No more typing reviews! Try our Samantha, our new voice AI agent.

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Rapid7 InsightAppSec offers predefined templates for various attack types, enabling easy execution and reporting.
The stable and reliable performance, rated five out of five, offers a crash-free and bug-free experience.
The Attack Replay feature allows users to reproduce and analyze attack sequences, benefiting developers.
Dynamic application security scanning supports both predefined and customizable templates, accommodating external and internal applications without needing server deployments.
InsightAppSec enhances both regulatory compliance and security posture, efficiently aiding in penetration testing and generating insightful reports.

CONS

InsightAppSec could expand its testing techniques and include more templates, following frameworks like MITRE ATT&CK.
Adding SaaS and mobile application scanning, including firmware recommendations, would enhance InsightAppSec.
The feature for managing scan configurations needs improvement, as currently, new configurations may overwrite existing ones.
Reduced false positives in identifying complex attacks would significantly enhance InsightAppSec's effectiveness.
InsightAppSec should improve its reporting feature by enabling extra columns and providing CSV format for remediation reports.
 

Rapid7 InsightAppSec Pros review quotes

Brandi Lea - PeerSpot reviewer
Regional Information Security Analyst, Lead at a healthcare company with 10,001+ employees
Aug 24, 2026
Rapid7 MDR has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits.
Shritam Bhowmick - PeerSpot reviewer
Vulnerability Management Lead at garrett
Jun 13, 2025
The reporting functionality is excellent.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Feb 3, 2026
Customers use the product for scanning purposes and do not want to be restricted with respect to the number of scans they perform.
Learn what your peers think about Rapid7 InsightAppSec. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,806 professionals have used our research since 2012.
reviewer2284569 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Feb 24, 2025
Relatively speaking, InsightAppSec is good compared to Insight VM.
Mar 20, 2025
I would rate the technical support from Rapid7 a ten, indicating high-quality support.
MK
Head of Infrastructure at Pearl Data Direct
Feb 25, 2025
When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports.
SonNguyen3 - PeerSpot reviewer
Technical Manager at a computer software company with 11-50 employees
Apr 10, 2025
Rapid7 InsightAppSec is a good product for dynamic application security testing, providing neat reports that include validation actions and helping to generate web application firewall rules for web applications.
Krzysztof Witko - PeerSpot reviewer
IT Security Engineer at a financial services firm with 51-200 employees
Jan 28, 2025
The automatic automation of the automated authorization to the SCANNET environment is valuable.
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Mar 4, 2024
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to paste the provided CDN into your metadata. Once connected, every piece of information, including vulnerabilities, can be accessed. It also offers demo sessions.
Aakash Shankar - PeerSpot reviewer
Senior Cybersecurity Solutions Engineer at Trillium Information Security Systems
Jun 7, 2024
Dynamic application security scanning provides predefined templates and supports customization. The ability to scan external and internal applications, including on-premises ones, is precious. Additionally, it is a cloud platform, so we don't need to deploy servers or resources. This makes it time-efficient and cost-effective.
 

Rapid7 InsightAppSec Cons review quotes

Brandi Lea - PeerSpot reviewer
Regional Information Security Analyst, Lead at a healthcare company with 10,001+ employees
Aug 24, 2026
While Rapid7 MDR is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode.
Shritam Bhowmick - PeerSpot reviewer
Vulnerability Management Lead at garrett
Jun 13, 2025
In terms of behavioral and pattern recognition, identifying complex attacks such as SQL, blind SQL, JSON, and LDAP injections often results in 94% false positives.
SohailHyder - PeerSpot reviewer
Head Of Cyber Security at Super Secure
Feb 3, 2026
Customers sometimes experience issues with performance.
Learn what your peers think about Rapid7 InsightAppSec. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
913,806 professionals have used our research since 2012.
reviewer2284569 - PeerSpot reviewer
Manager at a financial services firm with 5,001-10,000 employees
Feb 24, 2025
There is room for improvement in the response time of customer service and support levels.
Mar 20, 2025
There is room for improvement in Rapid7 InsightAppSec by giving clients the ability for extra columns on reports and enabling the extraction of remediation reports into a CSV format. Currently, the PDF format is cumbersome to go through when dealing with thousands of pages.
MK
Head of Infrastructure at Pearl Data Direct
Feb 25, 2025
The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports.
SonNguyen3 - PeerSpot reviewer
Technical Manager at a computer software company with 11-50 employees
Apr 10, 2025
The technical support from Rapid7 is not bad, but the response time can be quite slow sometimes.
Krzysztof Witko - PeerSpot reviewer
IT Security Engineer at a financial services firm with 51-200 employees
Jan 28, 2025
Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version.
Vikas Dusa - PeerSpot reviewer
Cyber Security Trainer and Programmer at Freelancer
Mar 4, 2024
Rapid7 InsightAppSec needs improvement in detecting phishing pages.
Aakash Shankar - PeerSpot reviewer
Senior Cybersecurity Solutions Engineer at Trillium Information Security Systems
Jun 7, 2024
The dynamic scanning feature has simplified and improved the security testing process. I suggest adding a SaaS feature to the solution to support scanning SaaS applications, making it more comprehensive. It would be beneficial if the solution could also scan mobile applications. It only scans web applications and should also cover mobile applications, including firmware recommendations.