Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs HCL AppScan vs OpenText Dynamic Application Security Testing comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Application Security Tools
Application Security Tools
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Sthembiso Zondi - PeerSpot reviewer
Has a straightforward setup process and valuable security features
We use AppScan primarily for security testing and performance monitoring across our systems The product's features for comprehensive code analysis (static) and live environment testing (dynamic) have significantly enhanced our ability to identify and address vulnerabilities, improving overall…
Navin N - PeerSpot reviewer
Effective scanning of diverse file extensions with fast reporting and issue resolution
We develop software packages for clients, and these clients are mostly in the BFSI sector. The packages need to be scanned, and we engage Fortify WebInspect for this.  Customers typically perform their own application pen tests, but in some cases, we have engagements where customers want us to scan…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"The most valuable feature is the application tracking reporting."
"The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
"The SAST component was absolutely 100% stable."
"The main advantage of this solution is its centralized reporting functionality, which lets us track issues, then see and report on the priorities via a web portal."
"Vulnerability details is valuable."
"The most valuable feature for me is the Jenkins Plugin."
"The solution is cheap."
"The most valuable feature of HCL AppScan is scanning QR codes."
"The platform has valuable security features, helping us identify sensitive code issues and the possibility of internal applications' exposure to external threats."
"We leverage it as a quality check against code."
"The most valuable feature of the solution is the scanning or security part."
"It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings."
"Usually when we deploy the application, there is a process for ethical hacking. The main benefit is that, the ethical hacking is almost clean, every time. So it's less cost, less effort, less time to production."
"AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further."
"Reporting, centralized dashboard, and bird's eye view of all vulnerabilities are the most valuable features."
"Guided Scan option allows us to easily scan and share reports."
"It is scalable and very easy to use."
"The most valuable feature is the static analysis."
"The accuracy of its scans is great."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
 

Cons

"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"Licensing models and Swift language support are the aspects in which this product needs to improve. Swift is a new language, in which major customers require support for lower prices."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"Checkmarx needs to be more scalable for large enterprise companies."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe. It would help if there was more scanning or if the process was more automated."
"I would like to see the tool’s pricing improved."
"Micro-services need to be included in the next release."
"There is room for improvement in the pricing model."
"The solution's scalability can be a matter of concern because one license runs on one machine only."
"I think being able to search across more containers, especially some of the docker elements. We need a little tighter integration there. That's the only thing I can see at this point."
"The solution needs to improve in some areas. The tool needs to add more languages. It also needs to improve its speed."
"AppScan needs to improve its handling of false positives."
"We have experienced challenges when trying to integrate this solution with other products. When you compare it with the other SecOps products, the quality of the output is too low. It is not a new-age product. It is very outdated."
"The solution could improve by having a mobile version."
"They should have a better UI for dashboards."
"I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
"It requires improvement in terms of scanning. The application scan heavily utilizes the resources of an on-premise server. 32 GB RAM is very high for an enterprise web application."
"One thing I would like to see them introduce is a cloud-based platform."
"We have had a problem with authentification."
"Fortify WebInspect could improve user-friendliness. Additionally, it is very bulky to use."
"The scanner could be better."
"Lately, we've seen more false negatives."
"A localized version, for example, in Korean would be a big improvement to this solution."
 

Pricing and Cost Advice

"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"It is an expensive solution."
"The interface used to create custom rules comes at an additional cost."
"We have purchased an annual license to use this solution. The price is reasonable."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"I believe pricing is better compared to other commercial tools."
"I rate the product's price a seven on a scale of one to ten, where one is low, and ten is high. HCL AppScan is an expensive tool."
"The tool was expensive."
"Pricing was the main reason that we went ahead with this solution as they were the lowest in the market."
"The solution is moderately priced."
"HCL AppScan is expensive."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"The solution is cheap."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"This solution is very expensive."
"Fortify WebInspect is a very expensive product."
"The pricing is not clear and while it is not high, it is difficult to understand."
"It’s a fair price for the solution."
"The price is okay."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
862,624 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Computer Software Company
17%
Financial Services Firm
13%
Government
10%
Manufacturing Company
10%
Financial Services Firm
15%
Government
15%
Manufacturing Company
12%
Computer Software Company
12%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as ...
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar ...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We us...
What do you like most about Fortify WebInspect?
The solution's technical support was very helpful.
What is your experience regarding pricing and costs for Fortify WebInspect?
The price of Fortify WebInspect is high, with the cost depending on the number of virtual users. It is approximately ...
What needs improvement with Fortify WebInspect?
The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate. The ...
 

Also Known As

No data available
IBM Security AppScan, Rational AppScan, AppScan
Micro Focus WebInspect, WebInspect
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
Aaron's
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: July 2025.
862,624 professionals have used our research since 2012.