No more typing reviews! Try our Samantha, our new voice AI agent.
it_user399378 - PeerSpot reviewer
Director of Information Technology at a tech consulting company with 501-1,000 employees
Consultant
Mar 10, 2016
It enforces source-code scanning and finding vulnerabilities in source code. It would be nice if it could manage the false positives better.
Pros and Cons
  • "It enforces source-code scanning, finding vulnerabilities in source code."
  • "Stability could use a little improvement as we've had some issues. It runs out of memory sometimes and uses a lot of resources."

What is most valuable?

It enforces source-code scanning, finding vulnerabilities in source code.

How has it helped my organization?

We're able to find vulnerabilities and weaknesses actually posting to site. We can get to these issues in our staging areas for active data and for verifying user vulnerabilities. It helps the development cycle in that we don't need other people involved in the scans. We're doing pre-scans and then getting other teams involved.

What needs improvement?

There are a lot of false positives and there's not a good way to manage them. They appear after every scan, and it would be nice to have them marked out so that we don't see them.

What was my experience with deployment of the solution?

We've had no issues with deployment.

Buyer's Guide
OpenText Core Application Security
June 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.

What do I think about the stability of the solution?

Stability could use a little improvement as we've had some issues. It runs out of memory sometimes and uses a lot of resources. Sometimes the scans don't work.

What do I think about the scalability of the solution?

For code scans, company size doesn't really matter so much as the size of the code. It works well with the code scans we're running. Our lines of code aren't as huge as other applications we build, and it doesn't support every type of our applications, which are primarily .NET and HPE apps.

How are customer service and support?

Technical support isn't top-notch, but it's not bad. It's just average. They take a while to resolve issues.

How was the initial setup?

The initial setup was pretty easy and straightforward.

What other advice do I have?

Find the solution that works best for your environment, using the group concept to try them all. Then determine which is best for you.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user362055 - PeerSpot reviewer
Senior Manager at a tech services company with 10,001+ employees
Real User
Dec 31, 2015
It addresses the source code scanning and dynamic scanning in a known, correlated way.
Pros and Cons
  • "I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way."
  • "It could use better integration with the incident management processor."

Valuable Features

It's one of the leaders in the application security space. I've used Fortify since 2007, and I think the most valuable feature is its ability to address the source code scanning and dynamic scanning in a known, correlated way. I think the best way to address application security is to have multiple types of scanning and a unified view for the customer.

Improvements to My Organization

It's forced the incorporation of security in the development process. That's really the biggest benefit for us.

Room for Improvement

It could use better integration with the incident management processor. This would allow us to understand the vulnerabilities that arise in the software and how they're linked to the incident management center.

Deployment Issues

The deployment has not had issues.

Stability Issues

It is a quite stable solution.

Scalability Issues

It's quite scalable and addresses a huge volume.

Customer Service and Technical Support

It's good, but could be better to align with other main vendors, such as IBM.

Initial Setup

It's not straightforward, but it's not complex either. It could also be improved.

Other Solutions Considered

I'm very familiar with IBM and Barracuda and others. I always know HP's competition, but I feel most comfortable with HP.

Other Advice

My advice would be to look not only at the software, but also at the processor and the people who will be using the software. You should buy not just the software, but also the services to train people to use it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user310152 - PeerSpot reviewer
it_user310152Fortify Business Development at a tech vendor with 10,001+ employees
Vendor

In terms of integration with SIM/SIEM solution, what do you use?

Buyer's Guide
OpenText Core Application Security
June 2026
Learn what your peers think about OpenText Core Application Security. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,747 professionals have used our research since 2012.
it_user326421 - PeerSpot reviewer
Solution Security Architect with 1,001-5,000 employees
Real User
Oct 16, 2015
It has added a very quick turnaround for security code reviews, allowing us to integrate this function into the overall development and testing lifecycle.
Pros and Cons
  • "Excellent – from the PoC through setup and implementation; we received timely and knowledgeable support whenever we need it."
  • "It needs to support more languages."

