We use both Burp Suite Professional and the Enterprise Edition for manual application assessments and dynamic assessments at my client's company.
Cyber security Lead at a manufacturing company with 1,001-5,000 employees
A security testing solution with a useful dynamic scanning feature, but it could be more stable.
Pros and Cons
- "I like normal dynamic scanning, general web applications scanning, and vulnerability assessments."
- "There's definitely room for improvement. There are lots of false positives. Once I do the manual assessment, it comes as a false positive. They need to improve the Enterprise Edition, especially the part that gives false positives."
- "It's not a stable product. Sometimes, it takes a lot of time to scan."
What is our primary use case?
What is most valuable?
I like normal dynamic scanning, general web applications scanning, and vulnerability assessments.
What needs improvement?
There's definitely room for improvement. There are lots of false positives. Once I do the manual assessment, it comes as a false positive. They need to improve the Enterprise Edition, especially the part that gives false positives.
The scan result is also unstable. In some applications, it'll basically give the frameworks, but the GRE is missing from it. It won't report some scans, and some results are substandard.
In the next release, I'm looking for a scanning tool that has SAST and DAST. For example,
Veracode provides all those things. Burp Suite Enterprise Edition only provides vulnerability scanning like static analysis and dynamic analysis, software composition analysis, and practice applications. They should also offer more with different packages.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Enterprise Edition for about two months.
Buyer's Guide
PortSwigger Burp Suite Enterprise Edition
June 2026
Learn what your peers think about PortSwigger Burp Suite Enterprise Edition. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
900,644 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's not a stable product. Sometimes, it takes a lot of time to scan. Sometimes it runs the scan for almost three or four days, and if some audits get filled, it stops immediately. It's unstable and takes lots of time compared other vulnerability scanners. Burp Suite Professional is excellent and stable. It gives lots of options for manual assessment. But PortSwigger Burp Suite Enterprise Edition still has lots of room for improvement.
How are customer service and support?
Technical support gave me a few options to speed up the scanning process, but it still took three or four days. I wasn't satisfied with my experience.
Which solution did I use previously and why did I switch?
Most companies I have worked with over the past decade used Burp Suite Professional for application scanning. Generally, most companies will go for PortSwigger Burp Suite Enterprise Edition for code analysis or go for Checkmarx or HPE Fortify. There are some pretty good solutions available in the market, like IBM AppScan and Acunetix, which are well established in the application scanning market.
How was the initial setup?
The initial setup is straightforward. We have deployed it in vCenter in a VM environment.
What's my experience with pricing, setup cost, and licensing?
PortSwigger Burp Suite Enterprise Edition is expensive compared to other solutions. The license for Burp Suite Professional is more economical and gives you the same scanning features because the scanning, in general, is the same in both editions. But I can't do lots of things like automation in my manual assessment. The Professional edition is preferred my choice if I was making the purchase decisions.
What other advice do I have?
I would tell potential users that it'll work fine with vCenter. You can deploy it because it gives you the option of taking the snapshot and do other stuff quite easily. Manageability is also good in a virtual environment.
On a scale from one to ten, I would give PortSwigger Burp Suite Enterprise Edition a six.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber security Lead at PCS
Can be used for dynamic application scanning, but its stability of the scans could be improved
Pros and Cons
- "Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition."
- "The stability of the scans could be improved."
What is our primary use case?
We use the solution for dynamic application scanning. We used the solution in a big IT solution company to do some certification for the government agency.
What is most valuable?
Parallel scans can be done with PortSwigger Burp Suite Enterprise Edition. Since the solution was deployed in a vCenter solution, the reports could be kept for a longer duration.
What needs improvement?
The stability of the scans could be improved.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Enterprise Edition for six months.
What do I think about the stability of the solution?
I rate the solution a seven out of ten for stability.
What do I think about the scalability of the solution?
I rate the solution six and a half out of ten for scalability.
What other advice do I have?
I rate the solution six and a half out of ten for its user-friendly interface. PortSwigger Burp Suite Enterprise Edition is suited for large projects, and you can increase the memory.
Overall, I rate the solution six and a half out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free PortSwigger Burp Suite Enterprise Edition Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Popular Comparisons
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Tenable Security Center
Tenable Vulnerability Management
Rapid7 InsightVM
Qualys CyberSecurity Asset Management
Buyer's Guide
Download our free PortSwigger Burp Suite Enterprise Edition Report and get advice and tips from experienced pros
sharing their opinions.













