No more typing reviews! Try our Samantha, our new voice AI agent.

AWS WAF vs Rapid7 AppSpider comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
Web Application Firewall (WAF) (7th)
AWS WAF
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
61
Ranking in other categories
Web Application Firewall (WAF) (4th)
Rapid7 AppSpider
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
14
Ranking in other categories
Static Application Security Testing (SAST) (31st)
 

Mindshare comparison

Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
AWS WAF5.3%
Imperva Application Security Platform8.1%
Fortinet FortiWeb7.5%
Other79.1%
Web Application Firewall (WAF)
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Rapid7 AppSpider0.7%
SonarQube17.7%
Checkmarx One10.4%
Other71.2%
Static Application Security Testing (SAST)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
Azam S M - PeerSpot reviewer
Infrastructure Lead at Danat Fz LLC
Has successfully filtered malicious traffic and allowed country-specific access controls
For improvement in AWS WAF, we can have better monitoring. One of the things that should be improved in AWS WAF is the monitoring; we need to identify the requests and where they are coming from. If it's a bot, we should differentiate the requests, whether they are automated or not. The way we see it now is just mentioned as a percentage from bots and actual users, which should include proper graphs and detailed information. We also need a feature where we can filter specific requests. If there are scripts in the requests, we should be able to filter those requests to see if there are any scripts running from them.
HW
Marketing Expert at J's communication
Clients benefit from broad authentication and effective crawling but need localization improvements
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who require security assessments One of the most valuable features of AppSpider is its broad range of authentication identification, which is a key reason for its utilization.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cloudflare is cheaper compared to Azure WAF, which I have considered before."
"Someone with a basic understanding of networking and security will be able to implement the firewall's basic features within 15 minutes."
"The setup process is very simple for me."
"Does a good job preventing web application attacks."
"I'm highly satisfied. It's remarkably user-friendly, enabling me to quickly identify issues, and deploy solutions, and it offers the necessary features."
"The integration of Cloudflare with Cloud Suite is its most valuable feature."
"It is a SaaS solution unlike much of the competition."
"Cloudflare has positively impacted my organization by making it easier for me to handle and set up DNS for multiple clients; I can easily go in and access their accounts, make changes they need, and it's a one-stop shop."
"The ability to take multiple data sets and match those data sets together is the solution's most valuable feature."
"The automation of blocking for security attacks is valuable, with AWS applying rate limiting."
"The access instruction feature is the most valuable. This is what we use the most."
"The most valuable feature of the solution is the ability to integrate central sets. It protects from intrusion attacks such as scripting and SQL injections."
"It is a one-click WAF with no effort needed."
"The solution's initial setup process is easy."
"The most valuable features of AWS WAF are its cloud-native and on-demand."
"It's simple, easy to use."
"I would say that it is stable, as I am not aware of any major issues."
"It is really accurate and the rate of false positives is very low."
"The most valuable feature of Rapid7 AppSpider is the vulnerability reporting data. Additionally, the data is reported in a convenient way rather than seeing them as a PDF. We are able to generate all the reports exactly what we want in a flexible way."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information. You don't need specialized skills to use the product."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information, and you don't need specialized skills to use the product."
"The initial deployment is very straightforward and simple. The product is stable if configured properly."
"It scans all the components developed within a web application."
"The setup is usually straightforward."
 

Cons

"They have some limitations with third-party integrations."
"They need to improve their support because getting a response for basic requests took around 48 hours, which is too long."
"It would be ideal if the solution offered better log integration and more integration with different platforms."
"The platform's control features related to real-time authentication and response time need improvement."
"The solution's learning curve can still be further reduced"
"The dashboard could be more user-friendly."
"I have experienced some difficulties with Cloudflare's support as a customer based in India."
"Cloudflare Web Application Firewall should improve visibility for a customer."
"The complexity of deploying turnkey solutions could be simplified."
"Alternative WAFs have something like bot mitigation or bot control within the WAF, but you don't have such things in AWS WAF."
"It will be helpful if the product recommends rules that we can implement."
"For uniformity, AWS has a well-accepted framework. However, it'll be better for us if we could have some more documented guidelines on how the specific business should be structured and the roles that the cloud recommends."
"Technical support for AWS WAF needs improvement."
"AWS WAF can be improved if the dashboard is enhanced in such a way that everything will be displayed automatically without you going in there to see what is going on."
"The area of reporting in the product needs to have a proper format."
"In a future release I would like to see automation. There's no interaction between the applications and that makes it tedious. We have to do the preparation all over again for each of our other applications."
"AppSpider has some problems with the RAM needed while scanning."
"AppSpider could improve in the area of integration. They need to add more integration opportunities."
"Integration could be better. For example, while doing the scanning, using the recording username and passwords, there are issues."
"This price of this solution is a little bit expensive."
"The enterprise interface is too simple. It should be more customizable."
"AppSpider has some problems with the RAM needed while scanning."
"The solution is too slow. It could take a full day to scan. Competitors are much faster."
"Support response times are slow and can be improved."
 

Pricing and Cost Advice

"It is not too pricey."
"Cloudflare Web Application Firewall is more affordable than other solutions."
"The solution's pricing option needs to be more transparent for enterprise clients."
"Cloudflare offers different types of subscriptions for businesses, enterprises, and personal users, and the pricing is negotiable."
"It starts at $20 and can easily go up to $200 monthly"
"The solution is expensive."
"The pricing model is very straightforward compared to the competition. You just pay per month for the product and usage."
"The annual licensing fee is $10,000 USD."
"The product’s pricing is reasonable."
"It has a variable pricing scheme."
"It's an annual subscription."
"It's cheap."
"The solution's cost depends on the use cases."
"The price of AWS WAF is expensive if you do not know how to manage your software up or down. I price of the solution is average amongst the other competitors but it would be better if it was less expensive."
"We are kind of doing a POC comparison to see what works best. Pricing-wise, AWS is one of the most attractive ones. It is fairly cheap, and we like the pricing part. We're trying to see what makes more sense operation-wise, license-wise, and pricing-wise."
"For Kubernetes microservices, AWS is more expensive compared to OCI. AWS costs approximately 70 cents per hour, while OCI is 50% cheaper."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
"The price is pretty fair."
"The licensing cost depends on the number of users."
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
19%
Computer Software Company
8%
Comms Service Provider
8%
Manufacturing Company
7%
Financial Services Firm
15%
Computer Software Company
11%
Manufacturing Company
9%
Government
6%
Manufacturing Company
10%
University
9%
Financial Services Firm
9%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise26
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What are the limitations of AWS WAF vs alternative WAFs?
Hi Varun, I have had experienced with several WAF deployments and deep technical assessments of the following: 1. Im...
How does AWS WAF compare to Microsoft Azure Application Gateway?
Our organization ran comparison tests to determine whether Amazon’s Web Service Web Application Firewall or Microsoft...
What do you like most about AWS WAF?
The most valuable feature of AWS WAF is its highly configurable rules system.
What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price is not high, but for Japanese customers, localization may incur additional costs.
What needs improvement with Rapid7 AppSpider?
For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese repor...
What is your primary use case for Rapid7 AppSpider?
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who r...
 

Also Known As

Cloudflare WAF
AWS Web Application Firewall
AppSpider
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
eVitamins, 9Splay, Senao International
Microsoft
Find out what your peers are saying about Fortinet, F5, Imperva and others in Web Application Firewall (WAF). Updated: March 2026.
885,728 professionals have used our research since 2012.