No more typing reviews! Try our Samantha, our new voice AI agent.

CAST Highlight vs Tenable.io Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CAST Highlight
Average Rating
7.8
Reviews Sentiment
7.3
Number of Reviews
8
Ranking in other categories
Software Composition Analysis (SCA) (19th)
Tenable.io Web Application ...
Average Rating
7.8
Reviews Sentiment
5.8
Number of Reviews
18
Ranking in other categories
Application Security Tools (22nd)
 

Mindshare comparison

CAST Highlight and Tenable.io Web Application Scanning aren’t in the same category and serve different purposes. CAST Highlight is designed for Software Composition Analysis (SCA) and holds a mindshare of 1.2%, up 0.9% compared to last year.
Tenable.io Web Application Scanning, on the other hand, focuses on Application Security Tools, holds 1.4% mindshare, up 1.2% since last year.
Software Composition Analysis (SCA) Mindshare Distribution
ProductMindshare (%)
CAST Highlight1.2%
Snyk11.1%
Black Duck SCA9.2%
Other78.5%
Software Composition Analysis (SCA)
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Tenable.io Web Application Scanning1.4%
SonarQube12.7%
Checkmarx One8.3%
Other77.6%
Application Security Tools
 

Featured Reviews

Nishant Chauhan - PeerSpot reviewer
Senior Data Engineer at LTM
Automated code insights have improved security checks and made review workflows more consistent
If I talk about improvements for CAST Highlight, I would suggest three things. The first is better understanding or niche understanding. Right now, the intent matching is strong for general topics such as ease of use, but for niche B2B terms such as HIPAA compliance or multi-tenant architecture, it sometimes misses context. Improving the domain-specific models would make highlights more accurate for these verticals. The second improvement is more control over the deduplication logic. CAST Highlight's deduplication is great for avoiding spam, but sometimes we want two similar quotes if they are from very different company sizes, such as SMB versus enterprise perspectives on pricing. A slider to adjust deduplication strictness would help. The third suggestion I would like to give is deeper sentiment and outcome tagging. While it has core sentiment capabilities, it does not tag outcomes automatically. For instance, if a quote mentions saved $50,000 per year, tagging that as cost savings $50,000 would let us build ROI charts instantly instead of reading each quote manually. Regarding user experience, integrations, and reporting, I think there is room to enhance those aspects. Regarding user experience, I would suggest improving user actions in terms of bulk actions and keyboard shortcuts. Day-to-day analysts review 50-plus suggested quotes, and currently it is mostly clicking to approve one by one. Adding bulk approve or reject options and keyboard shortcuts would significantly reduce the time taken. A small UX change can lead to a big speed boost. The second point is integrations when pushing to the CMS and Slack alerts. Right now, we export approved highlights manually from CAST Highlight. If CAST Highlight could push directly to our CMS or send Slack alerts for high-strength quotes that hit trending topics, it would close the loop faster, reducing copy-pasting. The third improvement relates to reporting, specifically custom insight dashboards. The tool displays which topics have the most highlights, but we cannot build custom dashboards yet. For example, showing all security quotes from healthcare companies with more than 1,000 employees over the last 90 days would enable better filtering, and exportable dashboards would streamline quarterly reviews.
HL
Security Analyst at TOPNET
Web audits have identified vulnerabilities and now provide clear visibility into compliance gaps
We have experience with Tenable.io Web Application Scanning, and we use it as well; we have approximately ten licenses for web application scanning. We use it to find vulnerabilities, but Tenable.io Web Application Scanning does not include remediation; we remediate with other products. We use the…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We are using CAST Highlight for the location because it's an indicator for us that can differentiate us from the other health insurance company, and we are using the indicator as proof of the quality of service for our application."
"CAST Highlight provides a clear overview of the role portfolio and allows users to assess the overall quality of the environment. Users can see where improvements are needed and follow up on trends of the application."
"In cloud migration, I use CAST highlight to identify blockers, which are the negative road patterns, and also the boosters, which are positive code patterns."
"The most valuable features of CAST Highlight are automation and speed."
"Overall, the accuracy of CAST Highlight has been strong and reliability is consistent for our use case."
"It offers good performance."
"CAST Highlight is easy to use and has a good dashboard."
"We've been using it for two years and found that it is really profitable to have the product in our arsenal."
"I would recommend Tenable.io Web Application Scanning to others."
"All the features are valuable to us as they offer cutting-edge scanning methods and address the latest issues with a contemporary approach. Tenable.io Web Application Scanning is highly stable. I rate it a nine out ten. Since the solution works on the Cloud, it's highly scalable. I rate the scalability a nine out of ten. The setup of the solution is straightforward. The Return on Investment is substantial. I recommend the solution to all."
"The most valuable feature is the reporting, which provides a good level of detail with respect to vulnerabilities."
"The most valuable features of Tenable.io Web Application Scanning are the integration into specific use cases and scanning. All of the features of the solution are useful."
"The most effective feature of the product is the ability to scan the entire environment."
"Tenable.io Web Application Scanning provides a detailed report, identifying functions that are complex and need to be more maintainable and readable."
"Our customers adopt this solution because of the replication testing and the vulnerability assessment it can do. It is a multi-faceted product."
"The solution's instant reports feature is the most effective for detecting threats."
 

