I mainly use Burp Suite for manual testing, using it as a proxy to do my manual pen test.
Cyber Security Engineer at a transportation company with 10,001+ employees
A must-have for those knowledgeable in application security
Pros and Cons
- "The most valuable feature is Burp Collaborator."
- "Burp Suite gives you a very good automated scanning tool, which gives you around sixty to seventy percent security coverage without having to use a security resource."
- "BurpSuite has some issues regarding authentication with OAT tokens that need to be improved."
- "BurpSuite has some issues regarding authentication with OAT tokens that need to be improved."
What is our primary use case?
How has it helped my organization?
Burp Suite gives you a very good automated scanning tool, which gives you around sixty to seventy percent security coverage without having to use a security resource. Once the developer gets the report, they've got the PortSwigger lab to explain the vulnerability and have a POC right there, so it's very beneficial for developers.
What is most valuable?
The most valuable feature is Burp Collaborator.
What needs improvement?
BurpSuite has some issues regarding authentication with OAT tokens that need to be improved.
Buyer's Guide
PortSwigger Burp Suite Professional
March 2026
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
For how long have I used the solution?
I've been using this solution for around seven years.
What do I think about the scalability of the solution?
The Professional version is not very scalable because you need to buy licenses for each user, but the Enterprise version takes care of that.
How are customer service and support?
The support for the Enterprise solution isn't the best (I'd rate it as three out of five), but the Professional version provides all the documentation and the PortSwigger labs, so it's much better.
Which solution did I use previously and why did I switch?
I previously used OS SAP, but I switched to Burp Suite when the support for that solution stopped.
How was the initial setup?
The initial setup is very easy because Burp Suite has very good documentation. Setup took less than an hour, though it might take a less-experienced person longer to install a mobile application because of the application-level security.
What other advice do I have?
I would say Burp Suite has now surpassed SAP as a tool. The main aspect of Burp Suite is that it's like an army knife for a hacker, it's not just the automation or the scanning that it brings. For a person with 80-90% knowledge of application security, this tool is a must-have. I would rate Burp Suite nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head for Application Security at Hexaware Technologies Limited
Effective automatic scanning, Academy portal for learning, and reliable
Pros and Cons
- "The automated scan is what I find most useful because a lot of customers will need it. Not every domain will be looking for complete security, they just need a stamp on the security key. For these kinds of customers, the scan works really well."
- "This solution has helped our company in many ways."
- "There could be an improvement in the API security testing. There is another tool called Postman and if we had a built-in portal similar to Postman which captures the API, we would be able to generate the API traffic. Right now we need a Postman tool and the Burp Suite for performing API tests. It would be a huge benefit to be able to do it in a single UI."
- "There could be an improvement in the API security testing."
What is our primary use case?
The solution is for web security testing and the primary use is to eliminate the false positives.
How has it helped my organization?
This solution has helped our company in many ways. PortSwigger Acadamy has given us the knowledge to be able to do deeper tests. The effectiveness of the tests is directly proportional to your knowledge about security testing. Even if you do not have this knowledge at the beginning you still you can perform some kind of testing. If you do not know how to choose your payload then it is going to suggest the built-in payloads to which you can perform those test attacks.
You do not need to be an expert to use the solution, an intermediate skilled person can use it and over time they can become an expert. Sometimes it is difficult to find skilled employees to start working in this field for your company but with PortSwigger the new employee does not have to be an expert because they are able to grow quite quickly in their knowledge.
What is most valuable?
The automated scan is what I find most useful because a lot of customers will need it. Not every domain will be looking for complete security, they just need a stamp on the security key. For these kinds of customers, the scan works really well.
What needs improvement?
There could be an improvement in the API security testing. There is another tool called Postman and if we had a built-in portal similar to Postman which captures the API, we would be able to generate the API traffic. Right now we need a Postman tool and the Burp Suite for performing API tests. It would be a huge benefit to be able to do it in a single UI.
In a future release, if there could be some kind of autonomous function, or user behavior prediction that would be beneficial.
For how long have I used the solution?
I have been using this solution for approximately three years.
What do I think about the stability of the solution?