What is most valuable?

  • It's On-Demand, and cloud-based which is well suited to occasional and price-conscious use.
  • Fast turn-around allows for easy integration into the development process without any major impact on development efforts.

How has it helped my organization?

It has added a very quick turnaround for security code reviews which allowed us to integrate this (formerly missing) function into the overall development and testing lifecycle.

What needs improvement?

It needs to support more languages.

For how long have I used the solution?

I've used it for three months.

What was my experience with deployment of the solution?

No issues encountered.

What do I think about the stability of the solution?

No issues encountered.

What do I think about the scalability of the solution?

No issues encountered.

How are customer service and technical support?

Excellent – from the PoC through setup and implementation; we received timely and knowledgeable support whenever we need it.

Which solution did I use previously and why did I switch?

We tried to do it by hand (which was very time consuming and error-prone) and some tools built-in to Visual Studio (which was not widely accepted by individuals).

How was the initial setup?

We had some issue with logins and account setups, but received excellent support.

What about the implementation team?

We implemented it ourselves with the help of HP.

What was our ROI?

Don’t know since the project got cancelled.

What other advice do I have?

Take advantage of the free trial and conduct a meaningful PoC. Get a buy-in from upper management early and co-ordinate with all stakeholders (e.g. developers, testing and/or QA groups).

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Information Security Advisor, CISO & CIO, Docutek Services at Docutek Services
Consultant
Top 20Leaderboard
Jul 6, 2015
It provides an independent review of third-party applications, allowing organizations to test software before purchasing. But try the free version first as there's no "right" way to measure ROI.
Pros and Cons
  • "HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software."

    What is most valuable?

    I was able to quickly pass compliance with HIPAA.
    Correlated static and dynamic results with detailed priority guidance.
    Accurate results, tailored to each application.
    All results manually reviewed by application security experts .
    Central testing program management for all applications.

    How has it helped my organization?

    HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software. Third-party vendors can upload the source code and/or provide a URL, review the results, and then publish a report back to their customer.

    This service compels commercial vendors to take action to proactively fix vulnerabilities, while allowing them to remain in control of their applications. Security professionals can demand that high-priority problems be addressed and verified during the procurement or upgrade process, prior to acceptance. HP Fortify on Demand serves as an independent third-party solution to conduct unbiased analysis of applications and provide a detailed tamper-proof report back to the security team.

    What needs improvement?

    You are going to like the new detailed reporting. It can correlate the results from different forms of testing and prioritize them by severity to present the truest representation of application risk.

    For how long have I used the solution?

    1 year

    What was my experience with deployment of the solution?

    It was very easy to install and deploy.

    What do I think about the stability of the solution?

    No.

    What do I think about the scalability of the solution?

    No. Scalable infrastructure allows for fast turnaround times and it has no limitations based on lines of code, megabytes, or anything else.

    How are customer service and technical support?

    Customer Service:

    Good

    Technical Support:

    Good

    Which solution did I use previously and why did I switch?

    I currently use other solutions. We gave HP Fortify on Demand a try and we are very happy with the results.

    How was the initial setup?

    Yes. Very easy.

    What about the implementation team?

    We tried the free version first and then we acquired the software the product website.

    What was our ROI?

    Keep in mind that the calculation for return on investment and, therefore the definition, can be modified to suit the situation. It all depends on what you include as returns and costs. The definition of the term in the broadest sense just attempts to measure the profitability of an investment and, as such, there is no one "right" calculation. But, I have to say the client is very satisfied.

    What's my experience with pricing, setup cost, and licensing?

    Try the free version first.

    Which other solutions did I evaluate?

    I am already using other software. We wanted to try it and it works like a charm.

    What other advice do I have?

    Trust me, you want to be able to do automated and manual testing on a web application that is live.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
    PeerSpot user
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: June 2026
    Buyer's Guide
    Download our free OpenText Core Application Security Report and get advice and tips from experienced pros sharing their opinions.