Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs OpenText Dynamic Application Security Testing comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 21, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Dynamic Application Security Testing (DAST)
4th
Ranking in DevSecOps
5th
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (22nd), Container Security (23rd), Static Code Analysis (3rd), API Security (6th), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd)
OpenText Dynamic Applicatio...
Ranking in Dynamic Application Security Testing (DAST)
3rd
Ranking in DevSecOps
9th
Average Rating
7.2
Reviews Sentiment
6.1
Number of Reviews
22
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of Checkmarx One is 13.0%, down from 18.1% compared to the previous year. The mindshare of OpenText Dynamic Application Security Testing is 17.7%, down from 21.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Market Share Distribution
ProductMarket Share (%)
OpenText Dynamic Application Security Testing17.7%
Checkmarx One13.0%
Other69.3%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
RaviGupta4 - PeerSpot reviewer
Its ability to detect even complex vulnerabilities is invaluable
I would like WebInspect's scanning capability to be quicker. Specifically, being able to scan a particular flow or part of an application more rapidly would be beneficial. Additionally, the cost of the licensing, particularly for multiple user licenses, could be more relevant, which would improve affordability and distribution among users.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The user interface is modern and nice to use."
"The setup is fairly easy. We didn't struggle with the process at all."
"The most valuable feature for me is the Jenkins Plugin."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"The administration in Checkmarx is very good."
"Less false positive errors as compared to any other solution."
"The report function is the solution's greatest asset."
"The setup is very easy. There is a lot of information in the documents which makes the install not difficult at all."
"The user interface is ok and it is very simple to use."
"The accuracy of its scans is great."
"Guided Scan option allows us to easily scan and share reports."
"Fortify WebInspect is a scalable solution, it is good for a lot of applications."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"The tool provides comprehensive vulnerability assessments which help ensure our deliverables are as free from vulnerabilities as possible. It has also streamlined our web application vulnerability assessments, assisting us in delivering secure applications to our clients."
"The most valuable feature is the static analysis."
"When we are integrating it with SSC, we're able to scan and trace and see all of the vulnerabilities. Comparison is easy in SSC."
 

Cons

"It is an expensive solution."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
"When we first ran it on a big project, there wasn't enough memory on the computer. It originally ran with eight gigabytes, and now it runs with 32. The software stopped at some point, and while I don't think it said it ran out of memory, it just said "stopped" and something else. We had to go to the logs and send them to the integrator, and eventually, they found a memory issue in the logs and recommended increasing the memory. We doubled it once, and it didn't seem enough. We doubled it again, and it helped."
"Its user interface could be improved and made more friendly."
"Updating and debugging of queries is not very convenient."
"Some were valid and some were not applicable for us based on the scenario."
"It took us between eight and ten hours to scan an entire site, which is somewhat slow and something that I think can be improved."
"I want to enhance automation. Currently, Fortify WebInspect can scan and find vulnerabilities, but users with specific skills need to interpret the results and understand how to address them."
"I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
"The main area for improvement in Fortify WebInspect is the price, as it is too high compared to the market rate."
"One thing I would like to see them introduce is a cloud-based platform."
"There are some file extensions, like .SER, that Fortify WebInspect doesn't scan."
"Lately, we've seen more false negatives."
"I would like WebInspect's scanning capability to be quicker."
 

Pricing and Cost Advice

"For around 250 users or committers, the cost is approximately $500,000."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"It is the right price for quality delivery."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"The number of users and coverage for languages will have an impact on the cost of the license."
"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"We have purchased an annual license to use this solution. The price is reasonable."
"Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products."
"Its price is almost similar to the price of AppScan. Both of them are very costly. Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that."
"This solution is very expensive."
"The pricing is not clear and while it is not high, it is difficult to understand."
"The price is okay."
"It’s a fair price for the solution."
"Fortify WebInspect is a very expensive product."
"Our licensing is such that you can only run one scan at a time, which is inconvenient."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
872,778 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
Government
15%
Financial Services Firm
15%
Manufacturing Company
12%
Computer Software Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise9
Large Enterprise38
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise1
Large Enterprise15
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What is your experience regarding pricing and costs for Fortify WebInspect?
While I am not directly involved with licensing, I can share that our project's license for 1-9 applications costs between $15,000 to $19,000. In comparison, Burp Suite costs approximately $500 to ...
What needs improvement with Fortify WebInspect?
WebInspect works efficiently with Java-based or .NET based applications. However, it struggles with Salesforce applications, where it requires approximately 20-24 hours to crawl and audit but produ...
What is your primary use case for Fortify WebInspect?
I am currently working with several tools. For Fortify, I use SCA and WebInspect. Apart from that, I use Burp Suite from PortSwigger. For API testing, I use Postman with Burp Suite or WebInspect fo...
 

Also Known As

No data available
Micro Focus WebInspect, WebInspect
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Aaron's
Find out what your peers are saying about Checkmarx One vs. OpenText Dynamic Application Security Testing and other solutions. Updated: September 2025.
872,778 professionals have used our research since 2012.