No more typing reviews! Try our Samantha, our new voice AI agent.

Check Point WAF (formerly CloudGuard WAF) vs Imperva Application Security Platform comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 16, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Cloudflare WAF offers quick ROI, crucial protection for e-commerce, saves bandwidth, and balances cost with valuable free features.
Sentiment score
6.5
Check Point WAF improves security, reduces costs, and enhances efficiency, offering up to 90% returns and significant time savings.
Sentiment score
6.0
Imperva Application Security Platform offers substantial ROI for frequent attack targets, aiding compliance and cost-efficient protection.
My experience with the pricing or licensing of Cloudflare Web Application Firewall is that many features can be accessed for free, so the pricing is definitely reasonable.
Owner at Hga consulting
When we are attacked, we can understand how important the solution is.
Cyber security manager at a government with 1,001-5,000 employees
When you migrate to the cloud, it feels like saving 90% of your time.
Manager, Managed Security Services at a tech vendor with 51-200 employees
Most of the operations happen in the background, so I do not spend much time on it.
Principal Cybersecurity Specialist at Unitel S.A.
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
Head of Sales Services Department at a comms service provider with 51-200 employees
I was able to save over seven million dollars last year as return on investment in the company.
Senior Cybersecurity Consultant at Cyberoutcome Limited
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Senior Presales Consultant at Techlab security
 

Customer Service

Sentiment score
6.3
Cloudflare WAF support is mixed; responsive for some, but Indian customers face call availability and administrative issues.
Sentiment score
6.2
Check Point's customer service praised for efficiency but criticized for occasional delays and staffing issues, especially on weekends.
Sentiment score
6.9
Imperva's customer service is responsive and helpful, though some experience delays and require escalation for complex issues.
I would rate the technical support with Cloudflare as excellent every time I've had to contact them.
Owner at Hga consulting
The technical support of Cloudflare Web Application Firewall rates between five and seven at maximum.
IT Manager at Amla Commerce
They need to increase the number of people for 24/7 support.
Principal Cybersecurity Specialist at Unitel S.A.
They were responsive even before we committed to buying their solution.
Infrastructure Manager at FPMH
I also received full technical support, especially during the implementation.
Cyber security manager at a government with 1,001-5,000 employees
I would rate the technical support of Imperva DDoS as ten.
Head of Sales Services Department at a comms service provider with 51-200 employees
They need to work faster on the response time because of issues of urgent replies.
Senior Cybersecurity Consultant at Cyberoutcome Limited
The response is satisfactory, though the gaps in enablement and lab sessions are clear.
CTO at Malam Engineering PLC
 

Scalability Issues

Sentiment score
7.7
Cloudflare Web Application Firewall offers impressive scalability and automated management, but additional features may incur costs for smaller organizations.
Sentiment score
7.3
Check Point WAF offers seamless, scalable performance across multi-cloud environments, praised for its elastic scaling and efficient traffic management.
Sentiment score
7.6
Imperva is praised for scalability in cloud environments, though infrastructure compatibility and license costs may pose challenges.
The scalability of Cloudflare Web Application Firewall rates between 8 to 9, as it depends upon the use cases and what exactly the client needs.
IT Manager at Amla Commerce
If I need to scale, I open a Whatsapp group with the director and the team, and we quickly proceed to do so.
Cyber security manager at a government with 1,001-5,000 employees
They have sufficient resources, and there are no challenges from a scalability perspective.
Project Manager at a outsourcing company with 1,001-5,000 employees
Check Point CloudGuard WAF's scalability is very good.
Sr. VP of Creative & Development at a non-tech company with 51-200 employees
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
Head of Sales Services Department at a comms service provider with 51-200 employees
I have not even needed support after deployment, since it has remained stable.
CTO at Malam Engineering PLC
It is easy to always scale to add more users.
Senior Cybersecurity Consultant at Cyberoutcome Limited
 

Stability Issues

Sentiment score
8.2
Cloudflare Web Application Firewall is praised for stability, high performance, effective protection, daily use, and minimal downtime.
Sentiment score
8.1
Check Point WAF delivers high reliability and performance, with minimal issues, often rated 8.5-10 by users.
Sentiment score
7.9
Imperva Application Security Platform is stable and reliable, with minimal downtime and quick resolution of occasional issues.
The stability of Cloudflare Web Application Firewall deserves a perfect 10 out of 10.
IT Manager at Amla Commerce
It is very stable.
Team Leader, Cloudops & Cloud Architect at a consultancy with 501-1,000 employees
It is very stable, never crashing or giving me an error that I can see.
Sysadmin at a government with 501-1,000 employees
I did not have any issues in the last three years during which I had more than ten critical services running on CloudGuard.
Information Technology - Infrastructure and Security at Cyprus Development Bank
It is also a stable product without much glitch or downtime.
Senior Presales Consultant at Techlab security
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
CTO at Malam Engineering PLC
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Room For Improvement

