No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point WAF (formerly CloudGuard WAF) vs GitHub Advanced Security comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Check Point WAF (formerly C...
Ranking in Application Security Tools
4th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
81
Ranking in other categories
Data Loss Prevention (DLP) (6th), Web Application Firewall (WAF) (5th), DevSecOps (2nd)
GitHub Advanced Security
Ranking in Application Security Tools
14th
Average Rating
8.6
Reviews Sentiment
6.5
Number of Reviews
12
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Application Security Tools category, the mindshare of Check Point WAF (formerly CloudGuard WAF) is 1.1%, up from 0.4% compared to the previous year. The mindshare of GitHub Advanced Security is 2.2%, down from 7.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Check Point WAF (formerly CloudGuard WAF)1.1%
GitHub Advanced Security2.2%
Other96.7%
Application Security Tools
 

Featured Reviews

Krishnakumar Mahadevan - PeerSpot reviewer
CISO at Spink Solutions Private Limited
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
Devendiran Kandan - PeerSpot reviewer
DevOps Engineer at a tech vendor with 1,001-5,000 employees
Security scanning has protected our pipelines but currently needs clearer dashboards and controls
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inline product, I'm not seeing user-friendly things in GitHub Advanced Security. Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, before building and deploying the code, we want to block or do an advanced model, but it is not supporting. During deployment, code scanning is not good. It is a little complicated. It is not a straightforward method we can complete. We need expertise to get the full benefit, and troubleshooting sometimes requires going through that. The security overview dashboard is not really clear. It's not showing centralized information; each repo is showing, but if you compare it with competitors, it is not that great. Mainly in the centralized dashboard, enterprise level needs to improve. A centralized way where we can get that overall view is needed, and we want that code scanning and blocking deployments based on security. There are AI improvements, but however, it is not so easy to configure. It is multiple windows we need to go through and make changes or configure that. A few things we need to enable going into settings, and a few things we can find out in security. One product where security means the security dashboard should cover everything, but it is going here and there in many places.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"By using a cloud application security solution, our company can save costs by reducing the need for additional security hardware and software and improving operational efficiency."
"Having a cloud detection response helps to very quickly identify security threats in our environment."
"The features I have found most valuable are the comprehensive threat prevention capabilities, automated policy management, and seamless integration with cloud environments."
"Check Point CloudGuard WAF has been especially helpful here, automatically learning and adjusting protection without requiring constant manual tuning."
"The most valuable features are its ease of use and multiple functionalities."
"The best feature of Check Point CloudGuard WAF is its advanced threat prevention, which is integrated with Check Point threat cloud intelligence providing real-time protection against web application attacks, including zero-day threats, automatically sourced from the threat cloud, Check Point threat intelligence database, analyzing millions of indicators of compromise daily."
"User attitude reviews help us keep all online users compliant with company regulations and policies."
"Ease of deployment and efficiency, particularly for API security, are phenomenal."
"It ensures user passwords or sensitive information are not accidentally exposed in code or reports."
"I have not experienced any performance or stability issues with GitHub Advanced Security."
"It is a stable solution...It is a scalable solution as it can handle new applications along with the analysis part."
"The best features of GitHub Advanced Security are its flexibility and the multiple options it has compared to other tools."
"The product's most valuable features are security scan, dependency scan, and cost-effectiveness."
"GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need."
"GitHub Advanced Security uses artificial intelligence in the backend, specifically CodeQL, to analyze code and provide fewer but more reliable findings, so there are less false positives."
"The most valuable is the developer experience and the extensibility of the overall ecosystem."
 

Cons

"It didn't lower the TCO, it actually raised it, in my opinion."
"We need to have many of the baselines or development guides providing less complex writing or development."
"For now, the product is doing all that I need, however, I need the support of IPv6."
"While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and customizing the user interface and reporting database."
"It was costlier than other solutions."
"You need to know exactly the system. You cannot have someone running the system if they don't have the knowledge to do so."
"Regarding the false positive rate, we need to configure it according to our environment because unless we configure it according to our environment, it's a tedious process, particularly with Check Point WAF (formerly CloudGuard WAF), and sometimes if it's not configured properly, there are more than 60% of false positives that we receive."
"I have encountered issues with Check Point CloudGuard Application Security's technical support. It also has missing configuration features."
"There could be a centralized dashboard to view reports of all the projects on one platform."
"There could be DST features included in the product."
"The report limitations are the main issue."
"Maybe make it compatible with more programming languages. Have a customized ruleset where the end-user can create their own rules for scanning."
"GitHub Advanced Security should look into API security issues, which they currently do not. Additionally, open-source security vulnerabilities are not getting updated in a timely manner."
"An area of GitHub Advanced Security that has room for improvement is customization."
"The customizations are a little bit difficult."
"We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security."
 

Pricing and Cost Advice

"If the pricing for the Infinity platform covers everything, it would be more straightforward. I had a hard time selling it to our CEO as a former CFO because of the differentials. There are different deltas year to year over a five-year period. It is very difficult to explain. It would be easier to digest for our executives if there was a flatter scale"
"It is extremely affordable and high value for cost."
"I find the pricing to be reasonable."
"It is not cheap, but it is worth it."
"The pricing is competitive compared to other solutions on the market. So, the licensing cost is average."
"Check Point CloudGuard Application Security's pricing is comparable to other products in the market."
"Check Point CloudGuard WAF is expensive compared to Azure WAF."
"The tool's licensing costs are yearly and competitive."
"The solution is expensive."
"The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
15%
Computer Software Company
15%
Financial Services Firm
10%
Construction Company
8%
Financial Services Firm
15%
Computer Software Company
9%
Comms Service Provider
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business57
Midsize Enterprise24
Large Enterprise40
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise4
Large Enterprise7
 

Questions from the Community

What is your experience regarding pricing and costs for CloudGuard for Application Security?
It is a little bit expensive, but the pricing model is acceptable, though a reduction would make it more competitive with leaders such as Palo Alto.
What needs improvement with CloudGuard for Application Security?
The false positive rate is a concern, but I could recommend improvements where false positives have to be minimized better. This all depends on how the rules are customized and configured, and it c...
What is your primary use case for CloudGuard for Application Security?
The main purpose is to have network security through machine learning, which can offer threat detection and intelligence for my endpoints, and I am looking for application security. I am looking fo...
What needs improvement with GitHub Advanced Security?
We used additional third-party solutions, but we replaced them with GitHub Advanced Security, even though I do not have a very good opinion about GitHub Advanced Security. Even though it is an inli...
What is your primary use case for GitHub Advanced Security?
I'm working with software development nowadays. As a process, we are using the dependent bot alerts and the code scanning for Java, and some of the code scanning is happening. Security secrets in c...
What advice do you have for others considering GitHub Advanced Security?
Dependent bots and the secret detection are good compared to others. However, code scanning is not finding very good results based on pipeline where it will scan and do code scanning. While build, ...
 

Also Known As

Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec, Check Point CloudGuard Code Security
No data available
 

Overview

 

Sample Customers

Orange España, Paschoalotto
Information Not Available
Find out what your peers are saying about Check Point WAF (formerly CloudGuard WAF) vs. GitHub Advanced Security and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.