Try our new research platform with insights from 80,000+ expert users
Data Protection Officer at Aura
Real User
Top 5
AI-driven analyses improve efficiency and reliability

What is our primary use case?

My main use cases for security testing with PortSwigger Burp Suite Professional are mobile application penetration testing and web application penetration testing in the IT industry.

What is most valuable?

I find all the features of PortSwigger Burp Suite Professional most useful, particularly the AI enhancement for results and follow-up for retests.

This feature helps me follow up on my results and perform retests step-by-step. The automation in AI verifies the findings, ensuring they are correct, and performs step-by-step testing.

The Intruder tool enhances testing efficiency through intercepting information and analyzing it. It helps to analyze web applications and intercept the traffic.

What needs improvement?

The only potential improvement would be adding Postman integration specifically for APIs.

For how long have I used the solution?

I have been working with the tool for five years.

Buyer's Guide
PortSwigger Burp Suite Professional
August 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.

What do I think about the stability of the solution?

I haven't experienced any issues with stability; it is a stable solution.

What do I think about the scalability of the solution?

They have an option for enterprise for scalability, but I currently use just a single license.

My environment is medium-sized, and I am the only user of this tool.

Which solution did I use previously and why did I switch?

Before working with PortSwigger Burp Suite Professional, I evaluated other tools for testing such as OWASP ZAP.

PortSwigger Burp Suite Professional offers benefits because it's not open source, providing extra features such as AI enhancements that are not available on OWASP ZAP. OWASP ZAP is completely free.

How was the initial setup?

The setup process for PortSwigger Burp Suite Professional is quite easy. I would rate the setup a nine on a scale from one to ten, where ten means easy.

Deployment takes approximately two minutes.

What's my experience with pricing, setup cost, and licensing?

The cost of PortSwigger Burp Suite Professional is reasonable at approximately $500 per year per user.

What other advice do I have?

As a user and customer, I can say that PortSwigger Burp Suite Professional is a good tool that performs its intended functions effectively. It operates as an interceptor and analysis tool, completing its tasks reliably.

On a scale from one to ten, I rate PortSwigger Burp Suite Professional a nine.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Flag as inappropriate
PeerSpot user
Senior Business Development Manager at Intouch World
Reseller
Top 5
Enables efficient cost management and supports in-depth penetration testing
Pros and Cons
  • "The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency."

    What is our primary use case?

    I primarily use PortSwigger Burp Suite Professional for penetration testing of applications.

    What is most valuable?

    The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency.

    What needs improvement?

    The dashboard of PortSwigger Burp Suite Professional could be made more user-friendly.

    For how long have I used the solution?

    I have been using PortSwigger Burp Suite Professional for about eight to nine years.

    What do I think about the stability of the solution?

    PortSwigger Burp Suite Professional is a very stable tool, and I would rate its stability as eight out of ten.

    What do I think about the scalability of the solution?

    I would rate the scalability of PortSwigger Burp Suite Professional as eight out of ten.

    How are customer service and support?

    The technical support for PortSwigger Burp Suite Professional is pretty good, and I would give it a nine.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of PortSwigger Burp Suite Professional is straightforward.

    What's my experience with pricing, setup cost, and licensing?

    I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.

    What other advice do I have?

    I would recommend PortSwigger Burp Suite Professional to others. I would rate the overall solution as eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    PortSwigger Burp Suite Professional
    August 2025
    Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
    865,384 professionals have used our research since 2012.
    Khasim Mirza - PeerSpot reviewer
    Security Consultant - Cyber & Information Security at Kinetic IT
    Real User
    Top 10
    Helps with penetration testing and web application testing
    Pros and Cons
    • "The tool provides complimentary services. It allows you to add a lot of extensions, and you can get extensions quite often. It is quite a flexible application."

      What is our primary use case?

      We use the solution for penetration testing, web application testing, etc.

      How has it helped my organization?

      We use the tool to test the application security, like APIs. It is one of the major tool for any security or to test web applications.

      What is most valuable?

      The tool provides complimentary services. It allows you to add a lot of extensions, and you can get extensions quite often. It is quite a flexible application.

      What needs improvement?

      Reporting could be improved. If you use any AI feature, you can go out and take and provide more in-depth information.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for over ten years. We are using the latest version of the solution.

      What do I think about the stability of the solution?

      The product is highly stable.

      I rate the solution’s stability an eight out of ten.

      What do I think about the scalability of the solution?

      The solution is scalable.

      Five users are using this solution.

      I rate the solution’s scalability an eight out of ten.

      How are customer service and support?

      Customer support respond immediately.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The initial setup is easy and take you around ten minute, provided you have downloaded the application.

