Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Dynamic Application Security Testing (DAST)
4th
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (22nd), Container Security (23rd), Static Code Analysis (3rd), API Security (6th), DevSecOps (5th), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
2nd
Average Rating
8.2
Reviews Sentiment
7.5
Number of Reviews
19
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of Checkmarx One is 13.0%, down from 18.1% compared to the previous year. The mindshare of Rapid7 InsightAppSec is 9.6%, up from 9.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Market Share Distribution
ProductMarket Share (%)
Rapid7 InsightAppSec9.6%
Checkmarx One13.0%
Other77.4%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Shritam Bhowmick - PeerSpot reviewer
Provides reliable applications security but needs better integration options
There are areas for improvements regarding false positives. Integration capabilities are lacking, as options for integrations with other tools such as SNOW, Jira, or other integration tools are not sufficient in Rapid7 InsightAppSec. The user interface sometimes has glitches, which may prevent appropriate results during navigation, and even when we get appropriate results, it can be impossible to export them to CSV records or download files. Regarding scalability, Rapid7 InsightAppSec is not a scalable solution for our industry due to limited integration capabilities. Rapid7 relies on another tool called InsightConnect, which requires additional investment, detracting from scalability. Another area that needs improvement is the integration of AI capabilities into the platform. Both Rapid7 InsightAppSec and InsightVM need to advance in that area. In terms of behavioral and pattern recognition, identifying complex attacks such as SQL, blind SQL, JSON, and LDAP injections often results in 94% false positives. This necessitates improvement in their behavioral-based analytics feature.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility."
"One of the most valuable features is it is flexible."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"It is a stable product."
"It gives the proper code flow of vulnerabilities and the number of occurrences."
"The solution allows us to create custom rules for code checks."
"Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%."
"Overall, the ability to find vulnerabilities in the code is better than the tool that we were using before."
"It is very convenient to get reports from the tool, which offers high-level environmental statistics."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"I would rate the technical support from Rapid7 a ten, indicating high-quality support."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"The product’s most valuable feature is UI. It is easy to manage and find vulnerabilities in the application."
"Relatively speaking, InsightAppSec is good compared to Insight VM."
"When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
 

Cons

"Checkmarx could improve the speed of the scans."
"The pricing can get a bit expensive, depending on the company's size."
"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"Creating and editing custom rules in Checkmarx is difficult because the license for the editor comes at an additional cost, and there is a steep learning curve."
"I can't create a business case with multiple-factor authentication."
"With Checkmarx, normally you need to use one tool for quality and you need to use another tool for security. I understand that Checkmarx is not in the parity space because it's totally different, but they could include some free features or recommendations too."
"The statistics module has a function that allows you to show some statistics, but I think it's limited. Maybe it needs more information."
"The number of web applications we can scan is limited."
"I required a solution to manage on-premises, but I was not as satisfied as expected."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
"In the future, if they can have integration with a lot of ticketing systems then it would be amazing."
"When you add new projects for the same product, it either duplicates or replaces the scan configuration. If I run a scan for the same product with a different scan configuration, it should keep the previous scan configuration and not replace it with the new scan configuration. It should just add the new scan configuration. That would be helpful. They do keep the results as it is, but the scan configuration keeps changing. For example, I have set a scan configuration to a full scan, and next week, I want to run a new scan for the same product with some changes or new functionalities. I want to run a partial scan. Currently, if I change the scan configuration to partial, it changes the old one also to partial. That should be improved."
"We'd like to see integrations with WAF solutions."
"I would like more details of what the product can do."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange. They need to work a little bit more on their interface to make it more understandable. The interface is the only problem. I'm using Rapid7, which is very intuitive. There are other applications available in the market with a better interface. They can include more techniques or options to test different types of security because the templates are limited. It would be great to see them follow the MITRE ATT&CK framework or what is there in tools like Veracode and Synopsys."
 

Pricing and Cost Advice

"The number of users and coverage for languages will have an impact on the cost of the license."
"I believe pricing is better compared to other commercial tools."
"The interface used to create custom rules comes at an additional cost."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"It is the right price for quality delivery."
"If you want more, you have to pay more. You have to pay for additional modules or functionalities."
"We have purchased an annual license to use this solution. The price is reasonable."
"Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products."
"Rapid7 InsightAppSec is cheap."
"Its price is competitive. It is not expensive."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"The price of this product is very cheap."
"I'm not sure how much it costs exactly, but I know it's expensive."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
872,008 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
19%
Computer Software Company
13%
Manufacturing Company
10%
Government
6%
Computer Software Company
15%
Manufacturing Company
13%
Financial Services Firm
13%
Government
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise9
Large Enterprise38
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise2
Large Enterprise5
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
There are areas for improvements regarding false positives. Integration capabilities are lacking, as options for integrations with other tools such as SNOW, Jira, or other integration tools are not...
What is your primary use case for Rapid7 InsightAppSec?
Our main use case for Rapid7 InsightAppSec is to perform internal assessment of applications and external facing applications. We have a cloud engine plus on-premises engine, and we have been lever...
 

Also Known As

No data available
InsightAppSec
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about Checkmarx One vs. Rapid7 InsightAppSec and other solutions. Updated: September 2025.
872,008 professionals have used our research since 2012.