I use it for my customers.
CTO at FPT Telecom
A cheap solution with a good technical support team
Pros and Cons
- "The solution is cheap."
- "Improvement can be done as per customer requirements."
What is our primary use case?
What needs improvement?
Improvement can be done as per customer requirements.
For how long have I used the solution?
I have been using HCL AppScan for some time.
How are customer service and support?
The technical support is good.
Buyer's Guide
HCL AppScan
June 2026
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
How was the initial setup?
The initial setup took one to two days.
What's my experience with pricing, setup cost, and licensing?
The solution is cheap.
What other advice do I have?
I rate the overall solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Scientific Officer at a tech services company with 51-200 employees
Efficiently scans through the website and identifies vulnerabilities
What is our primary use case?
HCL AppScan efficiently scans through the website and identifies vulnerabilities for AWS. It is reducing tools day by day, making it more efficient.
What needs improvement?
HCL AppScan generates false results. Sometimes, it incorrectly identifies requests as vulnerable when they are not vulnerable. In the ADSL feature managed, the primary objective is to identify application security vulnerabilities. However, sometimes AppScan wrongly flags something as a vulnerability when it's not present, which we call a false positive.
For how long have I used the solution?
I have been using HCL AppScan for nine years.
What do I think about the stability of the solution?
I rate the solution’s stability an eight out of ten.
What do I think about the scalability of the solution?
The solution is scalable if required.
How are customer service and support?
Customer support is helpful.
How would you rate customer service and support?
Positive
How was the initial setup?
There is a licensing partner. Sometimes, it is required to install a server. I must remove that license and then eject a new one on a different server. It becomes a bit harder for beginners if they do not have enough experience to install Zoho software.
Deployment takes around an hour, and one person can do it.
I rate the initial setup a six and a half out of ten, where one is difficult and ten is easy.
What's my experience with pricing, setup cost, and licensing?
The tool is not cost-efficient. Considering the type of service with encryption security scanning from HCL AppScan, it drives up the cost unnecessarily. It is fairly priced.
What other advice do I have?
There are some very cost-effective solutions out there. They are also very efficient for systems scanning.
Overall, I rate the solution an eight-point five out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
HCL AppScan
June 2026
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
Mechanical maintenance technician at SAQ
Helps with the scan of the web interface and supports special languages
Pros and Cons
- "Compared to other tools only AppScan supports special language."
- "The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed."
What is our primary use case?
I use the tool to scan the web interface.
What is most valuable?
Compared to other tools only AppScan supports special language.
What needs improvement?
The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed.
For how long have I used the solution?
I have been using the solution for two years.
How are customer service and support?
The solution has dedicated and good tech support. We can open a ticket and we get information within two hours. Once we open a ticket we get validation or confirmation of our problem. When we get to the specialist, we will get more information.
How would you rate customer service and support?
Positive
What other advice do I have?
I would rate the overall solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Global Business Development Executive - Applications, Data & AI Practice at Kyndryl
Stable and scalable but not user-friendly
Pros and Cons
- "AppScan is stable."
- "I mainly use AppScan for vulnerability scanning and database bridging."
- "AppScan is too complicated and should be made more user-friendly."
What is our primary use case?
I mainly use AppScan for vulnerability scanning and database bridging.
What needs improvement?
AppScan is too complicated and should be made more user-friendly.
For how long have I used the solution?
I've been using HCL AppScan for three to four years.
What do I think about the stability of the solution?
AppScan is stable.
What do I think about the scalability of the solution?
AppScan is scalable.
How are customer service and support?
HCL's technical support is ok, but it could be faster and more responsive.
How was the initial setup?
The initial setup was complex and took about a day and a half.
What other advice do I have?
I would rate AppScan four out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Innovation manager at a computer software company with 51-200 employees
Affordable and easy to expand but needs better performance
Pros and Cons
- "It was easy to set up."
- "The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great."
- "The performance could be better. Sometimes it doesn't work so well."
What is our primary use case?
I have a set project, and I'm writing an application for monitoring server status, and I tried several times to scan it with AppScan in order to understand if there are vulnerabilities in my code.
What is most valuable?
The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.
It was easy to set up.
It's a stable solution.
The product is easy to scale.
The solution is affordable and reasonably priced.
What needs improvement?