      I rate the initial setup a nine out of ten, where one is difficult, and ten is easy.

      What about the implementation team?

      The tool was deployed in-house.

      What's my experience with pricing, setup cost, and licensing?

      worth the money spent.

      Which other solutions did I evaluate?

      Yes, there many tools, and also a free tool i.e ZAP

      What other advice do I have?

      it does give you ability to run easily  various attack types , such as Sniper, Pitchfork attack, Battering RAM, Cluster bomb and various other attack types, which can be used to test Web application. 
      Overall, I rate the solution an eight out of ten.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Rooshan Naeem - PeerSpot reviewer
      Security Engineer at Eon Health
      Real User
      Top 5Leaderboard
      The solution helps us when testing applications
      Pros and Cons
      • "It is useful for scanning and tracing activities."
      • "Improvement should be done as per the requirements of customers."

      What is our primary use case?

      I have been using this solution for quite a long time. The features and request tampering are different. This solution helps us when testing applications. It is a flexible tool.

      What is most valuable?

      It is useful for scanning and tracing activities.

      What needs improvement?

      Improvement should be done as per the requirements of customers. 

      For how long have I used the solution?


      What do I think about the stability of the solution?

      I would rate the stability an eight out of ten. 

      What's my experience with pricing, setup cost, and licensing?

      The solution is reasonably priced. 

      What other advice do I have?

      Overall, I would rate the solution a nine out of ten. 

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Akshay Waghmare - PeerSpot reviewer
      Manager at a consultancy with 10,001+ employees
      Real User
      Top 5Leaderboard
      A stable and user-friendly solution that can be used for manual penetration testing
      Pros and Cons
      • "PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up."
      • "The technical support team's response time is mostly delayed and should be improved."

      What is our primary use case?

      We use PortSwigger Burp Suite Professional for manual penetration testing.

      What is most valuable?

      PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up.

      What needs improvement?

      The technical support team's response time is mostly delayed and should be improved.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for six to seven years.

      What do I think about the stability of the solution?

      PortSwigger Burp Suite Professional is a stable solution.

      What do I think about the scalability of the solution?

      Around 500 to 600 users are using the solution in our organization.

      How was the initial setup?

      The solution’s initial setup is quite easy.

      What was our ROI?

      PortSwigger Burp Suite Professional is worth its price.

      What's my experience with pricing, setup cost, and licensing?

      PortSwigger Burp Suite Professional is an expensive solution.

      What other advice do I have?

      Users should get the professional version for the solution because the community and the free edition do not have many things to offer. They should explore as much as possible, go for the web code application, and do the manual penetration testing.

      PortSwigger Burp Suite Professional allows us to do everything from setting the proxy to getting our own browser. Some features were not there in Burp Suite earlier. We had to attach Chrome to the Burp Suite to the proxy, but now they have given everything in a single bundle.

      Overall, I rate PortSwigger Burp Suite Professional ten out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Security Tester at Ray Business Technologies Private Limited
      Real User
      Top 5
      A Stable and Scalable Cloud-based Security Testing Software
      Pros and Cons
      • "The intercepting feature is the most valuable."
      • "Mitigating the issues and low confluence issues needs some improvement. Implementing demand with the ChatGPT under the web solution is an additional feature I would like to see in the next release."

      What is our primary use case?

      The solution has improved the organisation as it helps with scanning and doing the reports for the developers. The solution also helps with communicating the everyday issues and delivering high security and web applications to the customers.


      What is most valuable?

      The intercepting feature is the most valuable.


      What needs improvement?

      Mitigating the issues and low confluence issues needs some improvement. Implementing demand with the ChatGPT under the web solution is an additional feature I would like to see in the next release.


      For how long have I used the solution?

      The solution is used for scanning and doing reports for the developers.


      What do I think about the stability of the solution?

      It is a stable solution.


      What do I think about the scalability of the solution?

      It is a scalable solution. Ten specialists are working with Burp Suite Professional currently. We plan to increase the usage in the future. I rate the scalability an eight out of ten.


      How are customer service and support?

      The solution is implemented through a third-party team.


      How would you rate customer service and support?

      Positive

      Which solution did I use previously and why did I switch?

      I have used Nessus, previously. Nessus helped with only OS and analysis but Burp Suite helps with application scanning, detecting vulnerabilities and expertisation.


      How was the initial setup?

      The initial setup is easy. The deployment is done under a professional, and it takes one hour to be deployed. We have to add our information to get our code directly into the box and then we scan their applications. A single person is required for the deployment. I rate the initial setup a ten out of ten.


      What about the implementation team?

      The solution is implemented through a third-party team.


      What's my experience with pricing, setup cost, and licensing?

