Try our new research platform with insights from 80,000+ expert users

AWS WAF vs Checkmarx One comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

AWS WAF
Average Rating
8.0
Number of Reviews
53
Ranking in other categories
Web Application Firewall (WAF) (1st)
Checkmarx One
Average Rating
7.6
Reviews Sentiment
7.9
Number of Reviews
70
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (16th), Static Code Analysis (2nd), API Security (3rd), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
 

Mindshare comparison

AWS WAF and Checkmarx One aren’t in the same category and serve different purposes. AWS WAF is designed for Web Application Firewall (WAF) and holds a mindshare of 13.8%, down 15.5% compared to last year.
Checkmarx One, on the other hand, focuses on Application Security Tools, holds 13.1% mindshare, down 14.4% since last year.
Web Application Firewall (WAF)
Application Security Tools
 

Featured Reviews

Rohit Kesharwani - PeerSpot reviewer
Jan 24, 2024
A highly stable solution that helps mitigate different kinds of bot attacks and SQL injection attacks
We use AWS WAF to protect our application from different kinds of attacks. We use AWS WAF for retail customers Our retail application is vulnerable to a lot of bot attacks. AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry. The…
Rohit Kesharwani - PeerSpot reviewer
Feb 19, 2024
Provides good security analysis and security identification within the source code
We use the solution to validate the source code and do SAST and security analysis. Checkmarx dynamics code analysis improved our software security posture by showcasing vulnerabilities within the code and identifying or providing recommendations on how to improve The solution's user interface…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is Amazon. Everything is scalable. It is beyond what we need."
"The most valuable feature of AWS WAF is its highly configurable rules system."
"AWS WAF helps mitigate different kinds of bot attacks and SQL injection that happen within the retail industry."
"The most valuable features of AWS WAF are its cloud-native and on-demand."
"AWS WAF has a lot of integrated features and services. For example, there are security services that can be integrated very well for our customers."
"The most valuable feature of AWS WAF is the extra layer of security that I have when connecting to my web applications."
"Rule groups are valuable."
"As a basic WAF, it's better than nothing. So if you need something simple out of the box with default features, AWS WAF is good."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"The solution allows us to create custom rules for code checks."
"The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
"Our static operation security has been able to identify more security issues since implementing this solution."
"We were using HPE Security Fortify to scan code for security vulnerabilities, but it can scan only after a successful compile. If the code has dependencies or build errors, the scan fails. With Checkmarx, pre-compile scanning is seamless. This allows us to scan more code."
"Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%."
"The UI is very intuitive and simple to use."
"Less false positive errors as compared to any other solution."
 

Cons

"The default content policy available in the tool is not very strong compared to the competitors."
"We have issues with reporting, troubleshooting, and analytics. AWS WAF needs to bring costs down."
"It's a bit difficult to apply the right rules for the right security."
"We need more support as we go global."
"The technical support does not respond to bugs in the coding of the product."
"AWS WAF would be better if it uses AI or machine learning to detect a potential attack or a potential IP that creates an attack even before it happens. I want AWS WAF to capture the IP and automatically write the rule to automate the entire process."
"The product should improve the DDoS-related features."
"AWS WAF could improve by making the overall management easier. Many people that have started working with AWS WAF do not have an easy time. They should make it easy to use."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"Checkmarx could improve by reducing the price."
"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
"The cost per user is high and should be reduced."
"When we first ran it on a big project, there wasn't enough memory on the computer. It originally ran with eight gigabytes, and now it runs with 32. The software stopped at some point, and while I don't think it said it ran out of memory, it just said "stopped" and something else. We had to go to the logs and send them to the integrator, and eventually, they found a memory issue in the logs and recommended increasing the memory. We doubled it once, and it didn't seem enough. We doubled it again, and it helped."
 

Pricing and Cost Advice

"It's cheap."
"The product is moderately priced."
"You need an additional AWS subscription for this product if you are buying a managed tool."
"The pricing is good and manageable."
"The price of AWS WAF is reasonable, it is not expensive and it is not cheap."
"I rate the product price a five on a scale of one to ten, where one is high price, and ten is low price"
"It's quite affordable. It's in the middle."
"I would rate AWS WAF's pricing a seven out of ten."
"It's relatively expensive."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"I believe pricing is better compared to other commercial tools."
"It is an expensive solution."
"The solution is costly."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"It is the right price for quality delivery."
"The solution's price is high and you pay based on the number of users."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
813,418 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
14%
Manufacturing Company
8%
Government
5%
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Imperva WAF 2. F5 WAF 3. Polarisec Cloud WAF Typical limitations on cloud WAF is t...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft Azure Application Gateway web application firewall software was the better fit ...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx is not a cheap solution. For around 250 users or committers, the cost is approximately $500,000. However, the investment is justified considering the potential costs of security breaches ...
 

Also Known As

AWS Web Application Firewall
No data available
 

Overview

 

Sample Customers

eVitamins, 9Splay, Senao International
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Find out what your peers are saying about Amazon Web Services (AWS), Microsoft, F5 and others in Web Application Firewall (WAF). Updated: October 2024.
813,418 professionals have used our research since 2012.