No more typing reviews! Try our Samantha, our new voice AI agent.

Imperva Application Security Platform vs Rapid7 AppSpider comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare
Sponsored
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
79
Ranking in other categories
CDN (1st), WAN Optimization (4th), Distributed Denial-of-Service (DDoS) Protection (3rd), Managed DNS (1st), Domain Name System (DNS) Security (5th), Cloud Security Posture Management (CSPM) (18th)
Imperva Application Securit...
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
143
Ranking in other categories
CDN (2nd), Web Application Firewall (WAF) (1st), Distributed Denial-of-Service (DDoS) Protection (4th), Bot Management (1st), API Security (2nd)
Rapid7 AppSpider
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
14
Ranking in other categories
Static Application Security Testing (SAST) (30th)
 

Mindshare comparison

Distributed Denial-of-Service (DDoS) Protection Mindshare Distribution
ProductMindshare (%)
Imperva Application Security Platform8.5%
Cloudflare14.0%
Arbor DDoS7.2%
Other70.3%
Distributed Denial-of-Service (DDoS) Protection
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Rapid7 AppSpider0.8%
SonarQube15.3%
Checkmarx One9.7%
Other74.2%
Static Application Security Testing (SAST)
 

Featured Reviews

M.A. Faisal - PeerSpot reviewer
General Manager at bKash Limited
Advanced protection has secured critical web workloads and provides clear traffic visibility
From a security perspective, there remains a security loophole, as some browsers in the market can bypass the Turnstile solution, which requires approximately 40 seconds to do so. From a performance perspective, this is acceptable. We also tried Google reCAPTCHA, and that can also be bypassed. From a security perspective, I would say neither solution is completely secured. Regarding uptime, we have faced a couple of incidents due to Cloudflare in recent years, so I cannot say we receive 100% uptime for our region. We sometimes face challenges, including downtime and other issues. As a result, we are not receiving 100% uptime from Cloudflare's solution. Since most of our customers are in this region, we need alternatives. We need something more competitive than Cloudflare. Unfortunately, in Bangladesh, Cloudflare has three points of presence already, and we cannot find any other solution provider in Bangladesh as an alternative, which presents another challenge. Competitor solutions have more attack signatures, which ensure better security compared to Cloudflare's predefined configurations. Customers do not have options to modify any configuration parameters in Cloudflare, whereas other competitor solutions, such as F5 Distributed Cloud, allow customers to tune configurations according to their requirements. Cloudflare could improve in this area. Additionally, regarding visibility, Cloudflare has static visibility, but they could adopt dynamic graph features for their customers.
ST
Senior Cybersecurity Consultant at Cyberoutcome Limited
Strong policies and bot defenses have secured critical APIs and have reduced attack noise
From my research regarding the IAM space that Imperva Application Security Platform is trying to look into, I believe they still need to do a lot of modeling and modification to make sure that also helps. There are several competitors in the IAM space, so Imperva would do well if they can do some basic modeling and modifications from my own personal research and my own experience in the IAM space. Alternatively, they could actually just focus on trying to be stronger in the web application space and the database activity monitoring space.The main reason it is not a perfect ten is regarding support. At times, having to reach the support team takes eight hours to ten hours maximum. There are times when clients could have urgent issues to attend to. The support team could do more by having a faster response rate.
HW
Marketing Expert at J's communication
Clients benefit from broad authentication and effective crawling but need localization improvements
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who require security assessments One of the most valuable features of AppSpider is its broad range of authentication identification, which is a key reason for its utilization.…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Because our website is blazing fast it improves our conversion rates."
"There are key things that are used for our enterprise customers, such as Lambda and DNS."
"I have used it to bring enterprise-grade features to my small business clients at low or no cost."
"The overall performance of this solution is what makes it one of the best solutions on the market."
"The most valuable feature is its usability."
"The simplicity of the overall dashboard makes it a great product for a user like me who has less understanding of the internet than a developer or other more technical people."
"We're using dynamic components to build flexible pages to create and manage Git merge requests for code and reviews."
"It's a great product because it's scalable, has great coverage, and is mature with good defenses against DDoS attacks."
"I like the user-friendly interface."
"Simplifies putting everything in code."
"The solution is a leader in the market and is easy to use."
"Very scalable and very stable firewall for web applications, with a good interface in its cloud version."
"I find the configurability of the tools and the ease of operation to be the most valuable feature of Imperva."
"Customer Support has been the biggest help in dire situations."
"The compliance is the most valuable aspect."
"On the site security, I can see which countries have incidents, whether it was a robot attack, a real human user, or non-human user."
"Rapid7 AppSpider is good at managing different applications. It uses applets and generates reports to cover the PCA/GDPR compliance requirements."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information, and you don't need specialized skills to use the product."
"It does a scan that performs about 100 checks on web applications and produces a clear report on all of the vulnerabilities that are found."
"The most valuable feature is the reporting, which is compliant with international standards."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
"The initial deployment is very straightforward and simple."
"This solution is a leader in the industry."
 

