No more typing reviews! Try our Samantha, our new voice AI agent.

Checkmarx One vs Cloudflare vs Imperva Application Security Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.6
Checkmarx One enhances security by automating vulnerability detection, reducing costs, and improving development efficiency through CI/CD integration.
Sentiment score
6.2
Cloudflare's services enhanced security and efficiency, resulting in significant ROI, cost savings, and improved WordPress performance for businesses.
Sentiment score
6.0
Imperva enhances security, reduces costs, prevents downtime, and offers high ROI, compliance benefits, and traffic optimization for public portals.
Overall, between the fast scanning, automation, automatic reporting, and easy detection, it has reduced manual effort enough that we did not need an extra reviewer, even as our codebase or team size grew.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
Based on my interactions with the clients, I can tell that there is a return on investment because if something is not profitable and it's not helping to save costs or vulnerabilities, clients wouldn't come back to renew their license year after year.
Chief Technology Officer at 3CS Aquarah Limited
For the small project I was working on, using the basic tier provided a huge improvement at zero cost.
Security Specialist at a tech services company with 1,001-5,000 employees
In terms of return on investment with Cloudflare, it costs my time to set them up, but basically once they're set up, it's done.
Owner at Hga consulting
The return on investment for me is significant as time is the critical aspect.
Senior Network and Security Expert at a financial services firm with 201-500 employees
They know how much money they are losing while the system is down, so by increasing the possibility of not having a down website or web application, return on investment can be calculated easily.
Head of Sales Services Department at a comms service provider with 51-200 employees
I was able to save over seven million dollars last year as return on investment in the company.
Senior Cybersecurity Consultant at Cyberoutcome Limited
I have seen a return on investment with Imperva Application Security Platform, as it is generally associated with time savings, because the review of alerts and the visibility it gives saves us significant operational time.
Ingeniero Preventa at Imperia
 

Customer Service

Sentiment score
7.0
Checkmarx One support is praised for quick responses and knowledgeable staff, despite some reporting delays in technical support.
Sentiment score
6.9
Cloudflare's support is responsive and knowledgeable, with varying experiences depending on the plan and need for faster escalation.
Sentiment score
7.0
Imperva's customer service is praised for effectiveness and professionalism, though improvements in initial support and response times are suggested.
If you raise a support case with Checkmarx, it is handled smoothly.
Senior Specialist at a tech vendor with 10,001+ employees
The customer support team is amazing and they provide on-phone call, email support, and on-website support.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
I have relied on Checkmarx One customer support hundreds of times for several things, and Checkmarx One support is very proactive and very responsive.
Chief Technology Officer at 3CS Aquarah Limited
Cloudflare does not offer hands-on technical support to fix customer problems but rather a self-service model.
Senior Consultant CDN at a comms service provider with 10,001+ employees
I would rate the technical support with Cloudflare as excellent every time I've had to call them.
Owner at Hga consulting
We use other solutions where support is available through Slack channels and is more interactive, with someone responding within a couple of minutes or seconds.
General Manager at bKash Limited
I would rate the technical support of Imperva DDoS as ten.
Head of Sales Services Department at a comms service provider with 51-200 employees
They need to work faster on the response time because of issues of urgent replies.
Senior Cybersecurity Consultant at Cyberoutcome Limited
Responsive support addressing urgent needs.
Cybersecurity Consultant at Accenture Singapore Services Pte Ltd
 

Scalability Issues

Sentiment score
7.0
Checkmarx One is scalable for large workloads, but some users report challenges with configurations and licensing requirements.
Sentiment score
7.9
Cloudflare excels in scalability, supporting seamless transitions and performance during high-traffic periods, highly rated by users.
Sentiment score
7.5
Imperva excels in scalable security with efficient traffic handling, though custom SSL costs and on-premise expansion present challenges.
Approximately four billion lines of code are being scanned monthly.
Cyber Security Expert at Nestle
Since it is cloud-based, the infrastructure and PaaS, IaaS, and SaaS are taken care of by the cloud marketplace.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Checkmarx One's scalability has changed my organization because the strong collaboration between the development and security team helps us to do things much faster.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
It is a SaaS tool, but the fact that they have workloads deployed across the world proves that it is a highly scalable tool.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
The tool offers very good performance, even during high-traffic periods.
Engineer at SITMEXICO
Cloudflare's scalability is quite good; it is very easy to scale whenever we want to include multiple domains.
Senior Network and Security Expert at a financial services firm with 201-500 employees
99% of customers are using the cloud version of Imperva DDoS protection, so they just purchase the new license and scale as needed.
Head of Sales Services Department at a comms service provider with 51-200 employees
I have not even needed support after deployment, since it has remained stable.
CTO at Malam Engineering PLC
It is easy to always scale to add more users.
Senior Cybersecurity Consultant at Cyberoutcome Limited
 