The solution has not had any crashes or any problems. It is reliable.
What do I think about the scalability of the solution?
The solution is scalable. There are types of operations we can do and it has good peak performance.
How are customer service and technical support?
PortSwigger has something called Academy where you can go to learn about many things related to security testing.
How was the initial setup?
The installation is very easy.
What's my experience with pricing, setup cost, and licensing?
The solution used to be expensive. However, they have reduced the price to approximately $400.00 which is reasonable.
Which other solutions did I evaluate?
I have evaluated Zap.
What other advice do I have?
My advice to others just starting out with security testing is to evaluate Zap, which is open-source, to allow them to get an understanding of the processes. Then once they have an understanding they should look into PortSwigger Burp Suite Professional. This solution would win in comparison with its features and would be a very good choice after they have some experience.
I rate PortSwigger Burp Suite Professional an eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
PortSwigger Burp Suite Professional
March 2026
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,976 professionals have used our research since 2012.
Manager at a consultancy with 10,001+ employees
A stable and user-friendly solution that can be used for manual penetration testing
Pros and Cons
- "PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up."
- "The technical support team's response time is mostly delayed and should be improved."
What is our primary use case?
We use PortSwigger Burp Suite Professional for manual penetration testing.
What is most valuable?
PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up.
What needs improvement?
The technical support team's response time is mostly delayed and should be improved.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Professional for six to seven years.
What do I think about the stability of the solution?
PortSwigger Burp Suite Professional is a stable solution.
What do I think about the scalability of the solution?
Around 500 to 600 users are using the solution in our organization.
How was the initial setup?
The solution’s initial setup is quite easy.
What was our ROI?
PortSwigger Burp Suite Professional is worth its price.
What's my experience with pricing, setup cost, and licensing?
PortSwigger Burp Suite Professional is an expensive solution.
What other advice do I have?
Users should get the professional version for the solution because the community and the free edition do not have many things to offer. They should explore as much as possible, go for the web code application, and do the manual penetration testing.
PortSwigger Burp Suite Professional allows us to do everything from setting the proxy to getting our own browser. Some features were not there in Burp Suite earlier. We had to attach Chrome to the Burp Suite to the proxy, but now they have given everything in a single bundle.
Overall, I rate PortSwigger Burp Suite Professional ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Engineer at RadiSys
Helps to scan APIs, set the response, and request errors
Pros and Cons
- "PortSwigger Burp Suite Professional has an intercept tab that helps us to scan our APIs, set the response, and request errors."
- "Scanning APIs using PortSwigger Burp Suite Professional takes a lot of time."
What is most valuable?
PortSwigger Burp Suite Professional has an intercept tab that helps us to scan our APIs, set the response, and request errors.
What needs improvement?
Scanning APIs using PortSwigger Burp Suite Professional takes a lot of time.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Professional for the last six months.
What do I think about the stability of the solution?
PortSwigger Burp Suite Professional is a stable solution.
What other advice do I have?
PortSwigger Burp Suite Professional is a very good product. My experience with the solution has been very good.
Overall, I rate PortSwigger Burp Suite Professional an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a consultancy with 10,001+ employees
Offers multiple features including automation of tasks but is somewhat lacking in stability
Pros and Cons
- "Enables automation of different tasks such as authorization testing."
- "Return on investment is good because it's a globally known product."
- "The solution lacks sufficient stability."
- "In general, there's not much to complain about but the stability of the tool is not good enough."
What is our primary use case?
We use PortSwigger to find simple bugs via authorization and authentication testing. It's about preventing attacks. Burp Suite enables you to drill down and check all test cases, irrespective of the application on which it's built. We are customers of PortSwigger and I'm a consultant.
What is most valuable?
Port Swigger enables automation of different tasks such as authorization testing. New extensions come in every day which can be used in Burp Suite while testing.
What needs improvement?
In general, there's not much to complain about but the stability of the tool is not good enough. I know that the RAM utilization is something they're working on but using a scan currently takes up too much memory. Resource utilization is an issue because when you're application testing, there are multiple threats and multiple application requests that are going in the backend.
For how long have I used the solution?
