No more typing reviews! Try our Samantha, our new voice AI agent.

Aikido Security vs Rapid7 InsightAppSec comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Aikido Security
Ranking in Dynamic Application Security Testing (DAST)
4th
Average Rating
9.0
Reviews Sentiment
7.3
Number of Reviews
9
Ranking in other categories
Application Security Tools (7th), Static Application Security Testing (SAST) (4th), Web Application Firewall (WAF) (11th), Container Security (16th), Software Composition Analysis (SCA) (6th), Static Code Analysis (4th), Cloud Security Posture Management (CSPM) (12th), DevSecOps (6th), Application Security Posture Management (ASPM) (5th)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
5th
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
21
Ranking in other categories
AI Observability (23rd)
 

Mindshare comparison

As of October 2026, in the Dynamic Application Security Testing (DAST) category, the mindshare of Aikido Security is 4.3%, up from 3.0% compared to the previous year. The mindshare of Rapid7 InsightAppSec is 5.5%, up from 5.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Mindshare Distribution
ProductMindshare (%)
Aikido Security4.3%
Rapid7 InsightAppSec5.5%
Other90.2%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Tarunn Goswami - PeerSpot reviewer
GEN AI Engineer at a educational organization with 51-200 employees
Security has shifted left and now catches vulnerabilities early in our development workflow
There are a few areas for improvement. The first is scan speed. For large repositories, initial scans can be slow. Incremental scanning helps, but full scans still take considerable time. The second thing is the false positive rate. While Auto-Triage is good, it is not perfect. Occasionally, genuine issues get filtered out and real false positives slip through. The third one is remediation guidance. Aikido Security tells you what is vulnerable, but sometimes the fix suggestions are generic. More specific, actionable remediation steps would save developer time. The fourth one is IDE integrations. It currently works best in CI/CD pipelines. A proper VS Code or JetBrains plugin for real-time scanning while coding would be a significant improvement. From a customer point of view, the following things could change. The first thing is documentation for custom rules. Aikido Security allows you to create custom scanning rules, but the documentation for this feature is surprisingly thin. I spent considerable time in community forums and with trial and error just to configure basic custom rules. Step-by-step guides with real-world examples would make this feature much more accessible. The second thing is better Slack and communication integrations. Currently, security alerts come through email and dashboard notifications, but our team lives in Slack. A more configurable Slack integration that sends contextual alerts directly to the relevant developer, not just a generic channel notification, would dramatically improve response time. The third one is historical trend reporting. While Aikido Security shows current vulnerability status well, generating historical reports showing security posture improvement over time is limited. For presenting security progress to management or stakeholders, better exportable trend reports would be very valuable.
Brandi Lea - PeerSpot reviewer
Regional Information Security Analyst, Lead at a healthcare company with 10,001+ employees
Rapid risk detection has transformed how I uncover hidden vulnerabilities in new applications
Rapid7 InsightAppSec offers excellent features including a cloud-based platform that allows for detailed breakdowns of information into more digestible bits. The platform is user-friendly with a broad range of tools, although it does require quite a bit of a learning curve. It allows me to aggregate data and put it into presentations to send to executives about the security status across the entire enterprise. My favorite aspect of the user-friendly interface of Rapid7 is the primary cloud-based dashboard, which I find most useful. I love that even inside a browser, the intuitive help options are available for figuring out what things are, whether it's hovering over a particular option for insights or using right-click features that offer tools and tips on managing the vulnerabilities when found. The interface is very clean, not overly convoluted or difficult to navigate, which I do enjoy. Rapid7 has positively impacted my organization by allowing me to discover vulnerabilities, both publicly known and zero-day, much faster and efficiently than I ever did in the past, ultimately saving the company a lot of money in compliance issues, fines, and possibly even lawsuits. The number of vulnerabilities I am discovering has improved by almost thirty seven percent in the last two years alone. Remediation especially has increased significantly because I am finding these vulnerabilities faster, and Rapid7 provides tips on how to remediate or harden against them, whether through hardening options or upgrading to better versions, which does save the company money.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Since switching to Aikido Security, I have noticed a positive impact on my team's productivity with measurable results, as we now have measurements."
"Aikido Security has positively impacted my organization because we feel more secure, we have a good monitoring system for vulnerabilities, and we are able to show our clients our security posture and the security posture of our internal systems."
"Aikido Security saved me several hours each week by automating vulnerability scanning and security checks, reducing the need for manual review and helping me focus on more development."
"Aikido Security nests directly in our development workflow and it catches security issues before they reach production."
"We were able to close 90% of issues with the help of Aikido Security tools, providing a return on investment."
"Aikido Security offers the best features including being very easy to use, allowing even a normal tech person with some hands-on experience to use this tool and clearly get the results they want."
"My advice for others looking into using Aikido Security is that if the codebase and everything need to be audited and recorded in a single forum, and if they want a unified solution to scan both the code and the image, they can definitely use it."
"My advice to others looking into using Aikido Security is to get it as soon as possible; right now, it is a very good tool for a very good price, and you will see a return on investment in less than six months."
"The automatic automation of the automated authorization to the SCANNET environment is valuable."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports."
"Relatively speaking, InsightAppSec is good compared to Insight VM."
"It is very convenient to get reports from the tool, which offers high-level environmental statistics."
"I would rate the technical support from Rapid7 a ten, indicating high-quality support."
"I rate stability ten out of ten."
"Rapid7 InsightAppSec helps us in both regulatory compliance and in strengthening our security posture."
 