      The pricing of the solution is reasonable. We only need to pay for the annual subscription. I rate the pricing five out of ten.


      What other advice do I have?

      All the security issues and the integration of the vulnerabilities will happen automatically and manually in the website. So the solution will be very helpful for the website. I rate the overall solution a nine out of ten.


      Which deployment model are you using for this solution?

      Private Cloud
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      AnkithKumar - PeerSpot reviewer
      Application Security Consultant at a tech services company with 10,001+ employees
      Real User
      Useful advanced tools, integrates well, and quick implementation
      Pros and Cons
      • "The most valuable feature of PortSwigger Burp Suite Professional is the advanced features, user-friendly interface, and integration with other tools."
      • "PortSwigger Burp Suite Professional can improve by having more features in the free version for beginners to try."

      What is our primary use case?

      We use PortSwigger Burp Suite Professional for security. I'm a security tester and I need it for my daily activities, I require it.

      How has it helped my organization?

      PortSwigger Burp Suite Professional has improved the organization by providing the security standards of the applications across the organization.

      We can test the weakness or loopholes in the application an attacker can use. We have an internal team that conducts the pen-testing from a hacker's point of view and try to close the issue before it is opened to the internet.

      What is most valuable?

      The most valuable feature of PortSwigger Burp Suite Professional is the advanced features, user-friendly interface, and integration with other tools.

      What needs improvement?

      PortSwigger Burp Suite Professional can improve by having more features in the free version for beginners to try.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for approximately two years.

      What do I think about the stability of the solution?

      The reliability of PortSwigger Burp Suite Professional is good. It doesn't hang very much, and it doesn't get stuck anywhere, it is reliable.

      What do I think about the scalability of the solution?

      PortSwigger Burp Suite Professional is scalable. You can add in-scope items, and remove any items that are not on the scope.

      We have approximately 30 people using the solution in my organization. We have managers, consultants, and senior consultants using it. If our testers increase the number of users will increase and then we will increase our usage of this solution.

      How are customer service and support?

      I have not needed to use the support from PortSwigger Burp Suite Professional.

      Which solution did I use previously and why did I switch?

      I was previously using OWASP Zap.

      How was the initial setup?

      The initial setup of PortSwigger Burp Suite Professional was simple. It can be done in approximately three minutes.

      I rate the initial setup of PortSwigger Burp Suite Professional a five out of five.

      What about the implementation team?

      I did the implementation of PortSwigger Burp Suite Professional myself.

      If there is a software update it is fairly simple to upgrade. There is a lot of reference material online. 

      What's my experience with pricing, setup cost, and licensing?

      There are multiple versions available of PortSwigger Burp Suite, such as enterprise, commercial, professional, and beginners.

      Which other solutions did I evaluate?

      My company has paid for the license for the solution. The price of the solution could be less expensive.

      What other advice do I have?

      This is one of the best solutions in the market. I would advise others to try this solution out.

      I rate PortSwigger Burp Suite Professional a nine out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Prasenjit Roy - PeerSpot reviewer
      Sr. Cloud Solution Architect - SAP on Azure at Accenture
      Real User
      A web security testing solution with many good functions
      Pros and Cons
      • "For pentesting scenarios, this is the number one tool. It can capture the request, and there are so many functions that are very good for that. For example, a black box satellite host."
      • "The price could be better. The rest is fine."

      What is our primary use case?

      I use PortSwigger Burp Suite Professional for penetration testing.

      What is most valuable?

      For pentesting scenarios, this is the number one tool. It can capture the request, and there are so many functions that are very good for that. For example, a black box satellite host. 

      What needs improvement?

      The price could be better. The rest is fine.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for more than ten years.

      What do I think about the stability of the solution?

      PortSwigger Burp Suite Professional is a stable solution. Sometimes we are limited because of a firewall, and they will block all the proxy requests. Sometimes there are some challenges, but we can manage them.

      What do I think about the scalability of the solution?

      PortSwigger Burp Suite Professional is a scalable solution. We have about 200 users in our company.

      How are customer service and support?

      Technical support is very good. 

      How was the initial setup?

      The initial setup is straightforward, but it is not very user-friendly, and you need someone to install the certificate. It is a bit complex, but we can manage that one. It took more than half an hour to deploy this solution.

      What's my experience with pricing, setup cost, and licensing?

      They should reduce the license cost a little bit. It is $400 per user, and it would be better if they could reduce the licensing fee. 

      What other advice do I have?

      I would tell potential users that if they want to go for penetration testing,  PortSwigger Burp Suite Professional is the obvious choice. 

      On a scale from one to ten, I would give PortSwigger Burp Suite Professional an eight.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2025
      Buyer's Guide
      Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.