Try our new research platform with insights from 80,000+ expert users
Quality Analyst at a tech consulting company with 51-200 employees
Real User
Mar 31, 2023
Easy to use with a good interface and high accuracy
Pros and Cons
  • "It offers very good accuracy. You can trust the results."
  • "The solution is not easy to set it up. You need a lot of knowledge."

What is our primary use case?

I'm primarily using it for testing of the company's website.

What is most valuable?

The interface is good.

It is easy to use.

I am certified with the product and have a good understanding of it.

The usability is very good.

It offers very good accuracy. You can trust the results. 

It's good software that is great for a beginner to use.

It can scale. 

The product is stable and reliable. 

What needs improvement?

It works for me. I don't see any missing features. 

The solution is not easy to set it up. You need a lot of knowledge. I'd like to see more documentation. They need to provide more videos and more information about the solution. The website isn't as helpful as it could be. They need to provide more information and maybe provide courses to help people get the most out of it. 

For smaller organizations, the solution is expensive. 

For how long have I used the solution?

I've been using the solution for two years. 

Buyer's Guide
PortSwigger Burp Suite Professional
January 2026
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.

What do I think about the stability of the solution?

I'd rate the stability eight out of ten. It is pretty stable. There are no bugs or glitches, and it doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution is very scalable. I'd rate the ability to extend ten out of ten.

Three people are using the solution.

How are customer service and support?

I do not have any experience with technical support. I had a colleague who would deal with support.

Which solution did I use previously and why did I switch?

I used to use OWASP Zap. It is a free solution. I moved to Burp as the accuracy rate was higher. We wanted something that provided correct information about errors. 

How was the initial setup?

The initial setup was a bit difficult. For a beginner, it's tough to set up. I'd rate the solution three out of ten in terms of ease of setup. There isn't proper documentation to help you through the process. 

I cannot recall how long the deployment took. I watched a lot of videos and just went ahead with eh setup myself. 

The product doesn't require any maintenance. 

What about the implementation team?

I handled the initial setup myself. I did not have any outside assistance. 

What was our ROI?

I have witnessed an ROI. It is worth the money.

What's my experience with pricing, setup cost, and licensing?

It is a bit expensive for smaller companies. If you're using it in a small company or for your own purposes, it's costly. I'd rate the cost three out of ten in terms of affordability.

I'm not sure of the exact cost of the solution as I don't directly deal with licensing. 

What other advice do I have?

I'm a customer. I'm using the professional version. It is the latest version. They always update it and provide me with the latest upgrades. 

I'd recommend the solution to others. It's very accurate and easy to use. 

I would rate the solution. Ten out of ten. 

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1966164 - PeerSpot reviewer
Cyber Security Specialist at a university with 10,001+ employees
Real User
Sep 21, 2022
Simple to use, informative centralized dashboard, and responsive support
Pros and Cons
  • "The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it."
  • "PortSwigger Burp Suite Professional could improve the static code review."

What is our primary use case?

PortSwigger Burp Suite Professional can be used on the cloud or on-premise.

What is most valuable?

The most valuable feature of PortSwigger Burp Suite Professional is the dashboard. It is very informative and you can receive all the information you need in one place. It's clear, well-defined, and organized. Anybody without any cybersecurity can use it.

What needs improvement?

PortSwigger Burp Suite Professional could improve the static code review.

In an upcoming release, PortSwigger Burp Suite Professional can give some possible remedies for any issues it has discovered after a scan of an application. At this time it provides vulnerabilities, having the possible remedies would be a benefit. It would be useful for the developers, to fix the issue immediately.

For how long have I used the solution?

I have been using PortSwigger Burp Suite Professional for approximately five years.

What do I think about the stability of the solution?

The stability of PortSwigger Burp Suite Professional is good.

What do I think about the scalability of the solution?

The scalability of PortSwigger Burp Suite Professional is good, it can integrate with other platforms.

In my previous company, I worked for we had 50 people using this solution and in my current company we have approximately 500 people using it.

How are customer service and support?

We can easily reach out to PortSwigger Burp Suite Professional support by phone, email, chat option, and a ticketing option, which is very good.

I rate the support from PortSwigger Burp Suite Professional a five out of five.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup of PortSwigger Burp Suite Professional is very simple.

Which other solutions did I evaluate?

Before choosing PortSwigger Burp Suite Professional I compared other tools, such as IBM AppScan. I found that PortSwigger Burp Suite Professional was more into web application security. The solution is very helpful, easy to use, and install.  They have a free version and anybody can start within minutes.