Cons

"I think Aikido Security could be improved by addressing its Jira integration, which I feel needs a bit of work."
"However, there was one minor issue that I faced. When I had a UUID for an object in the code, Aikido Security was considering it as a secret key, which it was not."
"I think Aikido Security could improve by reducing some pricing model. Pricing is quite high for a normal user, and if they can make it a little less, it will be much better."
"There are a few areas for improvement. The first is scan speed; for large repositories, initial scans can be slow, and while incremental scanning helps, full scans still take considerable time."
"Aikido Security can be improved by addressing the lags in the UI and ensuring that updates can be given very quickly and rapidly."
"I think Aikido Security could be improved with more detailed remediation guidance, such as additional beginner-friendly tutorials and enhanced customization for alerts and reporting."
"The accuracy of Aikido Security's output is still not very high, and there are a few features where they are still lacking behind regarding accuracy."
"Regarding Aikido Security's AI accuracy and reliability of output, I think its AI capabilities are all right, but it can miss the point sometimes; it is good to have a fast and cheap overview, but I would not rely 100% on it."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange."
"There is room for improvement in Rapid7 InsightAppSec by giving clients the ability for extra columns on reports and enabling the extraction of remediation reports into a CSV format. Currently, the PDF format is cumbersome to go through when dealing with thousands of pages."
"The number of web applications we can scan is limited."
"The technical support from Rapid7 is not bad, but the response time can be quite slow sometimes."
"The reporting feature of Rapid7 InsightAppSec needs improvement as it currently provides basic reports."
"In terms of behavioral and pattern recognition, identifying complex attacks such as SQL, blind SQL, JSON, and LDAP injections often results in 94% false positives."
"Scanning can be better. When you add new projects for the same product, it either duplicates or replaces the scan configuration."
"The only concern I have with Rapid7 is that it does not provide enough information about vulnerabilities within AppSec."
 

Pricing and Cost Advice

Information not available
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"The price of this product is very cheap."
"I'm not sure how much it costs exactly, but I know it's expensive."
"Its price is competitive. It is not expensive."
"Rapid7 InsightAppSec is cheap."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
13%
Outsourcing Company
11%
Manufacturing Company
11%
Financial Services Firm
8%
Manufacturing Company
14%
Construction Company
10%
Government
9%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise5
Large Enterprise6
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise2
Large Enterprise6
 

Questions from the Community

What needs improvement with Aikido Security?
One area I think Aikido Security could improve is the depth of their reporting and remediation guidance; sometimes, the platform flags a vulnerability but the suggested fix lacks detail, requiring ...
What is your primary use case for Aikido Security?
My main use case for Aikido Security is to consolidate all our application security scanning into one platform, primarily to manage multiple tools more efficiently. I use it to scan our code for vu...
What advice do you have for others considering Aikido Security?
My advice for anyone considering Aikido Security is to proceed and try it as the onboarding process is straightforward and can be completed within a day. Start by connecting critical repositories a...
What needs improvement with Rapid7 InsightAppSec?
While Rapid7 InsightAppSec is getting better with each update or version, it needs to enhance its zero-day detection for anomalous things without relying on third-party solutions like Vericode. Hav...
What is your primary use case for Rapid7 InsightAppSec?
My main use case for Rapid7 is onboarding all new applications both built in house and third party acquired, where I run them through a sandbox environment and allow Rapid7 to conduct an initial sc...
What advice do you have for others considering Rapid7 InsightAppSec?
If you are looking for a solution that will help identify vulnerabilities and provide remediation tips for hardening your infrastructure, I think Rapid7 does an excellent job. While I do not know t...
 

Also Known As

No data available
InsightAppSec
 

Overview

 

Sample Customers

FinTech GoCardless ZIP CertifID HealthTech Dental Intelligence PE & Group Techstars Cronos Group Security Tech Human Security Tines HR Tech Simployer Recruitee Agency November Five Other Lighthouse (Hospitality Tech) Smokeball (LegalTech) Runna (B2C Tech) GEA Group (Manufacturing) Community fibre (Telecom) n8n (Software Development)
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about Aikido Security vs. Rapid7 InsightAppSec and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.