Your web applications may be complex, but your application security testing tool doesn’t need to be. InsightAppSec brings Rapid7’s proven Dynamic Application Security Testing (DAST) technology to the Insight platform, combining powerful application crawling and attack capabilities, flexibility in scan scope and scheduling, and accuracy in results with a modern UI, intuitive workflows, and sensible data organization. This enables you to identify XSS, SQL injection, CSRF, and other vulnerabilities with unparalleled ease. The best part? All of these capabilities are delivered via the cloud so that you’re up and running in minutes to identify the critical security risks that exist in your applications.


| Product | Market Share (%) |
|---|---|
| Rapid7 InsightAppSec | 6.2% |
| Veracode | 18.2% |
| Checkmarx One | 17.0% |
| Other | 58.6% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Dynamic Application Security Testing (DAST) | Feb 8, 2026 | Download |
| Product | Reviews, tips, and advice from real users | Feb 8, 2026 | Download |
| Comparison | Rapid7 InsightAppSec vs Veracode | Feb 8, 2026 | Download |
| Comparison | Rapid7 InsightAppSec vs Checkmarx One | Feb 8, 2026 | Download |
| Comparison | Rapid7 InsightAppSec vs OpenText Dynamic Application Security Testing | Feb 8, 2026 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| Checkmarx One | 3.9 | 17.0% | 88% | 81 interviewsAdd to research |
| Veracode | 4.0 | 18.2% | 89% | 208 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 2 |
| Large Enterprise | 5 |
| Company Size | Count |
|---|---|
| Small Business | 84 |
| Midsize Enterprise | 61 |
| Large Enterprise | 168 |
Rapid7 InsightAppSec was previously known as InsightAppSec.
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
| Author info | Rating | Review Summary |
|---|---|---|
| Vulnerability Management Lead at garrett | 3.5 | We use Rapid7 InsightAppSec for internal and external application security assessments. It offers strong scan coverage and reporting. However, it needs better integration, fewer false positives, and enhanced AI capabilities. Its interface and scalability require improvement. We deploy via AWS. |
| Head Of Cyber Security at Super Secure | 3.5 | I've worked with Rapid7 InsightAppSec for over three years and found it reliable, especially for financial institutions. Customers appreciate flexible scan scheduling, though customizable reporting could improve. Support is decent, pricing is fair, and renewals suggest satisfaction. |
| Manager at a financial services firm with 5,001-10,000 employees | 3.0 | I used Rapid7 InsightAppSec alongside Insight VM for managing on-premises needs but found InsightAppSec better in web-based systems. Though it offers some good features, improvements are needed in customer support, integration, and pricing. I previously used different on-premises solutions. |
| Works | 4.0 | We use Rapid7 InsightAppSec primarily to scan for vulnerabilities in APIs and UIs, finding the remediation feature most valuable. However, report generation could be improved by allowing additional columns and CSV exports, as PDFs are cumbersome. |
| Head of Infrastructure at Pearl Data Direct | 4.0 | We use Rapid7 InsightAppSec mainly for securing our Java-based applications through monthly penetration tests. It excels in realistic threat simulation but needs improvements in customizable reporting and user interface. We also use Qualys WAS for vulnerability management. |
| Technical Manager at a computer software company with 11-50 employees | 4.0 | No summary available |
| IT Security Engineer at a financial services firm with 51-200 employees | 4.0 | I use InsightAppSec to help customers with environment scans, automating authorization effectively. However, it lacks virtual patching found in AppSpyder, which delays remediation. Competitors like Acunetix and Qualys have similar offerings. Deployment utilizes other cloud providers. |
| Cyber Security Trainer and Programmer at Freelancer | 4.0 | I use Rapid7 InsightAppSec to identify code vulnerabilities on dynamic and e-commerce websites. It features easy setup and configuration, includes integration through a CDM, and offers valuable insights and demo sessions. However, it could improve in detecting phishing pages. |