Cloudflare WAF needs feature enhancements, better usability, improved support, advanced DDoS protection, and solutions for latency and alerts.
Check Point WAF needs better latency, cost efficiency, support, integration, documentation, UI, monitoring, API security, and reporting.
Users seek improved UI, lower pricing, enhanced features, better support, and integrations in Imperva Application Security Platform.
The product can improve by having more multitenancy capability, which is currently not available.
Network Architect at a computer software company with 11-50 employees
I think they're doing a good job with DNS and as support for any domains that I create or that my clients create, it's mandatory for me to ensure they have Cloudflare as their DNS provider.
Owner at Hga consulting
And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network.
CTO at PlayNirvana
The provider could improve by providing better guidance and support during the configuration process.
Infrastructure Manager at FPMH
Future releases should include better bot mitigation, behavioral anomaly detection, compliance templates, advanced threat intel integration, and streamlined multi-cloud support to boost protection and usability.
Senior Cyber Security Engineer at a computer software company with 501-1,000 employees
A machine learning-based adaptive mode could help the WAF learn over time and auto-tune policies.
Technical Support Executive at a computer software company with 501-1,000 employees
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
CTO at Malam Engineering PLC
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Head of Sales Services Department at a comms service provider with 51-200 employees
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Senior Presales Consultant at Techlab security
 

Setup Cost

Cloudflare Web Application Firewall offers affordable, flexible pricing with no upfront costs, noted for competitiveness and included support services.
Check Point WAF is costly yet justified by features, with mixed views on pricing compared to competitors like Azure WAF.
Imperva's pricing varies by features and deployment, often seen as complex and costly, impacting adoption in sensitive markets.
It is more expensive than f5, where we purchased everything as bundles, and Check Point costs more, but it is worth the money.
Cyber security manager at a government with 1,001-5,000 employees
It is less costly than Cloudflare, Fortinet, and other vendors.
Project Manager at a outsourcing company with 1,001-5,000 employees
I know that its price is relatively expensive compared to other products but it gives benefits that are worth it.
Ciso at a government with 1,001-5,000 employees
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
Head of Sales Services Department at a comms service provider with 51-200 employees
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
Senior Cybersecurity Consultant at Cyberoutcome Limited
 

Valuable Features

Cloudflare Web Application Firewall provides comprehensive security features, easy setup, scalability, and competitive pricing with praised performance and stability.
Check Point WAF offers AI-driven threat prevention, DDoS protection, API security, and seamless integration to enhance application protection.
Imperva offers comprehensive web threat protection with an intuitive interface, advanced analytics, and seamless integration for simplified application security.
The custom rules and the geo-redundant geographical rule feature, which allows me to implement geographical rules for customers, add significant value.
Network Architect at a computer software company with 11-50 employees
The best features of Cloudflare Web Application Firewall are multiple, including the WAF, rate limiter, and bot attack protection.
IT Manager at Amla Commerce
Cloudflare Web Application Firewall's advanced reporting and analytics tools add a layer that we're able to visualize and see before it actually hits the local firewall.
Owner at Hga consulting
Upon implementation and evaluation with third-party penetration testing, it meets rigorous security standards required for dealing with financial institutions.
Infrastructure Manager at FPMH
It can protect against zero-day attacks and hidden anomalies.
Amministratore Della Sicurezza Di Rete at a government with 1,001-5,000 employees
The solution preemptively blocks zero-day attacks and detects hidden anomalies effectively.
Information Technology - Infrastructure and Security at Cyprus Development Bank
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
Senior Cybersecurity Consultant at Cyberoutcome Limited
I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website.
Head of Sales Services Department at a comms service provider with 51-200 employees
I believe the reputational analysis in Imperva Application Security Platform is effective for blocking security threats before impact.
Senior Presales Consultant at Techlab security
 

Categories and Ranking

Cloudflare Web Application ...
Sponsored
Ranking in Web Application Firewall (WAF)
6th
Average Rating
8.6
Reviews Sentiment
7.4
Number of Reviews
26
Ranking in other categories
No ranking in other categories
Check Point WAF (formerly C...
Ranking in Web Application Firewall (WAF)
8th
Average Rating
8.8
Reviews Sentiment
7.1
Number of Reviews
56
Ranking in other categories
Application Security Tools (5th)
Imperva Application Securit...
Ranking in Web Application Firewall (WAF)
3rd
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
136
Ranking in other categories
CDN (3rd), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st), API Security (2nd)
 

