Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Rapid7 AppSpider comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
CDN (1st), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Cloud Security Posture Management (CSPM) (13th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.6
Number of Reviews
59
Ranking in other categories
Web Application Firewall (WAF) (2nd)
Rapid7 AppSpider
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
14
Ranking in other categories
Static Application Security Testing (SAST) (32nd)
 

Mindshare comparison

Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF7.7%
F5 Advanced WAF9.2%
Microsoft Azure Application Gateway7.8%
Other75.3%
Web Application Firewall (WAF)
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
Rapid7 AppSpider0.5%
SonarQube Server (formerly SonarQube)20.3%
Checkmarx One9.9%
Other69.3%
Static Application Security Testing (SAST)
 

Featured Reviews

Carlos Alam Hernandez Baruch - PeerSpot reviewer
Fast and secure deployments simplify operations for government and fintech clients
It is a fast and secure DNS. It is very easy to deploy, and my customers are happy with this tool. Additionally, the CDN performance in Mexico is excellent, providing fast service and tools. It offers reliability during high-traffic periods, ensuring no impact on the environment. It helps my clients avoid using on-premise boxes, simplifying operations as they only use the prices on Cloudflare.
Abdalla Kenawy - PeerSpot reviewer
Provides great insights about requests, helping secure our infrastructure
I am working on AWS Web Services to manage infrastructure as a platform. I use services like KMS, EBS, CloudFront, S3, and EC2. I also work on WAF version two AWS WAF has provided great insights about requests, helping secure our infrastructure. It contributes by continuing to get the latest…
Rizwan-Alam - PeerSpot reviewer
Easy automated web app scanning, but gives many false positives and isn't always stable
One of the challenges I have with AppSpider is that it gives you a lot of false positives, especially when compared to other solutions. This is the main aspect that I hope to see Rapid7 improve on. Beyond reducing false positives, I would also like to see them implement better reporting features, particularly in the executive summary type of reports which need to be user-friendly and easily understood by non-technical people. The recommendations and solutions on these reports could always be improved to make them more relevant, too. Lastly, the stability isn't that great, and sometimes it becomes non-responsive. I feel like the stability of the application is very average and currently needs more work.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its most significant benefit to date is the speed with which it refreshes DNS records on the internet once you change it. If you are changing a website or registering a new record, it is very quick."
"DDoS attacks target unprotected machines. Cloudflare detects and stops these attacks using internal systems. It identifies incoming DDoS attacks, issuing challenges or blocking them immediately."
"The most valuable feature is the web application firewall."
"The DDoS protection is the most valuable aspect of the solution."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"Cloudflare is a security SaaS provider that provides security and protects us from any application layer attack."
"The solution automatically detects and responds to certain types of traffic based on geolocation."
"The solution offers the flexibility to control configuration rules."
"Its best feature is that it is on the cloud and does not require local hardware resources."
"One of the most valuable features of AWS WAF is its ability to filter web app traffic, allowing us to specify conditions such as IP addresses and HTTP headers."
"Some valuable features of AWS WAF include its seamless integration and ease of orchestration within the AWS platform."
"AWS WAF is very easy to use and configure on AWS."
"It's simple, easy to use."
"The most valuable feature of AWS WAF is its highly configurable rules system."
"Stable and scalable web application firewall. Setting it up is straightforward."
"We preferred the product based on its cost. AWS WAF is an out-of-the-box solution and integrates with the AWS services that we use. It's natively integrated with AWS."
"The solution is highly stable, rated at ten out of ten."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information. You don't need specialized skills to use the product."
"Rapid7 AppSpider is good at managing different applications. It uses applets and generates reports to cover the PCA/GDPR compliance requirements."
"AppSpider's most valuable feature is reporting - everything is stored in the local database so it can be sent to other machines."
"I like the ability the product has to detect vulnerabilities quickly, when it has been released in our environment, then displaying them to us."
"The most valuable feature of Rapid7 AppSpider is the vulnerability reporting data. Additionally, the data is reported in a convenient way rather than seeing them as a PDF. We are able to generate all the reports exactly what we want in a flexible way."
"The setup is usually straightforward."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
 

Cons

"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"It should be easier to collect the logs with companies like Sumo. However, based on my discussions with the salespeople, I understand that's how they make their money. With the enterprise product, they want people doing those kinds of enterprise features to do the logging. They want them to pay a lot of money, and that's where I have an issue with them. That should be a default. You should be able to get the log no matter what. The logging should be universal."
"Eventually, things go sideways and require fixes when it would have been easier to prevent the issue initially."
"I believe they currently have this feature, but there will most likely be integration with APIs so we can control some features through API."
"We're facing challenges due to an upgrade in the machine learning model. The problem arises from some users abusing the APIs, resulting in an influx of suspicious traffic. Cloudflare's learning model mistakenly identifies this traffic as human. Consequently, it assigns it a higher trust score, akin to legitimate human traffic, causing complications in our architecture. Previously, such traffic would have been categorized as suspicious, enabling us to apply appropriate blocking rules. However, we encounter difficulties distinguishing between genuine and suspicious traffic with the new categorization. Despite these challenges, overall, Cloudflare remains the preferred solution compared to Azure, AWS CloudFront, and Google Cloud Armor."
"The dashboarding could be improved, and the default metrics provided by AWS WAF could be upgraded."
"Compatibility and integration functionalities, especially with services like Kafka for event-driven messaging, could be better."
"It would be good if the solution provided managed WAF services."
"It's a bit difficult to apply the right rules for the right security."
"We don't have much control over blocking, because the WAF is managed by AWS."
"We must monitor and clean up the WAF manually."
"The area of reporting in the product needs to have a proper format."
"The technical support does not respond to bugs in the coding of the product."
"The product needs to be able to scale for large companies, like ours. We have millions of IP addresses that need to be scanned, and the scalability is not great."
"This price of this solution is a little bit expensive."
"AppSpider could improve in the area of integration. They need to add more integration opportunities."
"Support response times are slow and can be improved."
"It needs better integration with mobile applications."
"The performance of the solution could improve. When I compare the speed it is slower than others on the market. There are some tricks we use to help speed up the solution."
"The dashboard and interface are crucial and they need some improvement."
"The product should offer a GUI in Japanese and provide Japanese reports for end-users."
 

Pricing and Cost Advice

"I give the price a five out of ten."
"So far I use free tier and happy with it. You can subscribe to business package if needed."
"We are using the free version."
"We don't have any issues with the price."
"A free version of the solution is available."
"The solution has many features but there are ones that you need to pay for. Sometimes you have to find out which is available for free and which you have to pay for."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"There are no additional costs beyond the standard licensing fees."
"It's cheap."
"The solution's cost depends on the use cases."
"It has a variable pricing scheme."
"The pricing is good and manageable."
"The product is moderately priced."
"The price is average."
"There are no costs in addition to the standard licensing fees."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a seven or eight out of ten."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
"The licensing cost depends on the number of users."
"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"The price is pretty fair."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
867,676 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Comms Service Provider
11%
Financial Services Firm
10%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
9%
Government
6%
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
8%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise11
Large Enterprise25
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price is not high, but for Japanese customers, localization may incur additional costs.
What needs improvement with Rapid7 AppSpider?
For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese repor...
What is your primary use case for Rapid7 AppSpider?
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who r...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
AppSpider
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Microsoft
Find out what your peers are saying about F5, Amazon Web Services (AWS), Microsoft and others in Web Application Firewall (WAF). Updated: August 2025.
867,676 professionals have used our research since 2012.