Try our new research platform with insights from 80,000+ expert users

CucumberStudio vs Rapid7 InsightAppSec comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 13, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CucumberStudio
Ranking in Dynamic Application Security Testing (DAST)
7th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
12
Ranking in other categories
Rapid Application Development Software (28th)
Rapid7 InsightAppSec
Ranking in Dynamic Application Security Testing (DAST)
4th
Average Rating
8.2
Reviews Sentiment
7.7
Number of Reviews
18
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Dynamic Application Security Testing (DAST) category, the mindshare of CucumberStudio is 0.6%, up from 0.1% compared to the previous year. The mindshare of Rapid7 InsightAppSec is 12.0%, down from 13.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Walter Wirch - PeerSpot reviewer
Facilitates integration of test scenarios while needing modernization of components
CucumberStudio is primarily used for designing test scenarios and automating testing. We have implemented it in conjunction with our own routines for integration into our infrastructure CucumberStudio aligns with our strategy for data-driven testing. It supports our product owners in designing…
Krzysztof Witko - PeerSpot reviewer
Automated authorization streamlines security processes
The previous product, AppSpyder, had a virtual patching module where we could generate patches for third-party web application firewalls, such as Imperva or F5. Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version. Virtual patching could help protect web pages shortly after finishing the scan process.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"CucumberStudio has a very user-friendly interface."
"The best thing is that a person without knowledge about the program can easily understand what happened in our testing process."
"CucumberStudio aligns with our strategy for data-driven testing."
"The most valuable feature of CucumberStudio is its use of action words, which allows me to avoid writing test cases from scratch for the most common scenarios."
"The data table that helps in converting a single script to multiple test cases is very helpful."
"The URL is very useful, and it has a very good UI for deploying information of the scenarios created."
"CucumberStudio aligns with our strategy for data-driven testing."
"The solution is stable."
"Dynamic application security scanning provides predefined templates and supports customization. The ability to scan external and internal applications, including on-premises ones, is precious. Additionally, it is a cloud platform, so we don't need to deploy servers or resources. This makes it time-efficient and cost-effective."
"When considering DAST, it is not attributed to a singular feature but rather the capabilities of the engine that provides a genuine penetration testing experience and delivers insightful reports."
"You have various attack modules, and you also have the Attack Replay feature for the attack sequence. You can reproduce an attack and see it. That is a very good feature I noticed in this solution. It helps developers as well."
"The initial setup for us was easy enough. We didn't face too many issues. Deployment took maybe 30 minutes. It's quite quick and doesn't cause too much trouble at the outset."
"The templates feature is very easy. You just choose the kind of attack you want on your web application, and you run it against that template and receive a report. It's great."
"It uses a signature-based method to check for problems with your code and will provide an alert if anything is found."
"It is very convenient to get reports from the tool, which offers high-level environmental statistics."
"It is a very robust solution."
 

Cons

"I think it would be better if we could also do the reporting with CucumberStudio."
"A key area for improvement is to revamp outdated components such as HipTest publisher."
"The reporting needs to be improved."
"A key area for improvement is to revamp outdated components such as HipTest publisher."
"I would like to see better customer support."
"Another kind of deployment might be useful, perhaps an option to install the tool in a local deployment."
"CucumberStudio's API integration could be improved both in terms of reliability and design."
"The interface should be a little bit easier to manage. Sometimes, the logic that they use is kind of strange. They need to work a little bit more on their interface to make it more understandable. The interface is the only problem. I'm using Rapid7, which is very intuitive. There are other applications available in the market with a better interface. They can include more techniques or options to test different types of security because the templates are limited. It would be great to see them follow the MITRE ATT&CK framework or what is there in tools like Veracode and Synopsys."
"We get a lot of false positives during the tests."
"The product’s pricing could be flexible."
"I would like more details of what the product can do."
"When you add new projects for the same product, it either duplicates or replaces the scan configuration. If I run a scan for the same product with a different scan configuration, it should keep the previous scan configuration and not replace it with the new scan configuration. It should just add the new scan configuration. That would be helpful. They do keep the results as it is, but the scan configuration keeps changing. For example, I have set a scan configuration to a full scan, and next week, I want to run a new scan for the same product with some changes or new functionalities. I want to run a partial scan. Currently, if I change the scan configuration to partial, it changes the old one also to partial. That should be improved."
"The number of web applications we can scan is limited."
"They should add more features. I would like to see them do a little more on static analysis and also interactivity analysis. Currently, it does very basic static analysis. It could do a little more static analysis, which is something that would help. A lot more interactivity analysis should also be there. It should basically look at security during interactivity."
"Currently, InsightAppSec lacks similar functionality. Customers must wait for remediation during the developers' preparation of a new version."
 

Pricing and Cost Advice

Information not available
"They offer a good price, but I don't remember its cost. It is fair as compared to the competition. We have opted for project-based licensing, not user-based. We can add any number of users. That doesn't matter. It is worth the money."
"I rate Rapid7 InsightAppSec’s pricing an eight out of ten."
"Its price is competitive. It is not expensive."
"I'm not sure how much it costs exactly, but I know it's expensive."
"The price of this product is very cheap."
"Rapid7 InsightAppSec is cheap."
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
849,963 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
16%
Financial Services Firm
15%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Hiptest?
The best thing is that a person without knowledge about the program can easily understand what happened in our testing process.
What needs improvement with Hiptest?
A key area for improvement is to revamp outdated components such as HipTest publisher. Introducing modern technology could improve the platform. API-based solutions are present but could benefit fr...
What is your primary use case for Hiptest?
CucumberStudio is primarily used for designing test scenarios and automating testing. We have implemented it in conjunction with our own routines for integration into our infrastructure.
What do you like most about Rapid7 InsightAppSec?
In Rapid7 InsightAppSec, a distinctive feature is the provision of a CDM for integrating web servers and web applications. To establish the connection between these applications, you only need to p...
What needs improvement with Rapid7 InsightAppSec?
Currently, I do not see any specific areas for improvement except for possibly lowering the price.
What is your primary use case for Rapid7 InsightAppSec?
I use Rapid7 InsightAppSec ( /products/rapid7-insightappsec-reviews ) for dynamic application security testing. My main focus is on the quality of detection, specifically detecting vulnerabilities ...
 

Also Known As

Hiptest
InsightAppSec
 

Overview

 

Sample Customers

Cisco, Cardinal Health, Intuit, Smartbox, Accenture, Deliveroo
CenterPoint Energy, CPA Australia, Hypertherm, First American Financial Corporation, Rackspace
Find out what your peers are saying about CucumberStudio vs. Rapid7 InsightAppSec and other solutions. Updated: April 2025.
849,963 professionals have used our research since 2012.