Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Fortinet FortiDDoS vs Imperva Application Security Platform comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Application Security Tools Market Share Distribution
ProductMarket Share (%)
Checkmarx One9.9%
SonarQube16.9%
Snyk5.6%
Other67.6%
Application Security Tools
Distributed Denial-of-Service (DDoS) Protection Market Share Distribution
ProductMarket Share (%)
Fortinet FortiDDoS2.3%
Cloudflare16.6%
Arbor DDoS9.3%
Other71.8%
Distributed Denial-of-Service (DDoS) Protection
Distributed Denial-of-Service (DDoS) Protection Market Share Distribution
ProductMarket Share (%)
Imperva Application Security Platform8.2%
Cloudflare16.6%
Arbor DDoS9.3%
Other65.9%
Distributed Denial-of-Service (DDoS) Protection
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
MO
IT Analyst at Evapco, Inc.
Reliable protection and smooth setup enhance company security
Currently, I have two firewalls, with one located in Sorocaba, model 90D, and the other in São Paulo, model 30D. They are connected by VPN. I use the firewalls for VPN and final protection for my company, and my equipment is maintained by an internet company called Multiprox The equipment works…
reviewer1247523 - PeerSpot reviewer
Head of Sales Services Department at a comms service provider with 51-200 employees
Solution ensures website availability and proactive threat mitigation
Over the seven years, the most valuable features of Imperva DDoS that I have found are related to DDoS attacks, which are a group of attacks, and not all of them can be resolved on the endpoint level before the website. Using the web firewall before the website is a common use case to protect against malicious requests to the website. I have utilized Imperva's Intelligent Traffic Filtering feature. This feature helps me understand how the attack is progressing and what is happening inside the requests to our website. It allows me to granularly grant or deny access to certain parts of our website. This helps when we know our customers and the types of requests that can be sent from them, enabling us to block some malicious requests. Imperva DDoS has User Behavior Analytics and Threat Intelligence on its board, and this helps us to be protected proactively. Imperva DDoS connects to its database of threats, storing whole information about attacks all over the world in one simple engine. Everyone can use this feature, which can connect to this engine and get information about what is going on at the world level. That is the way to be protected at the company's level. The integration capabilities of Imperva DDoS are very easy and simple. We can run it in 2 hours.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Less false positive errors as compared to any other solution."
"Both automatic and manual code review (CxQL) are valuable."
"The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects."
"Checkmarx One has positively impacted my organization, especially in our CI/CD integration, where when we try to build any feature, they are always scanned by Checkmarx before they get released."
"We use the solution for dynamic application testing."
"Checkmarx One has positively impacted our organization as we tend to find vulnerabilities very early in the development cycle."
"It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
"The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
"The solution is very user-friendly and very easy to use."
"The most valuable feature is the cloud DDoS scrubbing capability."
"This solution can protect Layer 3, Layer 4 and Layer 7 attacks of applications for us."
"It allows me to see all the traffic on my network."
"The equipment works very well, and I have not encountered any issues with it. It is a good solution for my company."
"The equipment works very well, and I have not encountered any issues with it."
"The product allows the users to adjust the thresholds."
"The product's initial setup phase was really easy."
"Imperva has a complete picture of how the applications are utilizing it. It is handy. DDoS is good. It has an internally managed database. It is very easy to integrate. We have integrated it with SIEM services."
"They're quite easy to install and quite easy to set up. Clients really like that. Especially when you're dealing with the cloud, it's really easy."
"The features I have found most valuable with Imperva Web Application Firewall are account takeover protection, advanced bot protection, and API security."
"Simplifies putting everything in code."
"It has threat intelligence and we are using Incapsula. With threat intelligence, we can separate HTTP and HTTPS traffic. We can use Incapsula to send all the threat intelligence to the WAF."
"Compared to other web application firewalls in the market, Imperva does things in the most accurate way."
"The compliance is the most valuable aspect."
"It's very pretty easy to onboard the URL."
 

