Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Imperva Web Application Firewall comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), Static Code Analysis (3rd), API Security (5th), DevSecOps (5th), Risk-Based Vulnerability Management (9th)
Imperva Web Application Fir...
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Web Application Firewall (WAF) (7th)
 

Mindshare comparison

Checkmarx One and Imperva Web Application Firewall aren’t in the same category and serve different purposes. Checkmarx One is designed for Application Security Tools and holds a mindshare of 9.9%, down 14.3% compared to last year.
Imperva Web Application Firewall, on the other hand, focuses on Web Application Firewall (WAF), holds 5.6% mindshare, down 6.6% since last year.
Application Security Tools
Web Application Firewall (WAF)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Mitesh D Patel - PeerSpot reviewer
Effectively defends against threats like cross-site scripting (XSS), SQL injection, and others
It does bring value. For example, consider a BFSI customer. Their application is critical and represents their brand. Without a WAF, an attack could take their application down, harming their reputation. It leads to hampering the customer's workflow. With an Imperva WAF, they protect against attacks like DDoS or SQL injection, ensuring their application remains available and customers are happy. That's the main benefit for both the customer and the organization. The impact depends on the customer's use case. If their business primarily operates online, a CDN is beneficial for traffic optimization. Moreover, the integration options depend on the specific use case of our customers. Generally, integration capabilities are good with SIEM (Security Information and Event Management) parts.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution is always updating to continuously add items that create a level of safety from vulnerabilities. It's one of the key features they provide that's an excellent selling point. They're always ahead of the game when it comes to finding any vulnerabilities within the database."
"The SAST component was absolutely 100% stable."
"It shows in-depth code of where actual vulnerabilities are."
"Helps us check vulnerabilities in our SAP Fiori application."
"Both automatic and manual code review (CxQL) are valuable."
"Our static operation security has been able to identify more security issues since implementing this solution."
"The main thing we find valuable about Checkmarx is the ease of use. It's easy to initiate scans and triage defects."
"The most valuable feature is the application tracking reporting."
"The solution can be configured in just a couple of minutes."
"The most valuable features of the Imperva Web Application Firewall are DDoS, malware, and the other malicious threat prevention it provides. Additionally, third-party integration is available. You can forward the log for further analysis."
"The most valuable feature of Imperva, in addition to its strong knowledge base, is its effective protection for web applications."
"Imperva is easy to use and deploy. The UI is excellent."
"Compared to other web application firewalls in the market, Imperva does things in the most accurate way."
"The solution can scale."
"The solution is cloud-based and offers us good uptime. It has combined web and API security. Therefore, with one license, you access both application security and also API security."
"We can prevent attacks or issues even before they happen."
 

Cons

"Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"We want to have a holistic view of the portfolio-level dashboard and not just an individual technical project level."
"I would like to see the rate of false positives reduced."
"If it is a very large code base then we have a problem where we cannot scan it."
"The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
"They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy. Right now, it requires a SQL database, and the way the tool works is that it has an engine and then it has an analysis database in which it stores the information. So, it is pretty heavy from that perspective because you have to have a full SQL Server. They're working on something called Checkmarx Light, which is a slim-down version. They haven't released it yet, but that's what we need. There should be something a little more slimmed down that can just run the analysis and output the results in a format that's readable as opposed to having a full, really big, and thick deployment with a full database server."
"I would like to see the DAST solution in the future."
"The product's customization capabilities are a bit problematic, requiring support cases for backend modifications."
"There is nothing specific where the application firewall is falling short."
"I loved the approach of the cloud. The cloud has a lot of new features, like advanced web protection and DDoS protection. If those could also be on-boarded onto the on-prem versions, that would be ideal. They need to pay attention to both deployment options and not just favor one."
"The tool's UI is complicated. It would be best to have a more accessible UI dashboard to make the job easier."
"Some of the features should be included in the next release is a file integrating monitoring tool. This feature should be improved."
"The support for the on-premises version needs improvement."
"The reporting is missing some features, such as: only two export formats, and the time period does not include the last day, week, year."
"An improvement for Imperva WAF would be to reduce the number of false positives and create more strong use cases based on AI/ML or behavioral analytics."
 

Pricing and Cost Advice

"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"We have purchased an annual license to use this solution. The price is reasonable."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"The solution is costly."
"It's an excellent product, but it can be very costly."
"The solution's pricing is an issue."
"Make sure you understand the way that Imperva charges. It's very affordable. However, I would like to see a package with the Virtual Patching included. You get to do patching separately."
"It is very costly, but the return on investment is very high. Its cost was around $70,000, and we got it back in just six months."
"There is a license for this solution and we purchase the license annually with no additional fees."
"It is a very affordable solution."
"The price of this solution is a little bit high compared to competitors."
"Imperva Web Application Firewall is expensive."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
862,624 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Financial Services Firm
16%
Computer Software Company
12%
Insurance Company
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
Is Citrix ADC (formerly Netscaler) the best ADC to use and if not why?
For ADC, any ADC can do a good job. But in case if you want to add WAF functionality to the same ADC hardware you have to look for other ADC's like F5, Imperva, Radware, Fortinet, etc.
DDoS solutions: Any other solutions to consider aside from Radware DDoS Protection Service and F5 Silverline DDoS Protection?
You can have a look to Imperva Cloud WAF, the anti-DDoS mitigation is under 1s and works very well. I observed a lot of DDoS attacks that were well managed (even not seen by the customer) by Imperv...
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
BlueCross BlueShield, eHarmony, EMF Broadcasting, GE Healthcare, Metro Bank, The Motley Fool, Siemens
Find out what your peers are saying about Checkmarx One vs. Imperva Web Application Firewall and other solutions. Updated: March 2019.
862,624 professionals have used our research since 2012.