by the rest of their customers. We see our licensing as a good value because we leverage it heavily."
"Veracode is affordable for large organizations, but its pricing may be out of reach for small and medium companies."
"Compared to other similar products, the licensing and pricing are definitely competitive. If you see Checkmarx as the market leader, then we are talking about Veracode being a fraction of the cost. You also have to consider your hidden costs: you need a team to maintain it, a server, and resources. From that point of view, Veracode is great because the cost is really a fraction of many competitors."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
13%
Construction Company
10%
Government
10%
Financial Services Firm
9%
Financial Services Firm
14%
Manufacturing Company
11%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise2
Large Enterprise6
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What needs improvement with Rapid7 InsightAppSec?
While Rapid7 InsightAppSec is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode. Hav...
What is your primary use case for Rapid7 InsightAppSec?
My main use case for Rapid7 is onboarding all new applications both built in house and third party acquired, where I run them through a sandbox environment and allow Rapid7 to conduct an initial sc...
What advice do you have for others considering Rapid7 InsightAppSec?
If you are looking for a solution that will help identify vulnerabilities and provide remediation tips for hardening your infrastructure, I think Rapid7 does an excellent job. While I do not know t...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

InsightAppSec
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Rapid7 InsightAppSec vs. Veracode and other solutions. Updated: August 2026.
913,806 professionals have used our research since 2012.