Fortify WebInspect vs Qualys Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Fortify WebInspect
Average Rating
7.0
Number of Reviews
17
Ranking in other categories
Dynamic Application Security Testing (DAST) (2nd), DevSecOps (8th)
Qualys Web Application Scan...
Average Rating
7.8
Number of Reviews
31
Ranking in other categories
Application Security Tools (19th), Static Application Security Testing (SAST) (14th)
 

Mindshare comparison

As of June 2024, in the Dynamic Application Security Testing (DAST) category, the mindshare of Fortify WebInspect is 44.0%, up from 40.2% compared to the previous year. The mindshare of Qualys Web Application Scanning is 30.0%, down from 47.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
Unique Categories:
DevSecOps
15.5%
Application Security Tools
2.4%
Static Application Security Testing (SAST)
1.8%
 

Featured Reviews

AB
May 5, 2020
Easy to use with a simple interface, but we sometimes had trouble capturing login sequences
We use WebInspect for performance network application testing to be sure that we aren't creating any security issues The most valuable feature is the performance. The user interface is ok and it is very simple to use. There were times when we had to run the login sequence several times in order…
Brammadevan K - PeerSpot reviewer
Feb 22, 2024
Operates as a DAST tool, examining the application from an external perspective to identify security issues
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an option to select or integrate other security standards directly within the platform, which limits the scope of scans to primarily OWASP. For broader compliance, custom integrations are required, which is a cumbersome process. The platform primarily supports OWASP standards for scanning. If an organization needs to comply with other standards, such as ISO or NIST, there's no straightforward option to select these within the scanning interface. This limitation requires custom solutions to meet other compliance requirements, which is not ideal. Qualys should enhance its interface to allow users to easily select and scan according to multiple standards, not just OWASP. This includes both internal and external scans, providing a more flexible and comprehensive approach to web application security. In addition to choosing standards, there's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage. The process should be simplified to eliminate the need for two distinct setups for internal and external scans within Qualys.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's a well-known platform for doing dynamic application scanning."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"Good at scanning and finding vulnerabilities."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"The solution is easy to use."
"Technical support has been good."
"When we are integrating it with SSC, we're able to scan and trace and see all of the vulnerabilities. Comparison is easy in SSC."
"I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors. It allows many types of outputs, such as bar and chart previews."
"Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
"​We have experienced quick customer support. They have a complete list of our previous issues along with our history, which makes it faster for them to solve issues.​"
"The most valuable feature of Qualys Web Application Scanning is the effective scanning that can be done."
"The most valuable feature is that we are able to scan the services and put credentials like a user ID password. We can verify the vulnerability level."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"By using QualysGuard, we are able to finish external scans with assured results in half the time.​"
"You can integrate your Burp Suite results and create an integrated report. Also, the way it shows the results - threats and exploit details - makes remediation very easy."
 

Cons

"Not sufficiently compatible with some of our systems."
"I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"Creating reports is very slow and it is something that should be improved."
"Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environment."
"It took us between eight and ten hours to scan an entire site, which is somewhat slow and something that I think can be improved."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"We have often encountered scanning errors."
"It should have better automatic reporting."
"Deployment can be complicated."
"Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly."
"We procured around 110 licenses for Web Application Scanning, but we have issues running concurrent scans. I don't currently have the option to trigger scans for all 100-plus websites. The default limit is around 10 conference scans. It's not very scalable, to be honest, because of the limitation that they put on concurrent scans."
"The reporting contains too many false positives."
"The solution needs to adjust its pricing. They should make it more affordable."
"The pricing does not seem to be competitive."
"The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes."
 

Pricing and Cost Advice

"The pricing is not clear and while it is not high, it is difficult to understand."
"It’s a fair price for the solution."
"The price is okay."
"This solution is very expensive."
"Fortify WebInspect is a very expensive product."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"Try the free trial of the product to understand the basic working mechanisms.​"
"Pricing was reasonable and competitive. It was not too far above the other products."
"I rate the software’s pricing a six out of ten."
"The product has a very good licensing model."
"There are different options available with respect to licensing."
"​It is best to be an institutional buyer and directly contact the sales team, as they can provide over-the-top discounts for bulk orders​."
"Qualys WAS' pricing is competitive."
"We normally purchase an annual license."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
16%
Government
14%
Manufacturing Company
12%
Computer Software Company
15%
Financial Services Firm
15%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What needs improvement with Fortify WebInspect?
Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environm...
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What is your experience regarding pricing and costs for Qualys Web Application Scanning?
From my perspective, it is a budget-friendly option. Qualys offers good value for the features and protection it provides. The pricing seems reasonable, considering the comprehensive security solut...
What needs improvement with Qualys Web Application Scanning?
One area for improvement is the application scan interface. Although recent updates have introduced some features, there's a gap in supporting standards beyond OWASP. Currently, there isn't an opti...
 

Also Known As

Micro Focus WebInspect, WebInspect
Qualys WAS
 

Learn More

 

Overview

 

Sample Customers

Aaron's
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Find out what your peers are saying about Fortify WebInspect vs. Qualys Web Application Scanning and other solutions. Updated: May 2022.
787,779 professionals have used our research since 2012.