Try our new research platform with insights from 80,000+ expert users

HCL AppScan vs OWASP Zap comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

HCL AppScan
Ranking in Static Application Security Testing (SAST)
15th
Average Rating
7.8
Reviews Sentiment
6.1
Number of Reviews
43
Ranking in other categories
Application Security Tools (15th), Dynamic Application Security Testing (DAST) (1st)
OWASP Zap
Ranking in Static Application Security Testing (SAST)
11th
Average Rating
7.6
Reviews Sentiment
7.3
Number of Reviews
41
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of September 2025, in the Static Application Security Testing (SAST) category, the mindshare of HCL AppScan is 2.5%, down from 2.6% compared to the previous year. The mindshare of OWASP Zap is 4.6%, up from 4.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Market Share Distribution
ProductMarket Share (%)
OWASP Zap4.6%
HCL AppScan2.5%
Other92.9%
Static Application Security Testing (SAST)
 

Featured Reviews

Sthembiso Zondi - PeerSpot reviewer
Has a straightforward setup process and valuable security features
We use AppScan primarily for security testing and performance monitoring across our systems The product's features for comprehensive code analysis (static) and live environment testing (dynamic) have significantly enhanced our ability to identify and address vulnerabilities, improving overall…
Amit Beniwal - PeerSpot reviewer
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"You can easily find particular features and functions through the UI."
"AppScan is stable."
"It is a stable solution...It is a scalable solution...The initial setup or installation of HCL AppScan is easy."
"It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code."
"The most valuable feature of the solution is the scanning or security part."
"Compared to other tools only AppScan supports special language."
"Technical support is helpful."
"There's extensive functionality with custom rules and a custom knowledge base."
"Simple and easy to learn and master."
"OWASP is quite matured in identifying the vulnerabilities."
"This solution has improved my organization because it has made us feel safer doing frequent deployments for web applications. If we have something really big, we might get some professional company in to help us but if we're releasing small products, we will check it ourselves with Zap. It makes it easier and safer."
"The community edition updates services regularly. They add new vulnerabilities into the scanning list."
"I consider OWASP Zap to be the most effective solution overall; being open source allows integration with other systems via OWASP Zap APIs."
"The application scanning feature is the most valuable feature."
"The most valuable feature is scanning the URL to drill down all the different sites."
"The HUD is a good feature that provides on-site testing and saves a lot of time."
 

Cons

"They could add a software component analysis tool."
"AppScan is too complicated and should be made more user-friendly."
"If HCL AppScan is able to alert the clients over email once the scan is complete, it would be great. Right now, HCL AppScan doesn't let me know if the scanning part is finished or not, because of which I have to come back and check mostly."
"The solution's scalability can be a matter of concern because one license runs on one machine only."
"They have to improve support."
"​IBM Security AppScan Source is rather hard to use​."
"Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
"There are so many lines of code with so many different categories that I am likely to get lost. ​"
"The forced browse has been incorporated into the program and it is resource-intensive."
"It would be beneficial to enhance the algorithm to provide better summaries of automatic scanning results."
"There are too many false positives."
"Lacks resources where users can internally access a learning module from the tool."
"The product should allow users to customize the report based on their needs."
"For scalability, I would rate OWASP Zap between four to five out of ten."
"Deployment is somewhat complicated."
"OWASP Zap needs to extend to mobile application testing."
 

Pricing and Cost Advice

"AppScan is a little bit expensive. IBM needs to work a little bit on the pricing model, decreasing the license cost."
"The tool was expensive."
"I rate the product's price a seven on a scale of one to ten, where one is low, and ten is high. HCL AppScan is an expensive tool."
"Our clients are willing to pay the extra money. It is expensive."
"With the features, that they offer, and the support, they offer, AppScan pricing is on a higher level."
"The solution is moderately priced."
"The price is very expensive."
"The product has premium pricing and could be more competitive."
"The tool is open-source."
"OWASP Zap is free to use."
"This solution is open source and free."
"OWASP ZAP is a free tool provided by OWASP’s engineers and experts. There is an option to donate."
"This app is completely free and open source. So there is no question about any pricing."
"It is highly recommended as it is an open source tool."
"The tool is open source."
"The solution’s pricing is high."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
866,483 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
12%
Government
10%
Manufacturing Company
10%
Computer Software Company
17%
Financial Services Firm
11%
Manufacturing Company
8%
University
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise6
Large Enterprise31
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise11
Large Enterprise21
 

Questions from the Community

What do you like most about HCL AppScan?
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase.
What needs improvement with HCL AppScan?
AppScan needs to improve its handling of false positives. It also requires enhancements in customer support, similar to what Veracode provides. Regularly scheduling calls with clients to discuss fe...
What is your primary use case for HCL AppScan?
The primary use case for AppScan is for security purposes. I compare AppScan with other tools such as Veracode. We use AppScan for vulnerability detection and auto-remediation of vulnerabilities wi...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available with basic security vulnerabilities while Burp Suite Pro has it available with ...
What do you like most about OWASP Zap?
The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, i...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
 

Also Known As

IBM Security AppScan, Rational AppScan, AppScan
No data available
 

Overview

 

Sample Customers

Essex Technology Group Inc., Cisco, West Virginia University, APIS IT
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Find out what your peers are saying about HCL AppScan vs. OWASP Zap and other solutions. Updated: July 2025.
866,483 professionals have used our research since 2012.