No more typing reviews! Try our Samantha, our new voice AI agent.

HCL AppScan vs IBM Rational Performance Tester comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

HCL AppScan
Average Rating
7.6
Reviews Sentiment
5.9
Number of Reviews
44
Ranking in other categories
Application Security Tools (19th), Static Application Security Testing (SAST) (17th), Dynamic Application Security Testing (DAST) (6th)
IBM Rational Performance Te...
Average Rating
7.6
Number of Reviews
17
Ranking in other categories
Test Management Tools (18th)
 

Mindshare comparison

While both are Quality Assurance solutions, they serve different purposes. HCL AppScan is designed for Application Security Tools and holds a mindshare of 2.2%, down 2.5% compared to last year.
IBM Rational Performance Tester, on the other hand, focuses on Test Management Tools, holds 2.9% mindshare, up 1.4% since last year.
Application Security Tools Mindshare Distribution
ProductMindshare (%)
HCL AppScan2.2%
SonarQube14.5%
Checkmarx One9.2%
Other74.1%
Application Security Tools
Test Management Tools Mindshare Distribution
ProductMindshare (%)
IBM Rational Performance Tester2.9%
OpenText Application Quality Management8.4%
Tricentis qTest6.8%
Other81.9%
Test Management Tools
 

Featured Reviews

Ravi Khanchandani - PeerSpot reviewer
Founder Director at Techsa Services
Has improved identification of encryption and authentication issues across cloud and on-prem applications
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interface. However, there is one feature called SCA, which stands for Software Composition Analysis, that could be improved. When I'm doing an application scan, HCL AppScan has the ability to generate information about what components are in use. For example, if I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present. I would like to see more detailed reports from the tool. Currently, you can find out the components belonging to a specific software, but if detailed reporting became available, you would be in a better position to identify vulnerabilities. For instance, I could identify that I had the Log4j vulnerability and know that I need to fix my application accordingly. If they add the features I'm describing, I would consider giving them a higher rating. However, I've only been experienced with the product for three months.
KashifJamil - PeerSpot reviewer
CEO at Xcelliti
Supports web and mobile applications, very scalable, very stable, and wonderful support
There are some features that Micro Focus LoadRunner provides, but they are not available in IBM Rational Performance Tester. They should include such features. It can also have more reports similar to what HP provides. It might also need some improvement in terms of the tools and support for other technology areas. Certain technologies are not supported by every tool. They need to support all sorts of technologies and platforms on which web applications and mobile applications are built. They need complete support for all sorts of technologies.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of the solution is the scanning or security part."
"The benefits are that we can find security vulnerabilities fast, get that back to development teams, and report on those so they can act, fix the issues, and we will have secure code in place."
"The solution offers services in a few specific development languages."
"Scalability, and it's a very powerful tool."
"I mainly use AppScan for vulnerability scanning and database bridging."
"This solution saves us time due to the low number of false positives detected."
"I prefer Appscan, as it much more user friendly, and it detects cross-site scripting and SQL injection issues much better than other tools in the market."
"Compared to other tools only AppScan supports special language."
"Technical support is very good. I'm very satisfied with the assistance we've received so far."
"It can support both web applications and mobile applications, and in certain cases, it can also support testing of desktop applications or software-based applications. You can write web applications, mobile applications, and software-based applications."
"With each new version, the tool gets better and better features."
"ROI is big because we do not need vendors to assist some with performance testing."
"It's definitely helped in scaling the performance of our application."
"Once you are used to this tool, it is user friendly and provides very good analysis for web applications."
"Real time view and its inbuilt root cause analysis tools is something which I like the most."
"Customization and extensions made in Java is valuable because this can help you set elements to improve your results."
 

Cons

"The performance could be better. Sometimes it doesn't work so well."
"There are so many lines of code with so many different categories that I am likely to get lost. ​"
"We have experienced challenges when trying to integrate this solution with other products. When you compare it with the other SecOps products, the quality of the output is too low. It is not a new-age product. It is very outdated."
"The solution often has a high number of false positives. It's an aspect they really need to improve upon."
"IBM Security AppScan Source is rather hard to use."
"AppScan needs to improve its handling of false positives."
"IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications."
"Sometimes it doesn't work so well."
"The HP tool is overall a little better but much more expensive."
"There are some features that Micro Focus LoadRunner provides, but they are not available in IBM Rational Performance Tester. They should include such features. It can also have more reports similar to what HP provides. It might also need some improvement in terms of the tools and support for other technology areas. Certain technologies are not supported by every tool. They need to support all sorts of technologies and platforms on which web applications and mobile applications are built. They need complete support for all sorts of technologies."
"The solution is not easily scalable. If you want to extend the solution, you need to purchase a different kind of license. You also have to work with the IBM team to assist in scaling."
"As intuitive as a product can be, its use could still benefit from a decent set of manuals or guides."
"Reporting needs improvement to provide more customization options in the performance test analyst to build custom reports."
"Installation and configuration processes, and support from IBM all need to be improved."
"I’d like to see a tighter integration with Rational Quality Manager and the Jazz platform."
"For a rational performance testing solution, the initial setup is very complex. The setup was difficult and the documentation was not very up to date."
 

Pricing and Cost Advice

"The price is very expensive."
"The product is moderately priced, though it's an investment due to extensive code analysis needs."
"The price of HCL AppScan is okay, in my opinion. You just buy HCL AppScan and don't pay anything anymore, meaning it is just a one-time purchase."
"The solution is moderately priced."
"The tool was expensive."
"HCL AppScan is expensive."
"I rate the product's price a seven on a scale of one to ten, where one is low, and ten is high. HCL AppScan is an expensive tool."
"I would rate the product's pricing a nine out of ten. The product's pricing is expensive compared to the features that they offer."
"It is much cheaper than Micro Focus LoadRunner. We need perpetual licenses. Support is included in the first sale. After that, you need to renew support every year."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
886,719 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
10%
Government
10%
Manufacturing Company
9%
Financial Services Firm
17%
Construction Company
7%
Government
7%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise6
Large Enterprise8
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
During the learning curve of onboarding HCL AppScan, we learned that HCL has altered the portfolio and now offers HCL AppScan 360, which has a much better look and feel with an improved user interf...
What is your primary use case for HCL AppScan?
I'm currently working with BigFix and HCL AppScan. At least three people in my company are using HCL AppScan. Since we are a reseller, we run it in both lab environments and live production applica...
Ask a question
Earn 20 points
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
Rational Performance Tester
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
andagon, Regence BlueCross BlueShield of Oregon
Find out what your peers are saying about SonarSource Sàrl, Veracode, Checkmarx and others in Application Security Tools. Updated: April 2026.
886,719 professionals have used our research since 2012.