What solution is best depends on the client size and their requirements. If the client has a large enough budget, or if they're looking for an overall feature, I would recommend PortSwigger Burp Suite Professional as the primary go-to tool. However, if they're having any specific requirements, then they will have to think about using IBM AppScan.

What other advice do I have?

I would recommend the solution to technical professionals and non-technical persons. It is easy to use.

I rate PortSwigger Burp Suite Professional a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
PortSwigger Burp Suite Professional
January 2026
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1871559 - PeerSpot reviewer
Application Security Enginee at a tech vendor with 1,001-5,000 employees
Real User
Top 10
Jun 12, 2022
Excellent Intruder, Repeater, and Proxy features
Pros and Cons
  • "The initial setup is simple."
  • "We'd like to have more integration potential across all versions of the product."

What is our primary use case?

Mainly, the solution is a proxy. It also contains different tools, including intruder tools for customized automated attacks and tools for repeating requests, or decoding, et cetera. Many tools are there that can perform different tasks for different use cases. Apart from that, we have the BApp Store which contains a lot of tools as well. This Burb Suite is an application where we have all the tools. 

It is mainly used for pen testing.

How has it helped my organization?

Features such as the Intruder, Repeater, and Proxy have helped our organization a lot.

What is most valuable?

The Intruder, Repeater, and Proxy features have been great.

The initial setup is simple.

It is an easily scalable product.

The solution is very stable. 

What needs improvement?

In some cases, we got a few file postings while doing it by the automatic scan. If that could be better, that would be ideal. The scanner could just be updated a bit more. 

We'd like to have more integration potential across all versions of the product. The enterprise version seems to have better integration services than others. 

For how long have I used the solution?

I've been working with the solution for six years. 

What do I think about the stability of the solution?

The solution is quite stable. There are no bugs or glitches and it doesn't crash or freeze. It is reliable. 

What do I think about the scalability of the solution?

The solution scales well. It's not an issue.

How are customer service and support?

I have also had some queries and I have used their support services. It was like all solutions out there. They are quite good in general.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have used many other tools. This is one of the best tools that I'm using. I found this one much better. 

How was the initial setup?

We have found the initial setup to be very simple and straightforward. It's not overly complex or difficult. 

For any configuration for deployment in our project, we assign two people. We have a small team of two aligned with our project. They will handle everything related to implementation. The setup doesn't take longer than one day.

In terms of maintenance, for the customers, what we are doing is we have an internal cyber security team, in which there are people doing the pen test. There are people who are doing the vulnerability assessment for the WASP scan, SaaS. For each, we have a separate team, and based on that, most of the deployments are done by these pen testers only. We do not provide maintenance for customers, however, we do provide reporting and technical support.

What about the implementation team?

Before Burb Suite, we had our own technical team there for everything, including deployment. We have a separate network team and they will manage everything - including installation. It is very simple. You can download that directly. It's all very easy to do in-house.

What's my experience with pricing, setup cost, and licensing?

I don't deal with any aspect of the licensing at this time. I can't speak to the exact pricing. 

What other advice do I have?

I'm just a customer and an end-user.

We're using the latest version of the solution. We usually give an auto-update functionality. All the updates came automatically. We are updating it automatically.

We actually have an .EXE file in our system. We have the professional version. We've downloaded and given out the access key. It's on-premises, not the cloud. 

Overall, I've been very happy with the solution. I'd rate it nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1654029 - PeerSpot reviewer
Chief Info Sec Engineer at a tech services company with 11-50 employees
Real User
Aug 30, 2021
An easy to install solution for vulnerability assessment
Pros and Cons
  • "We use the solution for vulnerability assessment in respect of the application and the sites."
  • "We wish that the Spider feature would appear in the same shape that it does in previous versions."

What is our primary use case?

We are using the latest version and are in the process of upgrading it. 

What is most valuable?

We use the solution for vulnerability assessment in respect of the application and the sites. We use the intruder part, which is essentially the Proxy part, to check whether any brute-force attacks can be undertaken. 

What needs improvement?

We wish that the Spider feature would appear in the same shape that it does in previous versions. 

I believe we have developmental tools such Accuratix. It would be nice if the report that was accepted upon scanning would highlight all the weaknesses from the perspective of my application. 

For how long have I used the solution?

We have been using PortSwigger Burp Suite Professional for the last three years.

What do I think about the stability of the solution?

We have had no issues with the stability. 

What do I think about the scalability of the solution?

As we only have a couple of licenses, we have not encountered any issues concerning the scalability. 

How are customer service and technical support?

