No more typing reviews! Try our Samantha, our new voice AI agent.

DefectDojo vs Tines comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
39
Ranking in other categories
Vulnerability Management (11th), Container Security (13th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (1st), Cloud-Native Application Protection Platforms (CNAPP) (8th)
DefectDojo
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
Vulnerability Management (44th), DevSecOps (12th)
Tines
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
6
Ranking in other categories
Threat Intelligence Platforms (TIP) (11th), Security Orchestration Automation and Response (SOAR) (6th), AI-Powered Security Automation (1st), AI IT Support (10th)
 

Mindshare comparison

Vulnerability Management Mindshare Distribution
ProductMindshare (%)
DefectDojo0.9%
Wiz5.0%
Qualys VMDR4.2%
Other89.9%
Vulnerability Management
Security Orchestration Automation and Response (SOAR) Mindshare Distribution
ProductMindshare (%)
Tines4.5%
Microsoft Sentinel10.1%
Palo Alto Networks Cortex XSOAR8.8%
Other76.6%
Security Orchestration Automation and Response (SOAR)
 

Featured Reviews

RO
IT Security Expert at Alior Bank S.A.
Unified risk scoring has improved our cloud visibility and simplifies remediation priorities
Qualys TotalCloud provides unified vulnerability and threat assessment across both IAS and SaaS. This solution provides a single prioritized view of risk, which helps reduce the work I would have to do. We are no longer based on CVSS; we are based on Qualys risk scoring, which is based on CVSS plus internal findings made by Qualys, and then assigns its own score. The TruRisk insight feature has found a small number of assets with high vulnerability scores, though I am cautious since some information is classified. Qualys TotalCloud has positively impacted our bank's performance, and we have definitely seen benefits after implementing this solution.
reviewer2267097 - PeerSpot reviewer
Integration and Solution Architect at a government with 501-1,000 employees
Easy to use with efficient vulnerability reporting and team collaboration
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and we send this report to DefectDojo to have CVMs, Central Vulnerability Management. DefectDojo is Central Vulnerability Management. If you have a dashboard to set, we have…
Shadrach Godwish Chukwu - PeerSpot reviewer
Virtual Assistant / Technical Support at a tech services company with 11-50 employees
Automation has replaced repetitive tasks and helps my team organize workflows in real time
Tines is overall good, but the setup can feel a bit technical at first. More templates for common workflows would make it much easier to start quickly without building everything from scratch. I can say that the documentation could be much simpler and mainly example-based, showing real workflows. Faster support responses would also help, especially when someone is building a very complex workflow so they can easily get support responses at any point. The setup time is considerable. It takes time to set it up, and the learning curve is steep. It is not hard once you know it, but getting started takes a whole lot of time and effort and slows new users down considerably. I will heavily dwell on a few things. More ready-made templates would help so you do not always start from scratch. A simpler onboarding flow for new users would also make it much easier to get started very quickly. Better in-app guidance when building workflows would also be helpful.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It is a cloud-native app that integrates with both IaaS and SaaS. It seamlessly integrates with other platforms."
"The dashboards are particularly valuable as they offer a comprehensive view of the environment, highlighting any misconfigurations."
"I like the web API security and IoT scanning features the most. The user-friendly design of TotalCloud's interface enables customers to navigate it and use its full potential easily"
"I would recommend Qualys TotalCloud to other users because it is cost-efficient and has a good return on investment."
"The most valuable feature is the consolidated information that it provides from various platforms."
"Qualys TotalCloud provides unified vulnerability and threat assessment for IaaS and SaaS and a single prioritized view of risk, which helps reduce my workload by not having to combine multiple sources."
"I found the initial setup user-friendly."
"Qualys TotalCloud's most valuable feature is its ability to link clusters of assets, providing a clear model of deployments, vulnerabilities, and statuses."
"With the pipeline of detection and DefectDojo, we are able to see the real vulnerabilities, and we fix them."
"One of the most valuable features is that it’s a low-code solution."
"The tool was vendor-neutral."
"Tines is a very solid tool overall; once you get used to it, it makes work much easier and saves a whole lot of time."
"The best advantage is the no-code automation, excellent customer support services, and ease of integration with other tools."
"For an analyst, it would take at least one hour to two hours to get the result with this much perfection, but with Tines, it happens instantaneously."
"The best thing is that it's no code, so it doesn't require coding knowledge."
 

