We use WebInspect for dynamic application security testing, and integrating that into all our needs.
Assoc. Director at a tech services company with 10,001+ employees
Easy to use and has good cost/value
Pros and Cons
- "It is scalable and very easy to use."
- "The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
What is our primary use case?
What is most valuable?
In terms of its most valuable features, it is scalable and very easy to use.
What needs improvement?
Right now, it's kind of bulky. There are a lot of newer generation tools coming out that are easier.
Also, when it comes to the installation and deployment, they inspect the enterprise. It was ok with the scale, but still I think they can make it a little lighter in nature.
For how long have I used the solution?
I have been using WebInspect for around six, seven years.
Buyer's Guide
OpenText Dynamic Application Security Testing
June 2025

Learn what your peers think about OpenText Dynamic Application Security Testing. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,129 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's quite a stable product.
What do I think about the scalability of the solution?
WebInspect is a scalable product. We have users in the double digits, around 10-15 users. At any time there are a couple of project users, so I would say around eight to ten.
We require one person maximum for deployment and maintenance.
How are customer service and support?
I have been satisfied with my experience with the customer support.
Which solution did I use previously and why did I switch?
I previously used AppScan. We switched due to an overall change in our organization in Azure. IBM sold this to HCL so there is no IBM grant attached to it.
How was the initial setup?
The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex.
The first time we deployed it, it really took awhile because of some issues on our side and on their side. Installation can last for more than three days.
What about the implementation team?
Our team implemented it along with some of the other professional departments.
Which other solutions did I evaluate?
We did evaluate AppScan for this task. Both solutions are good. We also evaluated Oracle of course, but it is purely a SaaS solution and that's the reason it was not considered.
What other advice do I have?
Yes, I would recommend WebInspect. It is a good product, comparable to AppScan. It is quite scalable, and good cost/value with the support and backing from Micro Focus. It's good and I definitely recommend it.
On a scale of one to ten, I would give it an eight.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Senior Software Developer at a financial services firm with 10,001+ employees
Stable and well-known for dynamic application scanning but needs better integration with the cloud
Pros and Cons
- "It's a well-known platform for doing dynamic application scanning."
- "The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
What is our primary use case?
We primarily use the solution for dynamic application scanning.
What is most valuable?
It's a well-known platform for doing dynamic application scanning.
What needs improvement?
The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We've yet to test the scalability of the solution, so I can't comment on how scalable it is just yet. Right now, we have our DevOps team working with it, about three to five people.
How are customer service and technical support?
We've never been in touch with technical support.
How was the initial setup?
Right now we are in the middle integration, so I'm not sure how much time it's going to take. We haven't yet scanned any of our endpoints, and I'm not sure how much complexity will be involved during the process.
What other advice do I have?
We're using the public cloud deployment model. Our provider is Microsoft.
We just chose the solutions for dynamic scanning and static scanning, but we haven't performed any scanning yet.
I'd recommend it; I'd rate the solution seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
OpenText Dynamic Application Security Testing
June 2025

Learn what your peers think about OpenText Dynamic Application Security Testing. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,129 professionals have used our research since 2012.
Information Security Architect at a real estate/law firm with 1,001-5,000 employees
Great centralized dashboard but is a bit overpriced
Pros and Cons
- "I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
- "I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
What is our primary use case?
We primarily use the application for web application scanning.
What is most valuable?
I've found the centralized dashboard the most valuable. For management, it helps a lot to have abilities at the central level.
What needs improvement?
The solution needs improvements from the scanning and the technical perspective.
In the next release, we would love to see smooth scale mobile testing - if it has similar to testing with wider applications for different technologies as well because people are moving towards mobile. If the solution can integrate AI and also understand the application by itself, this will be great.
For how long have I used the solution?
I've been using the solution for three months.
What do I think about the stability of the solution?
Stability wise, the tool is stable, but the tool still requires some improvements in the latest technology websites. For example, if there is a single website or e-commerce website, it is still trying to understand a lot of the applications while it scans. It is not that smooth with complex websites. We have about 80-100 users on the solution.
How are customer service and technical support?