I've been using this solution for four years.
What do I think about the stability of the solution?
The stability could be improved.
What do I think about the scalability of the solution?
The scalability is quite good because PortSwigger can be used by multiple users through Jenkins and other things.
How are customer service and support?
The technical support is quite good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is not that difficult because there's good documentation on the PortSwigger website. Our employees each installed on their own machine, it's an executable file.
What was our ROI?
Return on investment is good because it's a globally known product. All our customers know Burp Suite. There's a return on investment because it's a major tool necessary for performing any manual or automation testing.
What's my experience with pricing, setup cost, and licensing?
The licensing cost depends on the number of users. One person can use the tool on a single laptop that can be shared between multiple users under a single license. We have around 15 users. We pay an annual license fee that includes technical support, it's not that expensive. They also provide a free community version.
What other advice do I have?
I recommend this solution and rate it seven out of 10 because it offers multiple features.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a university with 10,001+ employees
Simple to use, informative centralized dashboard, and responsive support
Pros and Cons
- "The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it."
- "The most valuable feature of PortSwigger Burp Suite Professional is the dashboard, which is very informative and lets you receive all the information you need in one place, as it is clear, well-defined, and organized so that anybody without any cybersecurity experience can use it."
- "PortSwigger Burp Suite Professional could improve the static code review."
- "PortSwigger Burp Suite Professional could improve the static code review."
What is our primary use case?
PortSwigger Burp Suite Professional can be used on the cloud or on-premise.
What is most valuable?
The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it.
What needs improvement?
PortSwigger Burp Suite Professional could improve the static code review.
In an upcoming release, PortSwigger Burp Suite Professional can give some possible remedies for any issues it has discovered after a scan of an application. At this time it provides vulnerabilities, having the possible remedies would be a benefit. It would be useful for the developers, to fix the issue immediately.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Professional for approximately five years.
What do I think about the stability of the solution?
The stability of PortSwigger Burp Suite Professional is good.
What do I think about the scalability of the solution?
The scalability of PortSwigger Burp Suite Professional is good, it can integrate with other platforms.
In my previous company, I worked for we had 50 people using this solution and in my current company we have approximately 500 people using it.
How are customer service and support?
We can easily reach out to PortSwigger Burp Suite Professional support by phone, email, chat option, and a ticketing option, which is very good.
I rate the support from PortSwigger Burp Suite Professional a five out of five.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup of PortSwigger Burp Suite Professional is very simple.
Which other solutions did I evaluate?
Before choosing PortSwigger Burp Suite Professional I compared other tools, such as IBM AppScan. I found that PortSwigger Burp Suite Professional was more into web application security. The solution is very helpful, easy to use, and install. They have a free version and anybody can start within minutes.
What solution is best depends on the client size and their requirements. If the client has a large enough budget, or if they're looking for an overall feature, I would recommend PortSwigger Burp Suite Professional as the primary go-to tool. However, if they're having any specific requirements, then they will have to think about using IBM AppScan.
What other advice do I have?
I would recommend the solution to technical professionals and non-technical persons. It is easy to use.
I rate PortSwigger Burp Suite Professional a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
President & Owner at Aydayev's Investment Business Group
Plenty of plugins, effective deep package analyzing, and reliable
Pros and Cons
- "I have found this solution has more plugins than other competitors which is a benefit. You are able to attach different plugins to the security scan to add features. For example, you can check to see if there are any payment systems that exist on a server, or username and password brute force analysis."
- "I have found this solution has more plugins than other competitors which is a benefit."
- "There needs to be better documentation provided. Currently, we need to buy books, or we need to review online some use cases from other professionals who have been using the solution to find out their experience. It is not easy to find out how to properly do a security assessment."
- "There needs to be better documentation provided."
What is our primary use case?
I was working in internet banking in the Middle East and we used Zap for light testing and we used Burp Suite for more deep protocol and package review of the security.
What is most valuable?
I have found this solution has more plugins than other competitors which is a benefit. You are able to attach different plugins to the security scan to add features. For example, you can check to see if there are any payment systems that exist on a server, or username and password brute force analysis. You are able to do many different types of scans, such as SQL injection. There are a lot of deep packages analyzing functions that make this solution have more usability.
