No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point WAF (formerly CloudGuard WAF) vs GitHub Advanced Security comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point WAF (formerly C...
Ranking in Application Security Tools
5th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
76
Ranking in other categories
Data Loss Prevention (DLP) (8th), Web Application Firewall (WAF) (5th), DevSecOps (2nd)
GitHub Advanced Security
Ranking in Application Security Tools
11th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
12
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Application Security Tools category, the mindshare of Check Point WAF (formerly CloudGuard WAF) is 0.9%, up from 0.2% compared to the previous year. The mindshare of GitHub Advanced Security is 2.4%, down from 8.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Check Point WAF (formerly CloudGuard WAF)0.9%
GitHub Advanced Security2.4%
Other96.7%
Application Security Tools
 

Featured Reviews

Krishnakumar Mahadevan - PeerSpot reviewer
CISO at Spink Solutions Private Limited
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Devendiran Kandan - PeerSpot reviewer
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Security scanning has protected our pipelines but currently needs clearer dashboards and controls
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inline product, I'm not seeing user-friendly things in GitHub Advanced Security. Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, before building and deploying the code, we want to block or do an advanced model, but it is not supporting. During deployment, code scanning is not good. It is a little complicated. It is not a straightforward method we can complete. We need expertise to get the full benefit, and troubleshooting sometimes requires going through that. The security overview dashboard is not really clear. It's not showing centralized information; each repo is showing, but if you compare it with competitors, it is not that great. Mainly in the centralized dashboard, enterprise level needs to improve. A centralized way where we can get that overall view is needed, and we want that code scanning and blocking deployments based on security. There are AI improvements, but however, it is not so easy to configure. It is multiple windows we need to go through and make changes or configure that. A few things we need to enable going into settings, and a few things we can find out in security. One product where security means the security dashboard should cover everything, but it is going here and there in many places.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Check Point CloudGuard WAF has positively impacted our organization in security and operational efficiency, with a 30-40% drop in malicious traffic and a 15-20% reduction in manual intervention for our SOC team due to reduced false positives and automated protection."
"Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning."
"With the introduction of AI in general, Check Point CloudGuard WAF provides very high accuracy on the data, allowing me to avoid a lot of false positives and saving me time in determining if what I'm seeing is a possible attack."
"We can ensure that by following and adapting our needs based on these guidelines we will be a great organization with a strong vision and a great security framework established to protect us."
"Check Point CloudGuard Network Security helped reduce the cost of ownership for our web application firewall by 50%."
"The biggest benefit from Check Point CloudGuard WAF that I saw is that it comes with one solution that completely outperforms its competitors."
"CloudGuard WAF has been great."
"User attitude reviews help us keep all online users compliant with company regulations and policies."
"GitHub Advanced Security uses artificial intelligence in the backend, specifically CodeQL, to analyze code and provide fewer but more reliable findings, so there are less false positives."
"The best features of GitHub Advanced Security are its flexibility and the multiple options it has compared to other tools."
"GitHub Advanced Security is ten out of ten scalable."
"I have not experienced any performance or stability issues with GitHub Advanced Security."
"It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part."
"Dependency scanning is a valuable feature."
"GitHub Advanced Security is a very developer-friendly solution that is integrated within my development environment."
"The initial setup was straightforward and completed in a matter of minutes."
 

Cons

"Check Point CloudGuard WAF's support is only available in English."
"CloudGuard could improve in areas such as ease of integration with Fortinet and reducing costs associated with deployment in cloud environments like Azure."
"While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database."
"The user interface, SmartConsole, sometimes malfunctions and requires a restart."
"The pricing can be a bit complex to understand initially."
"Pricing and licensing are really expensive for this product. While it provides a very good security level, the price for each service is high."
"As a reseller, the most difficult part is the lack of awareness."
"Support could be improved, particularly in terms of availability."
"The customizations are a little bit difficult."
"GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner."
"There could be DST features included in the product."
"Maybe make it compatible with more programming languages. Have a customized ruleset where the end-user can create their own rules for scanning."
"An area of GitHub Advanced Security that has room for improvement is customization."
"The reporting feature might need improvement. While it integrates seamlessly with my workflow, it doesn't provide management with oversight, such as statistics and the number of vulnerabilities."
"We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security."
"The deployment part of the product is an area of concern that needs to be made easier from an improvement perspective."
 

Pricing and Cost Advice

"The tool's licensing costs are yearly and competitive."
"Considering all the benefits we've observed, we find the price to be satisfactory."
"It is not cheap, but it is worth it."
"Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
"I find the pricing to be reasonable."
"It is extremely affordable and high value for cost."
"The base solution costs approximately 30,000 euros, with an additional 2,000 euros per year for licenses and support."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"The solution is expensive."
"The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Outsourcing Company
13%
Financial Services Firm
9%
Construction Company
9%
Financial Services Firm
16%
Computer Software Company
9%
Manufacturing Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business54
Midsize Enterprise23
Large Enterprise34
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for CloudGuard for Application Security?
It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.
What needs improvement with CloudGuard for Application Security?
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it c...
What is your primary use case for CloudGuard for Application Security?
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking fo...
What needs improvement with GitHub Advanced Security?
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inli...
What is your primary use case for GitHub Advanced Security?
I'm working with software development nowadays. As a process, we are using the dependent bot alerts and the code scanning for Java, and some of the code scanning is happening. Security secrets in c...
What advice do you have for others considering GitHub Advanced Security?
Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, ...
 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec, Check Point CloudGuard Code Security
No data available
 

Overview

 

Sample Customers

Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point WAF (formerly CloudGuard WAF) vs. GitHub Advanced Security and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.