The performance could be better. Sometimes it doesn't work so well. There's a tool for connecting the cloud with the application server. Sometimes it doesn't work really well.
I have not come across any missing features.
For how long have I used the solution?
I've been using the solution for six months. It's been less than a year so far.
What do I think about the stability of the solution?
The solution has been stable. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
So far, we've found the solution can scale well.
How are customer service and support?
I've reached out to support in the past. They are pretty good, however, they are also working from India, and I'm in Italy. There is a delay of course when I open a ticket. We have to wait a bit due to the time shift.
Which solution did I use previously and why did I switch?
We did not previously use a different solution. This was our first.
How was the initial setup?
The initial setup is pretty simple and straightforward. It's not an overly complex or difficult process.
It took about one day to deploy the solution.
What about the implementation team?
I handled the initial setup on my own. I did not ask for help from any consultants or integrators.
What's my experience with pricing, setup cost, and licensing?
I actually pay for tokens. Any time that I want to perform scanning, I have to pay for another token. It's pretty good for me, this system, as it's really, really nice when I need it. I just need to pay for it, and that's it.
What other advice do I have?
We are end-users.
I'd rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager, IT Test Automation Engineering at a outsourcing company with 10,001+ employees
Offers a few specific development languages but needs more languages and lacks good technical support services
Pros and Cons
- "The solution offers services in a few specific development languages."
- "They have to improve support."
- "This product lacks in many areas, and so we are looking at other options."
What is most valuable?
The solution offers services in a few specific development languages.
What needs improvement?
They have to improve support. Their support before, when it was IBM, was very good technical support. However, now, it's very bad.
They could add more language coverage. They don't cover so many development languages. They really should be covering more. If they did, it would be a huge improvement.
How are customer service and technical support?
The technical support is no longer any good. It's gone downhill since they were under IBM. Now, we are no longer satisfied with their level of service and we hope they will improve their services in the future.
Which other solutions did I evaluate?
I'm currently looking into Checkmarx. I'm evaluating their offering to see how it compares. This product lacks in many areas, and so we are looking at other options.
What other advice do I have?
I don't have information on the relationship HCL has with my company. My understanding is they are just a vendor for us.
In general, I would rate them at a six out of ten. There are many areas in which they could improve, including by adding more languages and re-vamping their technical support. They are lacking in a lot of areas.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
General Manager at a consultancy with 51-200 employees
Allows for dynamic scanning but lacks easy CI/CD integration
Pros and Cons
- "It identifies all the URLs and domains on its own and then performs tests and provides the results."
- "It's a good product; its automated crawler identifies all URLs and performs security tests, and it has very rich test cases which ensure pretty good coverage in terms of security testing while the UI is user friendly and intuitive."
- "One thing which I think can be improved is the CI/CD Integration"
- "Currently, we are satisfied with AppScan but I am sure there are better alternatives available because this is a very old product."
What is our primary use case?
We perform more dynamic scanning using AppScan. We set up a scan, perform it and get the results, and then give the results back to our customer.
Within our organization, there are four members of the team who are using it.
Currently, we are satisfied with AppScan but I am sure there are better alternatives available because this is a very old product. It's been on market for more than ten years now. I am sure there are a lot of new age products that are more scalable and cloud-based. Although we are using it and will probably continue to do so moving forward, I think there are better alternatives on the market now.
How has it helped my organization?
It takes care of our dynamic scanning needs.
What is most valuable?
It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive.
What needs improvement?
There are some false positives, which need to be removed, but this is common with all types of scanners.
One thing which I think can be improved is the CI/CD Integration. There is a CI/CD Integration model, but I guess they are deliberately not using it currently. There are challenges when integrating AppScan with CI/CD because sometimes the activation plus the login mechanism provided doesn't work properly. Sometimes a login mechanism fails and then the whole scan fails. It's difficult to integrate with CI/CD.
For how long have I used the solution?
I have been using this solution for almost two years.
What do I think about the scalability of the solution?
Scalability-wise, I'm not sure because you can buy the licenses depending on how many scans you want to do, but yes, it's scalable. I can do multiple scans simultaneously, but we have not tried more than that. I cannot tell you whether it can scale up to more than maybe two, three, or four simultaneous scans. We have not tested that.
How are customer service and technical support?
The technical support is quite good. They always respond quickly.
How was the initial setup?