Cons

"To improve the user experience, reporting could be simplified for better comprehension by end users and project managers, facilitating issue resolution."
"Their support could be improved."
"Enhancing clarity regarding its compliance capabilities would be beneficial, as the current scope is limited in geographic coverage."
"Qualys TotalCloud has the potential to improve by integrating a hybrid platform for comprehensive management of both on-premises and cloud infrastructures."
"There should be improvement from a dashboard perspective when collecting and showcasing data to lead management."
"Areas that need improvement in every solution include the remediation part. The remediation steps should be simple enough for everyone to understand."
"We encountered challenges identifying the correct resource category for certain items, such as those in containers or storage."
"Two areas for improvement in Qualys TotalCloud are the speed of the public cloud platform and vulnerability detection."
"We need something to notify the team responsible for a product when vulnerabilities are found."
"Tines was a little bit more expensive than Torq."
"They started implementing some AI, and their AI is isolated."
"The setup time is considerable; it takes time to set it up, and the learning curve is steep."
"Maybe Tines can add more features and demonstrations, like videos on how to use the features within the tool."
"There are three things that I would say could be better."
"Reporting and dashboards could be more advanced for deeper analysis."
 

Pricing and Cost Advice

"While Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive and may soon be considered overpriced."
"I am not sure about the pricing. From what I understand, it is a bit on the higher side, but I do not have the exact numbers."
"The cost is high, but it meets our organizational needs."
"Qualys TotalCloud offers cost-effective licensing flexibility."
"Qualys TotalCloud offers good pricing that is affordable and competitive with the market. Our partnership also provides us with additional benefits."
"The pricing is comparable. It is built into our other product, so I cannot piecemeal it. It is a part of our subscription."
"TotalCloud's price is about right where I would expect it to be."
"Although Qualys TotalCloud is relatively expensive due to its unique automation features, its cost-effectiveness is rated an eight out of ten, with ten being the most costly."
Information not available
Information not available
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
896,510 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
9%
Computer Software Company
9%
Comms Service Provider
8%
Comms Service Provider
13%
Financial Services Firm
11%
Computer Software Company
9%
Construction Company
8%
Financial Services Firm
13%
Manufacturing Company
8%
Insurance Company
8%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise3
Large Enterprise28
No data available
No data available
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
Areas that need improvement in every solution include the remediation part. The remediation steps should be simple en...
What is your primary use case for Qualys TotalCloud?
Our use case involves the assets that we have under cloud, the assets exposed to the internet, and the internal appli...
What is your experience regarding pricing and costs for DefectDojo?
The pricing is great. It is much cheaper compared to other solutions. We don't want to pay for things we are able to ...
What needs improvement with DefectDojo?
We need something to notify the team responsible for a product when vulnerabilities are found. We are able to attach ...
What is your primary use case for DefectDojo?
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and...
What needs improvement with Tines?
There are three things that I would say could be better. The first is the Change Control UI. I have noticed that the ...
What is your primary use case for Tines?
In the cybersecurity engineering and security automation field, we use Tines to automate the enrichment and analysis ...
What advice do you have for others considering Tines?
We are not in control of the deployment anymore. Initially we were using an S3 bucket to deploy Tines, but now Tines ...
 

Comparisons

 

Also Known As

Qualys TotalCloud with FlexScan
No data available
No data available
 

Overview

Find out what your peers are saying about Wiz, Tenable, Qualys and others in Vulnerability Management. Updated: May 2026.
896,510 professionals have used our research since 2012.