Mindshare comparison

As of April 2026, in the Web Application Firewall (WAF) category, the mindshare of Cloudflare Web Application Firewall is 4.7%, down from 7.2% compared to the previous year. The mindshare of Check Point WAF (formerly CloudGuard WAF) is 2.4%, up from 1.3% compared to the previous year. The mindshare of Imperva Application Security Platform is 7.6%, up from 7.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
Imperva Application Security Platform7.6%
Cloudflare Web Application Firewall4.7%
Check Point CloudGuard WAF2.4%
Other85.3%
Web Application Firewall (WAF)
 

Featured Reviews

DB
CTO at PlayNirvana
Advanced security reporting has protected high-traffic betting platforms from constant attacks
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we have a dedicated IT team for that, and I'm not involved with Cloudflare much anymore. But if I were to compare them to F5, I would like to see more features that F5 offers. F5 has an option to bring the whole infrastructure, the whole WAF and all their packages, Bot Management, and everything else on your infrastructure. You need to install certain services from their side, and then you can choose if you would like requests to hit your servers immediately or if requests need to be proxied through F5 backbone. That would be a nice addition because we have 90% of the traffic as legit traffic coming from whitelisted servers. If it comes from whitelisted servers, I don't need to go every request through the backbone; I could easily just IP whitelist everything. Then I could maybe have Bot Management on my infrastructure that drastically reduces the price of Cloudflare. I would like to see Push CDN more improved in the next release of Cloudflare Web Application Firewall. And maybe something similar to Pushpin that Fastly has, which is an option where you can push messages that then can be scaled globally over the network. From our perspective, if we have a listener that listens for stock updates, I would just need to have one processor that pushes those updates to the Cloudflare API, and then Cloudflare would broadcast that message to all listeners. Cloudflare will check the order of the message, and if you, as a customer, are not connected or have some kind of network issue, when you reconnect, you will receive the latest state and missing updates.
MK
CISO at Pink Solutions
Cloud security has strengthened risk posture and improved advanced threat visibility
There are some API gateway and API securities I mentioned. If these are incorporated with AI-related features, particularly those seven key vulnerabilities I mentioned—token theft and tool poisoning—that would be beneficial. AI-related features are not included yet in Check Point CloudGuard WAF. However, they are present in FortiGate. That is the advantage of FortiGate now. FortiGate is stopping all AI-related vulnerabilities now. FortiGate has this capability. It is unfortunate that even Palo Alto also lacks one or two of these features. Check Point Quantum is very good, without a doubt. However, their capabilities are not in comparison with Palo Alto. There are some features, but there are some gaps in comparison with Palo Alto.
ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.
report
Use our free recommendation engine to learn which Web Application Firewall (WAF) solutions are best for your needs.
886,719 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
17%
Financial Services Firm
9%
Comms Service Provider
8%
Computer Software Company
8%
Computer Software Company
26%
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
5%
Financial Services Firm
12%
Manufacturing Company
8%
Computer Software Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business16
Midsize Enterprise6
Large Enterprise6
By reviewers
Company SizeCount
Small Business35
Midsize Enterprise20
Large Enterprise19
By reviewers
Company SizeCount
Small Business84
Midsize Enterprise25
Large Enterprise62
 

Questions from the Community

What needs improvement with Cloudflare Web Application Firewall?
I don't see room for improvement to Cloudflare Web Application Firewall. One thing I don't know much about because we...
What is your primary use case for Cloudflare Web Application Firewall?
We are using Cloudflare Web Application Firewall's advanced reporting and analytics tools with their Zero Trust, so e...
What is your experience regarding pricing and costs for CloudGuard for Application Security?
Check Point CloudGuard WAF is expensive. It is a little bit expensive. You cannot avoid this from an Israeli product....
What needs improvement with CloudGuard for Application Security?
While Check Point CloudGuard WAF is a strong solution, it could be improved in a few areas such as simplifying and cu...
What is your primary use case for CloudGuard for Application Security?
Check Point CloudGuard WAF's primary use is protecting web applications and APIs from application layer attacks in th...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
 

Also Known As

Cloudflare WAF
Check Point CloudGuard Application Security, CloudGuard Application Security, CloudGuard AppSec
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

crunchbase, udacity, marketo, okcupid, zendesk
Orange España, Paschoalotto
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about Check Point WAF (formerly CloudGuard WAF) vs. Imperva Application Security Platform and other solutions. Updated: April 2026.
886,719 professionals have used our research since 2012.