Cons

"There's a bit of a learning curve at the outset."
"The ease of configuration and customization could be improved in CAST Highlight."
"There could be potential improvements or additional features added to CAST Highlight to make it better."
"Right now, the intent matching is strong for general topics such as ease of use, but for niche B2B terms such as HIPAA compliance or multi-tenant architecture, it sometimes misses context."
"Its price should be better. It is a pretty costly tool. They have two products: CAST Highlight and CAST AIP. I would expect CAST Highlight to have the Help dashboard and the Engineering dashboard. These dashboards are currently a part of CAST AIP, and if these are made available in CAST Highlight, customers won't have to use two different products all the time."
"It is a pretty costly tool. A lot of customers are resistant to using it."
"If I received categorization in containerization blockers, it would save time."
"CAST Highlight could improve to allow us to comment and do a deep analysis by ourselves."
"We have encountered some problems with the technical support from Tenable; I would rate it a five out of ten. It is not efficacious, especially the first-level support."
"Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."
"The solution's dashboards could be improved and made more user-friendly."
"The cloud and the on-premises versions have their own controllers, and there is no way to centrally manage controllers."
"I would like for them to add intervening proxy, whereby you can alter the get/put requests."
"It isn't easy to manage vulnerabilities in Tenable."
"Sometimes it lags with different cloud environments."
"The dashboard could be more user-friendly."
 

Pricing and Cost Advice

"Basic support is included with the standard licensing feed but it can be upgraded for an additional cost."
"CAST Highlight is an expensive solution."
"CAST Highlight is an expensive solution. However, CAST Highlight is less expensive than the CAST AIP, but it remains too expensive and the professional services from CAST are also too expensive. The high price is part of the problem with the CAST solutions."
"It is a pretty costly tool. A lot of customers are resistant to using it."
"The application is extremely affordable. There are no additional costs involved with licensing. We switched to Tenable.io Web Application Scanning from other solutions due to pricing."
"It follows the same licensing scheme as Tenable.io and Tenable. sc."
"For Tenable.io Web Application Scanning, it comes to around 6,50,000 Indian rupees, plus taxes."
"The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage."
"The pricing is okay."
"I rate the product's pricing a four out of ten."
"Tenable.io Web Application Scanning is expensive for small businesses."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
902,270 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Outsourcing Company
8%
Government
8%
Computer Software Company
8%
Financial Services Firm
15%
Manufacturing Company
9%
Comms Service Provider
8%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise6
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise5
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for CAST Highlight?
The pricing of CAST Highlight was not considered expensive or cheap, and no specific comment was made about the setup cost.
What needs improvement with CAST Highlight?
The solution provides agnostic blockers for platforms as well as for containerization. Within that containerization, it offers generic blockers. However, my project might require it to provide Wind...
What is your primary use case for CAST Highlight?
For CAST, I use it in cloud migration roadmap and in open source safety issues. These are my two main use cases.
What needs improvement with Tenable.io Web Application Scanning?
If there were a solution, I would like to see automation and an integrated remediation solution for vulnerability or patch management.
What advice do you have for others considering Tenable.io Web Application Scanning?
I do not understand what API approach means; I do not understand this term. I think Tenable.io Web Application Scanning is the best option on the market at the moment. My review rating for this pro...
What is your experience regarding pricing and costs for Tenable.io Web Application Scanning?
I think the price is expensive. We do not have an idea of how much we have to pay approximately, but comparing to other products, Tenable.io Web Application Scanning is expensive.
 

Overview

 

Sample Customers

Wells Fargo, Bank of NY Mellon, Northern Trust, Microsoft, Amazon, IBM, BMW, AT&T, US Army, US Air Force, US Navy, John Hancock, Marsh & McLennan, Ernst & Young, PwC, Volkswagen, Boston Consulting Group, London Stock Exchange, Telefonica, Saur France, Total Energies France, SNCF
IMDEX
Find out what your peers are saying about Snyk, Veracode, Black Duck and others in Software Composition Analysis (SCA). Updated: May 2026.
902,270 professionals have used our research since 2012.