Stability Issues

Sentiment score
7.3
Checkmarx One is generally stable but faces issues with large codebases, memory use, and session inconsistencies.
Sentiment score
7.5
Cloudflare is reliable with high stability ratings, minimal issues, improved network connectivity, and praised fast DNS services.
Sentiment score
7.9
Imperva Application Security Platform is praised for its stability, reliability, and robust performance, with high customer ratings.
I would rate the stability of this solution a nine on a scale of 1 to 10 where one is low stability and 10 is high.
Specialist Leader at Deloitte
Checkmarx One is often down when the cloud provider experiences issues.
Cyber Security Expert at Nestle
The service is very stable with no impacts during high-traffic periods.
Engineer at SITMEXICO
Cloudflare's reliability and uptime has met my expectations; it has been quite good in general.
Senior Network and Security Expert at a financial services firm with 201-500 employees
It is also a stable product without much glitch or downtime.
Senior Presales Consultant at Techlab security
One notable drawback is that, unlike Fortinet, which offers fast track labs and continuous enablement, Imperva Application Security Platform lacks lab access and fast track labs for enablement and product advertising.
CTO at Malam Engineering PLC
The stability of Imperva DDoS is very good, as it seems they have a lot of servers around the world.
Head of Sales Services Department at a comms service provider with 51-200 employees
 

Room For Improvement

Checkmarx One needs enhancements in accuracy, speed, integration, UI, support, pricing, and features for enterprise usability.
Users suggest improvements in Cloudflare's features, pricing, support, analytics, documentation, and partner relations for better service experience.
Imperva needs improved AI, integration, pricing, user interface, licensing, and bot protection to enhance security features and customer experience.
Integration into the IDE being used would be beneficial so that code does not need to be uploaded to the website and an IDE-friendly report could be generated.
Senior Software Engineer at a financial services firm with 10,001+ employees
It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from.
Specialist Leader at Deloitte
If you can improve the speed optimization, it takes around 30 to 40 minutes for checking a build. If you can make it within five minutes or 10 minutes, that would be great.
Senior Software Engineer at Tech Mahindra Limited
Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements.
General Manager at bKash Limited
There are some performance considerations when it comes to dynamic content that involves fetching data from databases or using APIs.
Senior Solutions Architect at Think Power Solutions
What Cloudflare is doing internally is that it is stepping ahead in areas like detection and protection.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
To convince my clients, a purely on-prem solution would be ideal since they are financial institutions.
CTO at Malam Engineering PLC
Maybe Imperva DDoS could use endpoints to get information about the attacks before they commence from the endpoint level or establish cooperation with endpoint vendors to share this information.
Head of Sales Services Department at a comms service provider with 51-200 employees
Regarding return on investment, ROI, I can say it is noticeable with Imperva Application Security Platform.
Senior Presales Consultant at Techlab security
 

Setup Cost

Checkmarx One is often costly but provides quality and security, with costs varying by team size and selected modules.
Cloudflare provides cost-effective, feature-rich plans for varying traffic needs, offering significant value compared to competitors like Akamai.
Imperva's pricing is complex and costly, with significant expenses, especially affecting smaller enterprises, despite some competitive options.
For a small team under 50 developers, normal expenses come under 30 to 60K.
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Due to the number of years I've implemented Checkmarx One, there are rebates and discounts from the OEM which makes it a lot more profitable.
Chief Technology Officer at 3CS Aquarah Limited
The pricing should be reasonable, matching what we are paying for.
Senior GenAI Engineer at a tech vendor with 10,001+ employees
I find it to be cheap.
Engineer at SITMEXICO
I rate the product’s pricing a five out of ten, where one is cheap, and ten is expensive.
Senior Solutions Architect at Think Power Solutions
The tool is a premium product, so it is very expensive.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
I would rate the pricing of Imperva DDoS as five, where one is very cheap and ten is very expensive.
Head of Sales Services Department at a comms service provider with 51-200 employees
the setup cost was high, with the hardware installation in the data center being particularly expensive.
Cyber Security Product Owner at a energy/utilities company with 10,001+ employees
We have noticed faster response times and fewer security alerts because after doing some custom policy tuning, everything seemed to be aligned and we have fewer attacks to monitor and fewer alerts to monitor.
Senior Cybersecurity Consultant at Cyberoutcome Limited
 