Installation is pretty straightforward. Deployment only took a day or two.
What about the implementation team?
We deployed it ourselves. Even one person can manage it so that's not an issue, but currently, we have four users who perform the activities and scans because of the volume of requests that we received from different businesses.
What other advice do I have?
I would recommend AppScan to other businesses. In a small-scale setup, it works perfectly fine, but if you are a larger organization with a lot of applications and you need to do CI/CD, then it's probably not the solution for you. Conversely, in a small organization with less than 20 applications, this will work pretty nicely.
On a scale from one to ten, I would give this solution a rating of seven.
If they can integrate with CI/CD and make the log-in mechanism a little smoother, they should be able to scale it up. If they could integrate with the CI/CD pipeline and make the scans a little faster, then I would give it a higher rating.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
A low rate of false positives translates to a savings in time
Pros and Cons
- "This solution saves us time due to the low number of false positives detected."
- "The most valuable feature is that it achieves a very low false-positive detection rate."
- "IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."
What is our primary use case?
The primary use case is to detect time-based Blind SQL Injection attacks, as well as Error-Based Injection attacks. The SQL injection attack is my favorite and I have more expertise in this vulnerability.
How has it helped my organization?
This solution saves us time due to the low number of false positives detected. Other scanners have an issue with respect to reporting false positives.
What is most valuable?
The most valuable feature is that it achieves a very low false-positive detection rate.
What needs improvement?
While I did not identify any specific bugs in this application. I did find that sometimes a restart was needed to deal with unresponsiveness means when AppScan is in a hang situation, this happens usually when you select a large number of sources.
IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.
For how long have I used the solution?
One to three years.
Which solution did I use previously and why did I switch?
We previously used Burp Suite. This application is best for static scanning.
How was the initial setup?
Complex
Which other solutions did I evaluate?
We also evaluated Acunetix and Nexpose.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief researcher at INSEC Security
The depth was low, but the part that the user could miss was also diagnosed
Pros and Cons
- "AppScan seems to be very good at detecting reflected XSS vulnerabilities."
- "The depth was low, but the part that the user could miss was also diagnosed."
What is our primary use case?
External and internal web application vulnerability scan.
How has it helped my organization?
- We were able to easily diagnose a large number of web applications automatically.
- The depth was low, but the part that the user could miss was also diagnosed.
What is most valuable?
AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.
What needs improvement?
It would be nice to be able to specify the parameter values used in the login sequence function.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at a tech vendor with 501-1,000 employees
Scalable and powerful, helps find errors in the code base
Pros and Cons
- "Scalability, and it's a very powerful tool."
- "I think it's a little bit complex, and that's quite a common issue with most of the IBM products."
What is our primary use case?
Our clients use it to try to find errors in base code, and also to find how solutions work together.
I believe they have on-premise usage; they are local government, so they are not very used to using the cloud.
How has it helped my organization?
I'm mainly working on the licensing side and not the technical side, so I don't get this kind of feedback.
What is most valuable?
Scalability, and it's a very powerful tool.
What needs improvement?
I believe there are improvements that can be made, but I'm not aware of those kinds of things.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
It's stable.
What do I think about the scalability of the solution?
For the market in Finland, when we are talking about a mid-size company, it equals a small company here in the USA, but they are mainly from 1,000 users to 10,000 users.
How is customer service and technical support?
Tech support is responsive. With the local support I get all the help I need. I'm a former IBMer, so I know the right contacts, so it's quite simple to work.
How was the initial setup?
I think it's a little bit complex, and that's quite a common issue with most of the IBM products.
Which other solutions did I evaluate?
Some of the customers are using office open-source tools, but most are not using a tool at all. So, that's the competition. Of course, they are thinking about return on investment because it's quite an expensive tool and they won't take it back.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST)Popular Comparisons
SonarQube
Checkmarx One
GitLab
Veracode
CrowdStrike Falcon Cloud Security
PortSwigger Burp Suite Professional
Acunetix
Coverity Static
Mend.io
Sonatype Lifecycle
OpenText Core Application Security
GitHub Advanced Security
GitGuardian Platform
OWASP Zap
Buyer's Guide
Download our free HCL AppScan Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Difference between IBM Appscan and HP fortify software
- Which solution do you prefer: Fortify WebInspect or HCL AppScan?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?


















