Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Rapid7 AppSpider comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
77
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (1st), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (13th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (3rd)
Rapid7 AppSpider
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
14
Ranking in other categories
Static Application Security Testing (SAST) (31st)
 

Mindshare comparison

Web Application Firewall (WAF) Market Share Distribution
ProductMarket Share (%)
AWS WAF5.8%
Fortinet FortiWeb8.1%
F5 Advanced WAF7.8%
Other78.3%
Web Application Firewall (WAF)
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
Rapid7 AppSpider0.7%
SonarQube18.8%
Checkmarx One10.4%
Other70.1%
Static Application Security Testing (SAST)
 

Featured Reviews

HA
Owner at Hga consulting
Has helped manage client domains with streamlined access control and threat visibility
I don't know what areas could be improved with Cloudflare WAF; Cloudflare is constantly improving and adding features to their feature set. They're doing a good job, and as far as DNS and support for any domains that I create or my clients create, it's mandatory for me to make sure that they have Cloudflare as their DNS provider. The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service. It doesn't pay to try to host your own website.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
HW
Marketing Expert at J's communication
Clients benefit from broad authentication and effective crawling but need localization improvements
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who require security assessments One of the most valuable features of AppSpider is its broad range of authentication identification, which is a key reason for its utilization.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I get a lot of value from Cloudflare's API because it enables you to build a separate environment inside the solution. You can create a domain for performing test requests before you move to the production environment and connect various domains."
"The overall experience with Cloudflare is positive, with a rating of eight out of ten."
"Its ease of integration with Office 365 and the fact that it's a good product compared to what I had before"
"Many websites require an SSL certificate because they sell stuff and want SSL. Cloudflare comes with an SSL certificate built in. It's automatic. You sign yourself up for Cloudflare, and an SSL certificate automatically protects your website. You don't necessarily need a certificate if you have a connection between your website and your host, the server, Cloudflare, and the host."
"The most valuable feature of Cloudflare is that it has a free version. They give us the free version with the anti-DDoS features and also the load balancing solution."
"It is a stable solution. I rate the stability a ten out of ten...I rate the scalability a ten out of ten."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"The solution offers the flexibility to control configuration rules."
"We do not have to maintain the solution."
"I believe the most impressive features are integration and ease of use. The best part of AWS WAF is the cloud-native WAF integration. There aren't any hidden deployments or hidden infrastructure which we have to maintain to have AWS WAF. AWS maintains everything; all we have to do is click the button, and WAF will be activated. Any packet coming through the internet will be filtered through."
"If hackers try to insert bugs, the tool blocks it."
"AWS WAF has helped to strengthen the security of my environment; it has also helped to improve the posture of our application, prevent all DDoS attacks and unnecessary traffic and SQL injection that is reducing the performance of our application."
"The most valuable feature is the security, making sure that files are protected, preventing unauthorized users from accessing the system."
"The product's initial setup phase was very simple."
"The product’s availability, ease of configuration, and documentation are valuable."
"The solution is stable."
"One of the most valuable features of AppSpider is its broad range of authentication identification, which is a key reason for its utilization."
"It is really accurate and the rate of false positives is very low."
"The most valuable feature is the reporting, which is compliant with international standards."
"What I like most about AppSpider is that it's easy to use and its automated scan gives me all the details I need to know when it comes to vulnerabilities and their solutions."
"AppSpider's most valuable feature is reporting - everything is stored in the local database so it can be sent to other machines."
"Rapid7 AppSpider is good at managing different applications. It uses applets and generates reports to cover the PCA/GDPR compliance requirements."
"The solution is highly stable, rated at ten out of ten."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information. You don't need specialized skills to use the product."
 

Cons

"I would like Cloudflare to offer a dedicated account manager for large enterprise clients like us."
"Areas like how assessment, discovery, and payload are dealt with and how it all comes into your organization can be considered when trying to make suggestions to Cloudflare for improvements."
"Support response time could be improved."
"There could be more courses with engineers. I like e-learning, however, having a specialist in a classroom is more comfortable for me."
"For large enterprises, the pricing is okay. However, the enterprise price for small projects is a bit high. A mid-tier pricing option would be beneficial."
"The Cloudflare load balancing capability hasn't really helped in enhancing my website's uptime and resiliency because we don't really get that much traffic; it's mostly remote users, and web hosting is done by a web hosting service."
"Cloudflare could offer a better view or maybe dashboards of the main resources used in the client."
"The product support needs to be accessible from more places, a wider area of coverage."
"One area that could be improved is the DDoS protection."
"The serverless product from AWS WAF could be improved. For example, they have only one serverless series, Lambda, but they should extend and improve it. Additionally, the firewall rules are not very easy to configure."
"The solution can improve its price."
"The dashboarding could be improved, and the default metrics provided by AWS WAF could be upgraded."
"The cost must be reduced."
"For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends."
"We should be able to do proper whitelisting."
"The solution's pricing could be improved."
"For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese reports for end-users."
"Support response times are slow and can be improved."
"The dashboard and interface are crucial and they need some improvement."
"AppSpider could improve in the area of integration. They need to add more integration opportunities."
"The product should offer a GUI in Japanese and provide Japanese reports for end-users."
"The enterprise interface is too simple. It should be more customizable."
"One of the challenges I have with AppSpider is that it gives you a lot of false positives, especially when compared to other solutions."
"This price of this solution is a little bit expensive."
 

Pricing and Cost Advice

"The price is reasonable."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"When you compare Cloudflare DNS to other solutions, such as Akamai, the price is reasonable."
"I give the price a five out of ten."
"The price of the solution is expensive."
"The pricing for the service is reasonable, neither excessively cheap nor prohibitively expensive. It aligns well with the value of their solution."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"There are no separate licensing costs we pay for since it is included in the plan we purchase."
"The product is moderately priced."
"It's an annual subscription."
"The solution is affordable."
"AWS WAF has reasonable pricing."
"You need an additional AWS subscription for this product if you are buying a managed tool."
"AWS WAF has reasonable pricing."
"The pricing should be more affordable, especially as it pertains to small clients."
"The price is pretty fair."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
"The licensing cost depends on the number of users."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
879,422 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Comms Service Provider
10%
Manufacturing Company
8%
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
9%
Government
6%
Financial Services Firm
13%
Manufacturing Company
10%
Computer Software Company
10%
Educational Organization
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise8
Large Enterprise25
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What do you like most about Cloudflare?
Cloudflare offers CDN and DDoS protection. We have the front end, API, and database in how you structure applications.
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price is not high, but for Japanese customers, localization may incur additional costs.
What needs improvement with Rapid7 AppSpider?
For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese repor...
What is your primary use case for Rapid7 AppSpider?
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who r...
 

Also Known As

Cloudflare DNS
AWS Web Application Firewall
AppSpider
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
eVitamins, 9Splay, Senao International
Microsoft
Find out what your peers are saying about Fortinet, F5, Amazon Web Services (AWS) and others in Web Application Firewall (WAF). Updated: November 2025.
879,422 professionals have used our research since 2012.