

HCL AppScan and Acunetix both compete in the security scanning tools market. HCL AppScan appears to have the upper hand in DAST capabilities, while Acunetix excels in reporting and speed.
Features: HCL AppScan provides robust dynamic application security testing, seamless integration within the development process, and powerful API scanning. Acunetix is valued for its quick scanning capabilities across multiple domains, a low false positive rate, and comprehensive security reporting options.
Room for Improvement: HCL AppScan needs to enhance its user interface, support multiple languages, and improve its dashboard features. Acunetix could benefit from better pricing options, a more intuitive user interface, and enhanced report customization to further reduce false positives.
Ease of Deployment and Customer Service: HCL AppScan offers flexible deployment options including on-premises and public cloud but receives mixed customer service feedback. Acunetix is versatile with deployment, supporting on-premises, cloud, and hybrid setups with generally responsive support that may encounter time-zone related delays.
Pricing and ROI: HCL AppScan is considered more affordable compared to high-end tools and is valued for quick ROI through vulnerability reduction. Acunetix's higher pricing is justified by its capabilities but is perceived as complex due to domain-based licensing. Despite its cost, it offers a favorable return on investment by positively impacting security processes.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on investment, as Acunetix helps reduce the man-days and effort needed for scanning bulk applications through automated assessments.
Veracode provides excellent assistance and regularly scheduled calls to address customer concerns and updates.
There is still room for improvement when it comes to the speed of response.
For high-severity issues, they reach out within two to three hours, and for critical issues, a response is received within 15 minutes.
The technical support from Invicti is very good and fast.
Support staff not being familiar with the problem.
Acunetix can handle increasing workloads and more applications easily.
Since we've been using HCL AppScan for about three months, we really have not encountered a false positive.
If I'm scanning a web application, it shows me the various components being used. It tells me whether I have Java libraries, .NET frameworks, or other log management libraries such as Log4j, and what versions of those specific components are present.
The main concern is related to false positives; Acunetix needs to work on identifying valid and invalid findings.
I could supply it with maybe a Swagger file or a JSON file, and Acunetix would pick it up, scan all the endpoints according to the OWASP Top Ten, and give me remediation and actionable remediation reports.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
Companies often choose based on budget constraints, with Veracode being on the higher end cost-wise.
The pricing cost is affordable for small and mid-sized organizations, and when compared to Checkmarx, it is significantly affordable, as Checkmarx is quite expensive.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further.
I have utilized its interactive application security testing, as well as both static application security testing, dynamic application security testing, and IAST.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
The best feature Acunetix offers is the centralized dashboard and the quality of reports it generates, which includes various options for selecting reports and developer options for directly sharing the reports with developers.
| Product | Mindshare (%) |
|---|---|
| Acunetix | 2.4% |
| HCL AppScan | 2.3% |
| Other | 95.3% |


| Company Size | Count |
|---|---|
| Small Business | 14 |
| Midsize Enterprise | 6 |
| Large Enterprise | 31 |
| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 7 |
| Large Enterprise | 19 |
HCL AppScan offers quick vulnerability detection with effective SDLC integration and is known for its user-friendly interface and seamless security integration.
HCL AppScan provides dynamic and static scanning to identify vulnerabilities like XSS and SQL injection. It integrates well into CI/CD pipelines, supports multiple languages, and offers web and dynamic scanning, helping businesses ensure security across development lifecycles. Users benefit from API coverage, Postman integration, and its ability to function in cloud and on-premise environments, facilitating a shift from DevOps to DevSecOps practices.
What features define HCL AppScan?HCL AppScan is leveraged in sectors requiring rigorous security checks, such as finance and healthcare, where it conducts comprehensive scans and offers insights into potential vulnerabilities. Its robust scanning capabilities aid companies in maintaining compliance and security standards.
Acunetix is a robust web application security testing tool offering rapid scanning, user-friendly interfaces, and accurate vulnerability detection with minimal false positives. It supports both cloud and on-premises deployment, making it versatile for various security needs.
Acunetix is distinguished by its capability to identify critical vulnerabilities such as cross-site scripting and SQL injection with high precision. It integrates seamlessly with CI/CD tools, supporting continuous scanning and large-scale application management. The centralized dashboard and detailed automated reporting streamline operations. Despite its benefits, users suggest improvements like reducing false positives, flexible pricing, and enhanced API scanning. Better integration with platforms like GitHub and Azure DevOps is sought, alongside more comprehensive customization and faster scanning. Mobile application scanning and improved team collaboration tools are also desired.
What features make Acunetix stand out?Acunetix is widely implemented across industries undertaking web application security assessments, including those requiring penetration testing and vulnerability assessment. It ensures applications meet security protocols and complies with standards while fitting into CI/CD workflows for secure pre-release checks.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.