Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Fortify WebInspect vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Application Security Tools
Dynamic Application Security Testing (DAST)
Static Application Security Testing (SAST)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…
Amit Beniwal - PeerSpot reviewer
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The value you can get out of the speedy production may be worth the price tag."
"The UI is very intuitive and simple to use."
"The solution is scalable, but other solutions are better."
"The solution allows us to create custom rules for code checks."
"Vulnerability details is valuable."
"It has all the features we need."
"The user interface is modern and nice to use."
"I have seen a return on investment from Checkmarx One."
"The most valuable feature is the static analysis."
"The user interface is ok and it is very simple to use."
"The tool provides comprehensive vulnerability assessments which help ensure our deliverables are as free from vulnerabilities as possible. It has also streamlined our web application vulnerability assessments, assisting us in delivering secure applications to our clients."
"The solution's technical support was very helpful."
"It's a well-known platform for doing dynamic application scanning."
"The transaction recorder within WebInspect is easy to use, which is valuable for our team."
"The accuracy of its scans is great."
"Guided Scan option allows us to easily scan and share reports."
"The API is exceptional."
"Simple and easy to learn and master."
"The vulnerabilities that it finds, because the primary goal is to secure applications and websites."
"OWASP is quite matured in identifying the vulnerabilities."
"OWASP Zap is straightforward to use. If someone doesn't have the budget for tools like Burp Suite, OWASP Zap is an excellent alternative."
"The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, it's very difficult."
"One valuable feature of OWASP Zap is that it is simple to use."
"They offer free access to some other tools."
 

Cons

"Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"Checkmarx could improve the REST APIs by including automation."
"Checkmarx could be improved with more integration with third-party software."
"I would like to see the rate of false positives reduced."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"Meta data is always needed."
"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"Creating reports is very slow and it is something that should be improved."
"Lately, we've seen more false negatives."
"The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate."
"Fortify WebInspect could improve user-friendliness. Additionally, it is very bulky to use."
"I would like WebInspect's scanning capability to be quicker."
"We have often encountered scanning errors."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"ZAP's integration with cloud-based CICD pipelines could be better. The scan should run through the entire pipeline."
"When comparing OWASP Zap and Burp Suite, the main difference besides pricing is that OWASP Zap has limitations with reporting levels and UI, which affects its reporting capabilities, whereas Burp Suite is already advancing with new AI features and scanning capabilities that OWASP Zap seems to be lacking."
"The technical support team must be proactive."
"OWASP Zap needs to extend to mobile application testing."
"There's very little documentation that comes with OWASP Zap."
"The forced browse has been incorporated into the program and it is resource-intensive."
"Reporting format has no output, is cluttered and very long."
"The port scanner is a little too slow.​"
 

Pricing and Cost Advice

"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"For around 250 users or committers, the cost is approximately $500,000."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"The tool's pricing is fine."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"The price is okay."
"The pricing is not clear and while it is not high, it is difficult to understand."
"It’s a fair price for the solution."
"This solution is very expensive."
"Fortify WebInspect is a very expensive product."
"This app is completely free and open source. So there is no question about any pricing."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"We have used the freeware version. I believe Zap only has freeware."
"The solution’s pricing is high."
"It's free and open, currently under the Apache 2 license. If ZAP does what you need it to do, selling a free solution is a very easy."
"This is an open-source solution and can be used free of charge."
"It is open source, and we can scan freely."
"OWASP Zap is free to use."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
855,266 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
17%
Government
14%
Manufacturing Company
12%
Computer Software Company
12%
Computer Software Company
18%
Financial Services Firm
12%
Manufacturing Company
8%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
The price of Fortify WebInspect is high, with the cost depending on the number of virtual users. It is approximately ...
What needs improvement with Fortify WebInspect?
The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate. The ...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan web...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
 

Also Known As

No data available
Micro Focus WebInspect, WebInspect
No data available
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Aaron's
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: May 2025.
855,266 professionals have used our research since 2012.