What needs improvement?
There needs to be better documentation provided. Currently, we need to buy books, or we need to review online some use cases from other professionals who have been using the solution to find out their experience. It is not easy to find out how to properly do a security assessment. The user interface is pretty basic and if you want to do more advanced operations you need to know more technical details, which are not publicly available. You need to get in touch with different engineers or somebody that publishes their experience in a book to be able to get the knowledge in how to use this solution to its fullest.
For how long have I used the solution?
I have been using this solution for approximately four years.
What do I think about the stability of the solution?
This is a stable solution when comparing it to competitors.
Which solution did I use previously and why did I switch?
I have used Zap and it is lightweight compare to this solution's functions.
How was the initial setup?
The setup is a bit complex.
What's my experience with pricing, setup cost, and licensing?
This solution requires a license. It is expensive but you receive a lot of functionality for the price.
What other advice do I have?
My advice to others is if you have one small web server and static pages, you can easily use Zap. However, if it is a more complex environment, with a payment system, with a lot of content, and has many defined user rules, it is better to use Burp Suite.
I rate PortSwigger Burp Suite Professional a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Cyber Security engineer at a manufacturing company with 10,001+ employees
Is fast, stable, and budget-friendly, but the dashboard needs improvement
Pros and Cons
- "PortSwigger Burp Suite does not hamper the node of the server, and it does not shut down the server if it is running."
- "This solution provides a very good mechanism for fixing interval time; for example, we can create a schedule, and the schedule runs on time, PortSwigger Burp Suite does not hamper the node of the server and does not shut down the server if it is running, it is quite fast and easy to install as well, and it is also a budget-friendly tool."
- "The reporting needs to be improved; it is very bad."
- "The reporting needs to be improved; it is very bad."
What is our primary use case?
We use PortSwigger Burp Suite Professional for security testing and for doing vulnerability scanning mechanisms.
How has it helped my organization?
It has partially improved the organization requirement however, The scanning mechanism is pretty slow and takes long duration to scan. Moreover, The server hangs up while scanning.
What is most valuable?
This solution provides a very good mechanism for fixing interval time. For example, we can create a schedule, and the schedule runs on time. PortSwigger Burp Suite does not hamper the node of the server, and it does not shut down the server if it is running.
It is quite fast and easy to install as well.
It is also a budget-friendly tool.
What needs improvement?
The reporting needs to be improved; it is very bad.
The dashboard feature or the front-end of the tool does not look good and is not very creative or user-friendly. It looks complicated when we log in to the tool. It looks boring and outdated.
For how long have I used the solution?
I've been using this solution within the last 12 months.
What do I think about the stability of the solution?
Stability-wise, improvements have been made, and it is reliable.
How are customer service and technical support?
Technical support is not so easy to get a hold of. We had to learn most of the things through the documentation. However, the documentation is not readily available online. We have to create new calls for it, and we have to email them. So, if you have a problem, then it can take some time to resolve it.
Which solution did I use previously and why did I switch?
No dint use.
How was the initial setup?
The initial setup was straightforward and took about one to two weeks.
What's my experience with pricing, setup cost, and licensing?
It's a budget-based tool, and it's a pretty decent budget tool for the mid-version of the application. It's a lower priced tool that we can rely on with good standard mechanisms. We have a yearly license.
Which other solutions did I evaluate?
Client provided product
What other advice do I have?
If you're looking for a budget-friendly tool, I would recommend PortSwigger Burp Suite Professional.
On a scale from one to ten, I would rate this tool at seven.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Fuzz Testing ToolsPopular Comparisons
Checkmarx One
CrowdStrike Falcon Cloud Security
Coverity Static
GitHub Advanced Security
OpenText Core Application Security
Sonatype Lifecycle
GitGuardian Platform
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is OWASP Zap better than PortSwigger Burp Suite Pro?
- What is the biggest difference between OWASP Zap and PortSwigger Burp?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?
- We're evaluating Tripwire, what else should we consider?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?




















