Try our new research platform with insights from 80,000+ expert users

Black Duck vs OpenText Static Application Security Testing comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.2
Black Duck improved efficiency by identifying vulnerabilities early, saving time, streamlining audits, reducing manual effort, and enhancing code security.
Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
If you're using it on critical external programs where there is regulatory compliance on ensuring that the source code is clean from open-source, there's substantial ROI.
 

Customer Service

Sentiment score
9.3
Black Duck support is praised for professionalism and speed, but faces inconsistent feedback, response delays, and suggests chatbot integration improvements.
Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
There are some pain points with the response time and first-level support quality.
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
The technical support has been good because we always received answers to our questions.
 

Scalability Issues

Sentiment score
8.0
Black Duck is scalable, praised for cloud support and integration, but pricing may deter smaller firms despite versatility.
Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
I would rate the scalability of Black Duck 8 or 9.
Fortify Static Code Analyzer integrates well and is scalable.
 

Stability Issues

Sentiment score
8.0
Black Duck is highly stable, reliable, with minimal issues; users recommend against transitioning to Hub due to potential problems.
Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
The stability of Fortify Static Code Analyzer is generally good.
I would rate the product stability as an eight.
 

Room For Improvement

Black Duck needs better integration, speed, UI, documentation, pricing, security, scalability, and support for improved user experience.
OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
It can improve on the security side of it, specifically vulnerabilities identification.
There are areas for improvement such as false positives and the scanning of containers.
Black Duck does not have the SBOM management part.
We would appreciate if the AI could give us more information about improvements and reduce the number of false positives, but this solution doesn't have this function yet.
It would be really helpful to include trending vulnerabilities and how to manage them.
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
 

Setup Cost

Black Duck's pricing ranges from $10,000 to $70,000, with unlimited users for code size, though some find it expensive.
Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
My experience with the pricing, setup costs, and licensing has been good.
 

Valuable Features

Black Duck excels in vulnerability scanning, license management, and policy management, offering strong UI and seamless Docker integration.
OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
The most valuable feature of Black Duck is the composition analysis feature, which is effective for security risk management.
Black Duck's ability to identify dependencies very accurately has been most valuable in identifying and mitigating risks.
The software composition analysis is most effective for security risk management.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
 

Categories and Ranking

Black Duck
Average Rating
7.6
Reviews Sentiment
7.4
Number of Reviews
22
Ranking in other categories
Software Composition Analysis (SCA) (1st)
OpenText Static Application...
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
Static Code Analysis (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Black Duck is designed for Software Composition Analysis (SCA) and holds a mindshare of 18.6%, down 22.6% compared to last year.
OpenText Static Application Security Testing, on the other hand, focuses on Static Code Analysis, holds 11.7% mindshare, up 10.0% since last year.
Software Composition Analysis (SCA)
Static Code Analysis
 

Featured Reviews

Saravanan_Radhakrishnan - PeerSpot reviewer
Enables applications to be secure, but it must provide more open APIs
The product enables other applications to be secure. We use it to onboard 400 to 500 applications into the DevOps platform, protect them, and have a secure environment. The tool integrates well with different technologies, application stacks, and databases. The APIs are available. We can read the blogs in the community for open-source compliance and security. The community feeds are important. Black Duck is a leader in Gartner. It is a reliable solution.
Aphiwat Leetavorn. - PeerSpot reviewer
Provides extensive language support and enhances secure coding practices
The deployment of Fortify Static Code Analyzer needs to be simplified. It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers. This change would facilitate easier installations and ensure all necessary components are connected and ready to use.
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
857,688 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Manufacturing Company
15%
Computer Software Company
13%
Insurance Company
4%
Financial Services Firm
29%
Computer Software Company
13%
Manufacturing Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How does WhiteSource compare with Black Duck?
We researched Black Duck but ultimately chose WhiteSource when looking for an application security tool. WhiteSource is a software solution that enables agile open source security and license compl...
What do you like most about Black Duck?
The cloud option of the product is always available and a positive aspect of the solution.
What is your experience regarding pricing and costs for Black Duck?
The price charged by Black Duck is exorbitant. For the features provided by the product, I would not want to pay a high price. There are many other products in the market that offer better features...
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
 

Also Known As

Blackduck Hub, Black Duck Protex, Black Duck Security Checker
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

Samsung, Siemens, ScienceLogic, BryterCX, Dynatrace
Information Not Available
Find out what your peers are saying about Black Duck, Snyk, Veracode and others in Software Composition Analysis (SCA). Updated: June 2025.
857,688 professionals have used our research since 2012.