So far technical support is good. It is fair enough. They haven't got a response or turn around time. From the support perspective, it is good.
Which solution did I use previously and why did I switch?
I haven't used any different solution here, but in another organization, I have used multiple application scanning products. I've used IBM scan. I have used SecuRex. Those were good as well.
How was the initial setup?
The initial setup is pretty good. They have a step by step guide and everything is given. It sets up with the environment but it requires a lot of memory and the system requires a lot of memory. That is the only negative, normally if you have a three-way scanner, it would run smoothly on even a small configuration laptop. This was a delicate setup.
What's my experience with pricing, setup cost, and licensing?
I'm not sure about the licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools with similar functionalities. The pricing is a little more costly than other regular solutions. There are only two such products that are this costly. This and IBM. The rest of the application scanners are not as costly.
What other advice do I have?
I am currently evolving, going through the product. We have yet to go through all the features and functionalities of the product. The way it checks for vulnerabilities helps a lot. It makes the most of the check for vulnerabilities. The centralized dashboard for the management is good but I'm still looking into it. That and other features we are yet to be discovered. I'm still trying to get to know all the features.
Looking at an enterprise level product is good. With it, you get a centralized board, you have a management view, enroll management and access management. Everything is there. But still, check your requirements, what you need. If you use it for a certain amount of applications, you might not need such a heavy tool.
Our requirement is 10 or 20 times more than a regular company and hence we went with an enterprise solution and had somebody who could implement this. If your requirement is a little less, it might just call for some other scanners based on your requirements.
If you do need such an extensive requirement, ensure that you also have the data servers and systems for such tools. It will be easy to implement in any environment if you do.
I would rate this solution 7 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Consultant at a tech services company with 1,001-5,000 employees
Good technical support but needs a reduction in false positives
Pros and Cons
- "Technical support has been good."
- "The initial setup was complex."
What needs improvement?
The service can be improved by creating a reduction of false positives.
For how long have I used the solution?
I've been using the solutions for the last three months.
What do I think about the scalability of the solution?
My organization is a big organization so I don't know exactly if my organization will increase usage.
How are customer service and technical support?
My experience with technical support has been good.
Which solution did I use previously and why did I switch?
We did use a different solution previously.
How was the initial setup?
The initial setup was complex.
What other advice do I have?
Currently, I'm satisfied with the solution. I would rate this product a 7 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Ops Risk Lead at a tech services company with 10,001+ employees
Needs a cloud-based version, although it's easy to scan and then to share scan reports
Pros and Cons
- "Guided Scan option allows us to easily scan and share reports."
- "One thing I would like to see them introduce is a cloud-based platform."
- "We have often encountered scanning errors."
How has it helped my organization?
Easy to scan and then share scan reports, it has definitely streamlined many processes.
What is most valuable?
Guided Scan option allows us to easily scan and share reports.
What needs improvement?
One thing I would like to see them introduce is a cloud-based platform.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
We have often encountered scanning errors.
What do I think about the scalability of the solution?
Not applicable.
How is customer service and technical support?
I would rate tech support at six out of 10.
How was the initial setup?
The setup was very straightforward.
What's my experience with pricing, setup cost, and licensing?
It’s a fair price for the solution.
Which other solutions did I evaluate?
No, we did not evaluate other options.
What other advice do I have?
I rate it five out of 10. I was not very impressed.
It's a good product, but get a license for cloud-based, if available.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free OpenText Dynamic Application Security Testing Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Popular Comparisons
Aqua Cloud Security Platform
Rapid7 InsightAppSec
PortSwigger Burp Suite Enterprise Edition
Check Point CloudGuard Code Security
Buyer's Guide
Download our free OpenText Dynamic Application Security Testing Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What alternatives are there for Fortify WebInspect and Fortify SCA?
- Which solution do you prefer: Fortify WebInspect or HCL AppScan?
- When evaluating Dynamic Application Security Testing (DAST), what aspect do you think is the most important to look for?
- Why is Dynamic Application Security Testing (DAST) important for companies?
Agreed, but as comparing with other cloud based web app scan tools, Web Inspect results are much more accurate, hence as a tool MicroFocus should start making this tool as a cloud version