The technical support is all right. 

This said, we have requested support on a couple of occasions, specifically one concerning training relating to the new features and add-ons coming onto the application, and this is still outstanding. 

How was the initial setup?

The initial setup is not very complex. Rather, it is easy and straightforward. 

What's my experience with pricing, setup cost, and licensing?

For a country such as Sri Lanka, the pricing is not reasonable. 

What other advice do I have?

There are around 10 people using the solution in our organization.

I don't have any advice off the cuff. When it comes to the web crawling features, it does not need to be in the same shape as before, but it would be nice if it allowed us to index associated things in the manner that we did so in the past. 

I rate PortSwigger Burp Suite Professional as a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1552449 - PeerSpot reviewer
Application Security Architect at a logistics company with 10,001+ employees
Real User
Apr 16, 2021
High performance, abundant plugins, and reliable
Pros and Cons
  • "I have found the best features to be the performance and there are a lot of additional plugins available."

    What is our primary use case?

    The solution is the standard in application penetration testing and this is what we use it for.

    What is most valuable?

    I have found the best features to be the performance and there are a lot of additional plugins available.

    For how long have I used the solution?

    I have been using the solution for approximately three years.

    What do I think about the stability of the solution?

    The solution is reliable, it is very stable.

    How was the initial setup?

    The installation is straightforward and simple. It only takes minutes to install.

    What about the implementation team?

    We did the deployment and one individual can do it, it is not complex. We have a team of three engineers and architects doing the deployments and maintenance.

    What's my experience with pricing, setup cost, and licensing?

    The price for the solution is expensive and could be cheaper. We pay an annual license and our team has several of them.

    What other advice do I have?

    I would recommend this solution to others.

    I rate PortSwigger Burp Suite Professional a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1508730 - PeerSpot reviewer
    Founder and Director at a financial services firm with 1-10 employees
    Real User
    Feb 21, 2021
    Great reporting with good crawling capability and offers a simple setup
    Pros and Cons
    • "The solution has a pretty simple setup."
    • "The pricing of the solution is quite high."

    What is our primary use case?

    We primarily use the solution for security testing - specifically for web-application security. 

    What is most valuable?

    The crawling capability is excellent.

    The product has very good reporting capabilities. They give you multiple reporting options.

    The solution has a variety of different extensions that you can use.

    The solution has a pretty simple setup.

    What needs improvement?

    The pricing of the solution is quite high. It would be ideal for the customers if they could lower the costs involved in their subscription.

    We have new tools in R language programming platforms that are coming up. The solution needs to ensure its compatible with that language.

    For how long have I used the solution?

    I've been using the solution for about two years at this point.

    What do I think about the stability of the solution?

    We use this solution every day. I don't have any issues with the solution. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable.

    What do I think about the scalability of the solution?

    I'm a consultant. I tend to use the tool for my clients. I only have one license on my computer. I don't need to scale the product.

    The solution is scalable, however. There's a different version for that aspect. You have Community, Professional, and Enterprise editions. Each has different capabilities.

    How are customer service and technical support?

    The solution offers good support services. There's also the product team that can assist. Overall, I've been happy with the level of service I've received.

    Which solution did I use previously and why did I switch?

    I've worked with other solutions, such as Acutenix. As a consultant, I always have two to three tools for running and validating for testing. There is no plus or minus to each tool, really. The process itself would be more like using multiple tools to find out whether it appears in all the tools or not.

    How was the initial setup?

    The initial setup is not overly complex. It's easy and straightforward. A company shouldn't have any issues with the implementation process.

    The deployment takes a maximum of an hour, actually. If you have to configure some prerequisites, it is one hour tops. There are advanced setups, however, how advanced the implementation depends on the client environment. If a company has an advanced setup, it could take some time. 

    Ultimately, the solution is installed directly onto my laptop.

    The maintenance process is pretty minimal. The yearly subscription keeps everything updated. They will notify you if there is an upgrade that needs to be addressed.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of the solution is quite high. Costs are based on their subscription model. The pricing affects whether a client will engage with me and the solution or not. It could be a deal-breaker. Budgets are often tight.

    What other advice do I have?

    The solution has an annual subscription model, and therefore you'll have to keep updating the new version. It's part of the package. They release a new version and that is covered under your subscription.

    I'm a consultant. I buy tools from multiple vendors. I provide development assessment services for my clients.

    This is one more product in the suite of tools or applications, which are used for testing. Anyone at any sized company could use this solution.

    I'd recommend this solution. It's one more tool to have in your bag.