Valuable Features

Checkmarx One offers comprehensive vulnerability scanning, seamless CI/CD integration, and enhances productivity with ease of use and automation.
Cloudflare offers superior caching, DNS management, and security, enhancing performance, global reach, and domain management with innovative features.
Imperva Application Security Platform offers effective threat mitigation, real-time intelligence, and robust API security, enhancing compliance and reducing vulnerabilities.
Since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days.
Cyber Security Expert at Nestle
The best features Checkmarx One offers, over the past years, include broad language and technical support that Checkmarx provides, covering most languages.
Senior Specialist at a tech vendor with 10,001+ employees
Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle.
Product security engineer at a tech vendor with 10,001+ employees
Techniques like minification and image compression reduce the size of assets, leading to better performance and faster user load times.
Senior Solutions Architect at Think Power Solutions
The solution has been able to compare it to the market, and I think the product has taken great strides in automating quite a bit of things, and they use a lot of AI.
Principal Cyber Prevent and Defense Engineer at a comms service provider with 1,001-5,000 employees
Most of our DNS records that are presented to the internet are proxied whenever possible, providing another layer of defense from our perspective.
Senior Security Engineer at ManpowerGroup
The API security feature is particularly valuable because most attackers do not try to come in from where it is expected.
Senior Cybersecurity Consultant at Cyberoutcome Limited
If someone attempts to access the server, the WAF blocks that SSRF alert, or RCE, Remote Code Execution alert, blocking immediately based on the signature, not only by the payload or the IP address.
SOC Analyst L1 at CMS-IT-SERVICES-PVT-LTD
It reduces the DDoS attacks and reduces the attacks from threat actors, including SQL Injection and zero-day attacks, by using dynamic application profiling from Imperva.
IT Security Analyst & Engineer (Project, Remote) Australia-Europe at a manufacturing company with 10,001+ employees
 

Mindshare comparison

Application Security Tools Mindshare Distribution
ProductMindshare (%)
Checkmarx One8.8%
SonarQube13.6%
Snyk5.1%
Other72.5%
Application Security Tools
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Cloudflare14.0%
Imperva Application Security Platform8.5%
Arbor DDoS7.2%
Other70.3%
Distributed Denial-of-Service (DDoS) Protection
Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Imperva Application Security Platform8.5%
Cloudflare14.0%
Arbor DDoS7.2%
Other70.3%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
reviewer2818155 - PeerSpot reviewer
Senior Associate at a tech vendor with 10,001+ employees
Application protection has improved and reporting and dashboards still need refinement
I believe Imperva Application Security Platform should have a more interactive wizard. While the dashboard is good, it could be more eye-catching. Based on my perspective, I recommend modifying the dashboards, especially the main dashboard where I can see the traffic hit count, alerts, and other latest information. In terms of reporting, I find it challenging to create reports; in my earlier days, it was difficult. Over time, I have learned how to create reports, but it should be easier to do so. I have used other tools such as firewalls or SolarWinds, where creating a report is straightforward and does not take much time, unlike in Imperva, where I have to add many elements. Modifications in the integration aspects would also be beneficial.
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
894,807 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Manufacturing Company
9%
Computer Software Company
8%
Government
5%
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
8%
Manufacturing Company
8%
Financial Services Firm
12%
Manufacturing Company
8%
Computer Software Company
7%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise11
Large Enterprise26
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise25
Large Enterprise69
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additi...
What needs improvement with Checkmarx?
One way Checkmarx One could be improved is if it could automatically run scans every month after implementation. If i...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What is your experience regarding pricing and costs for Cloudflare?
The tool's pricing is moderate. I rate the product’s pricing a five out of ten, where one is cheap, and ten is expens...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
 

Also Known As

No data available
Cloudflare DNS
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: May 2026.
894,807 professionals have used our research since 2012.