Try our new research platform with insights from 80,000+ expert users

Checkmarx One vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Average Rating
7.6
Reviews Sentiment
6.9
Number of Reviews
71
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Vulnerability Management (24th), Static Code Analysis (3rd), API Security (5th), DevSecOps (5th), Risk-Based Vulnerability Management (9th)
The Fastly Next-Gen WAF (po...
Average Rating
7.6
Reviews Sentiment
7.1
Number of Reviews
3
Ranking in other categories
Web Application Firewall (WAF) (28th)
 

Mindshare comparison

Checkmarx One and The Fastly Next-Gen WAF (powered by Signal Sciences) aren’t in the same category and serve different purposes. Checkmarx One is designed for Application Security Tools and holds a mindshare of 9.9%, down 14.3% compared to last year.
The Fastly Next-Gen WAF (powered by Signal Sciences), on the other hand, focuses on Web Application Firewall (WAF), holds 1.0% mindshare, up 0.7% since last year.
Application Security Tools
Web Application Firewall (WAF)
 

Featured Reviews

Syed Hasan - PeerSpot reviewer
Partner experiences excellent technical support and seamless initial setup
In my opinion, if we are able to extract or show the report, and because everything is going towards agent tech and GenAI, it would be beneficial if it could get integrated with our code base and do the fix automatically. It could suggest how the code base is written and automatically populate the source code with three different solution options to choose from. This would be really helpful.
Shashank N - PeerSpot reviewer
Provides good stability, but the agent-based approach could be more convenient
The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF. Additionally, the agent-based approach presents challenges with managing agents across versions and dependencies on specific application platforms like Apache or NGINX, leading to compatibility issues and complexity in integration. This agent-based system proved particularly difficult to manage.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It's not an obstacle for developers. They can easily write their code and make it more secure with Checkmarx."
"The UI is user-friendly."
"The UI is very intuitive and simple to use."
"The most valuable features of Checkmarx are its integration with multiple SCM solutions and CICD tools, its ability to scale according to user licenses, and the quick scanning process."
"The feature that I have found most valuable is that its number of false positives is less than the other security application platforms. Its ease of use is another good feature. It also supports most of the languages."
"The features and technologies are very good. The flexibility and the roadmap have also been very good. They're at the forefront of delivering the additional capabilities that are required with cloud delivery, etc. Their ability to deliver what customers require and when they require is very important."
"I have seen a return on investment from Checkmarx One."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"The product's most valuable feature is its ability to set up the rules easily."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
 

Cons

"There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver."
"The Dynamic Application Security Testing (DAST) feature should be better."
"This product requires you to create your own rulesets. You have to do a lot of customization."
"We can run only one project at a time."
"Its user interface could be improved and made more friendly."
"Meta data is always needed."
"Checkmarx is not good because it has too many false positive issues."
"We have received some feedback from our customers who are receiving a large number of false positives."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
 

Pricing and Cost Advice

"It is the right price for quality delivery."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"I believe pricing is better compared to other commercial tools."
"This solution is expensive. The customized package allows you to buy additional users at any time."
"It is not expensive, but sometimes, their pricing model or licensing model is not very clear. There are similar variables, such as projects or developers, and sometimes, it is a little bit confusing."
"The price of Checkmarx could be reduced to match their competitors, it is expensive."
"It is an expensive solution."
"Signal Sciences is pretty cheap compared to other solutions."
"The pricing is 50% less than Akamai."
"The product has an affordable cost."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
862,543 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
20%
Computer Software Company
14%
Manufacturing Company
10%
Government
6%
Computer Software Company
13%
Manufacturing Company
11%
Financial Services Firm
11%
Healthcare Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The pricing is relatively expensive due to the product's quality and performance, but it is worth it.
What do you like most about Signal Sciences?
The product's most valuable feature is its ability to set up the rules easily.
What needs improvement with Signal Sciences?
Fastly don't support caching for China users. That's the only feature lacking compared to Akamai.
 

Also Known As

No data available
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: July 2025.
862,543 professionals have used our research since 2012.