    I would rate the solution at a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Consultant
    PeerSpot user
    reviewer1293489 - PeerSpot reviewer
    IT Security Analyst at a tech services company with 11-50 employees
    Real User
    Jan 10, 2021
    Stable, easy to set up, and speeds up our vulnerability assessment and penetration testing
    Pros and Cons
    • "I find the attack model quite amazing, where I can write my scripts and load my scripts as well, which helps quite a bit. All the active scanning that it can do is also quite a lot helpful. It speeds up our vulnerability assessment and penetration testing. Right now, I am enjoying its in-browser, which also helps quite a bit. I'm always confused about setting up some proxy, but it really is the big solution we all want."
    • "I am from Brazil. The currency exchange rate from a dollar to a Brazilian Real is quite steep. It is almost six to one. It would be good if it can be sold in the local currency, and its price is cheaper for us."

    What is our primary use case?

    I'm a junior cybersecurity analyst, and I'm helping the seniors to do some testing. Meanwhile, I'm also getting trained with the tool. I mostly use it for vulnerable apps assessment and some auditing. Other analysts use it for penetration testing.

    We are using the latest version. We downloaded it three days ago.

    What is most valuable?

    I find the attack model quite amazing, where I can write my scripts and load my scripts as well, which helps quite a bit. All the active scanning that it can do is also quite a lot helpful. It speeds up our vulnerability assessment and penetration testing. Right now, I am enjoying its in-browser, which also helps quite a bit. I'm always confused about setting up some proxy, but it really is the big solution we all want.

    What needs improvement?

    I am from Brazil. The currency exchange rate from a dollar to a Brazilian Real is quite steep. It is almost six to one. It would be good if it can be sold in the local currency, and its price is cheaper for us. 

    For how long have I used the solution?

    I have been using PortSwigger Burp for six months now.

    What do I think about the stability of the solution?

    I have found no issues so far with its stability. I can't complain anything about it.

    What do I think about the scalability of the solution?

    I can't say much about that because we are going to transition to cloud management. I don't know for sure how it is going to scale up. We are still in the testing and planning stages. We currently have approximately five users, and our team is still growing.

    How are customer service and technical support?

    I haven't yet used their technical support.

    How was the initial setup?

    The initial setup is completely easy. It took a day to deploy.

    What's my experience with pricing, setup cost, and licensing?

    It is expensive for us in Brazil because the currency exchange rate from a dollar to a Brazilian Real is quite steep.

    What other advice do I have?

    It is a really big solution. There are so many modules. You got to have some training to do it properly and go through a lot of documentation.

    I would rate PortSwigger Burp a nine out of ten. I haven't found anything to complain about, but there is always some room for improvement.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1471662 - PeerSpot reviewer
    Lead Software Architect at a tech services company with 201-500 employees
    Real User
    Dec 21, 2020
    Excellent Community version for skills mapping that is easy to setup and is stable
    Pros and Cons
    • "The extension that it provides with the community version for the skills mapping is excellent."
    • "Currently, the scanning is only available in the full version of Burp, and not in the Community version."

    What is our primary use case?

    We use this solution when we develop any of our software applications and host it with the website for external clients. All of the applications go through the vulnerability scanner.

    What is most valuable?

    Burp Suite is very helpful. The extension that it provides with the community version for the skills mapping is excellent.

    What needs improvement?

    The interface for external clients needs improvement.

    Currently, the scanning is only available in the full version of Burp, and not in the Community version.

    I would like the scanning included for free also.

    For how long have I used the solution?

    We have been using this solution for a year and a half.

    What do I think about the stability of the solution?

    It's a stable solution. We have not had any issues.

    How are customer service and technical support?

    I have not contacted technical support. 

    We have not experienced any issues where we couldn't resolve them using our internal team.

    We have not required any technical support.

    Which solution did I use previously and why did I switch?

    When we compare it to other programs that we have such as OWAP Zap, we found Burp to be more suitable.

    How was the initial setup?

    The initial setup is straightforward.

    It is very easy to automate. It requires some configuration that has you follow step by step instructions. 

    It can take four to five hours to go live.

    Anyone with minimal knowledge and training can use this tool.

    What's my experience with pricing, setup cost, and licensing?

    We are using the community version, which is free.

    Which other solutions did I evaluate?

    We evaluated OWASP Zap, which was fully open-source.

    We use the community version and found that Burp was easier and more useful.

    The interface is better in PortSwigger Burp.

    What other advice do I have?

    I would rate PortSwigger Burp an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.
    Updated: January 2026
    Buyer's Guide
    Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.