Cons

"This product requires you to create your own rulesets. You have to do a lot of customization."
"Checkmarx One is often down when the cloud provider experiences issues. A more fail-tolerant solution needs to be created."
"Checkmarx being Windows only is a hindrance. Another problem is: why can't I choose PostgreSQL?"
"The pricing can get a bit expensive, depending on the company's size."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"Its user interface could be improved and made more friendly."
"If it is a very large code base then we have a problem where we cannot scan it."
"I would like to see analytics, big data."
"There aren't really any aspects of the solution we are unhappy with. It's been a positive experience overall."
"The main improvement would be to change the firewall model, however, currently, everything is fixed and working well."
"Alerts and reporting features must be improved."
"The solution can be a little more user-friendly and it can be more affordable."
"The web interface could be much better."
"The challenge lies within the customer environment, particularly in Brazil, where companies have stringent security requirements for implementing solutions."
"The primary area for improvement is the on-premises capacity limit, currently fixed at 10 GB."
"Imperva Web Application Firewall can improve by providing better features, such as improved prevention of zero-day attacks. Additionally, it should include a VR meta-analysis."
"The log analytics interface within Incapsula isn't really good. For example, if you have to get all logs from there, it's a very cumbersome process."
"Sometimes, it takes a bit of time for the technical staff of the solution to get back to our company with a resolution for our problems."
"I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators of compromise."
"The tool needs to improve CPU and storage memory."
"It should be more user-friendly. Like other web solutions, it would be helpful to be able to easily do policy configuration and identification inside the application. Understanding the in-depth configuration of a policy is somewhat difficult for an engineer, and they can improve that."
"I don't really use it and therefore can't speak to areas of improvement."
"Support is one thing I wish Imperva could improve."
 

Pricing and Cost Advice

"The solution's price is high and you pay based on the number of users."
"The tool's pricing is fine."
"It is a good product but a little overpriced."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"We have purchased an annual license to use this solution. The price is reasonable."
"The number of users and coverage for languages will have an impact on the cost of the license."
"For around 250 users or committers, the cost is approximately $500,000."
"The product’s pricing needs improvement."
"The solution is reasonably priced."
"It's quite pricey."
"The cost is on par with other solutions such as Cloudflare and Akamai."
"The price of Imperva Web Application Firewalls is expensive compared to others."
"The price is high compared to other solutions like FortiWeb."
"The pricing is somewhat expensive. It is actually a huge investment when compared to other countries."
"The data packages are higher than our needs so we end up paying for data that we don't use."
"On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing a five out of ten."
"The tool's pricing is good."
"Imperva Web Application Firewall is expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
881,757 professionals have used our research since 2012.
 

Comparison Review

it_user68487 - PeerSpot reviewer
Security Expert with 51-200 employees
Nov 6, 2013
CloudFlare vs Incapsula: Web Application Firewall
CloudFlare vs Incapsula: Round 2 Web Application Firewall Comparative Penetration Testing Analysis Report v1.0 Summary This document contains the results of a second comparative penetration test conducted by a team of security specialists at Zero Science Lab against two cloud-based Web…
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Computer Software Company
10%
Manufacturing Company
10%
Government
5%
Manufacturing Company
12%
Comms Service Provider
10%
Financial Services Firm
9%
Government
7%
Financial Services Firm
12%
Computer Software Company
9%
Manufacturing Company
9%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
By reviewers
Company SizeCount
Small Business10
Large Enterprise6
By reviewers
Company SizeCount
Small Business83
Midsize Enterprise25
Large Enterprise61
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additi...
Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Arbor would be the best bid, apart from Arbor, Palo Alto and Fortinet have good solutions. As this is an ISP, I would...
What is your experience regarding pricing and costs for Fortinet FortiDDoS?
Fortinet FortiDDoS offers lower costs compared to other solutions. The licensing costs are annually renewed.
What needs improvement with Fortinet FortiDDoS?
There is a need for more features that protect personal information, especially given the PDP issue in Indonesia.
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What do you like most about Imperva Incapsula?
We use Imperva DDoS to stop DDoS attacks and reduce the amount of unwanted queries against web services or web scraping.
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
 

Also Known As

No data available
Fortinet DDoS, FortiDDos
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Black Gold Regional Schools, Amadeus Hospitality, Jefferson County, Chunghwa Telecom, City of Boroondara, Dimension Data
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Application Security Tools. Updated: February 2026.
881,757 professionals have used our research since 2012.