Cons

"Yes, there were a few times when some of their CDN nodes would fail, creating serious speed issues with the site without any warning or notification from their side."
"Cloudflare's free plan is limited to 5,000 records for their free plan. They should increase that. For example, if I create a domain called abc.com and a subdomain called a.abc.com, my record count will be two. I can make a maximum of 5,000 subdomains. However, if we use our own DNS hosted on another provider, there is no limit. Their free plan also lacks name server customization."
"The solution could work at being less expensive. It costs a lot to use it."
"The installation was complex until I learned what I had to learn."
"I would like to not need a separate server for non-www redirection under the CNAME setup option."
"Sometimes their more advanced caching tools can cause higher first-byte times and problems with JavaScript."
"One area of improvement is in the Access Rules. Hypothetically, if we wanted to block or challenge traffic outside of the United States, the only way to currently do that (as far as I know) is to enter every single country outside of the United States. That could be a labor intensive job. A solution could be to enable users to create a rule where traffic is only allowed within a certain country."
"Several features that I think is essential is not available in the free and business package."
"We faced issues regarding compliance with client procedures. The client had strict compliance rules, and Imperva needed to be on a VM, while the client required containerization, causing a conflict. They went with Imperva for the on-premise version but shelved the cloud project due to too many blockers."
"It is complicated to integrate the solution's on-cloud version with other platforms."
"The solution works for particular zones but isn't always the best solution for all zones."
"The tool's UI is complicated. It would be best to have a more accessible UI dashboard to make the job easier."
"I would like to see automated reporting to improve visibility."
"I am not sure if this application has a policy where you can create your custom policy and run it as our firewall."
"I have found some issues with caching; seems to be inconsistent."
"The log analytics interface within Incapsula isn't really good. For example, if you have to get all logs from there, it's a very cumbersome process."
"One of the challenges I have with AppSpider is that it gives you a lot of false positives, especially when compared to other solutions."
"AppSpider has some problems with the RAM needed while scanning."
"Integration could be better."
"Support response times are slow and can be improved."
"The product should offer a GUI in Japanese and provide Japanese reports for end-users."
"There are some glitches with stability, and it is an area for improvement."
"The solution is too slow. It could take a full day to scan. Competitors are much faster."
"AppSpider has some problems with the RAM needed while scanning."
 

Pricing and Cost Advice

"That is one of the great features. I was able to access the majority of the features and services for free."
"I think the pricing is competitive. I think as far as licensing is concerned it's pretty straightforward because it's based on domain. It's just that sometimes domains could be tricky with some customers."
"We are using the free version."
"Cloudflare's pricing is not much higher and is good for middle-level organizations."
"The product's pricing is cheap."
"It's a premium model. You can start at zero and work your way up to the enterprise model, which has a very high pricing level."
"We are using the free tier of the solution."
"The pricing depends on the usage, but the cheapest would be around 5,000 USD a month."
"The tool is expensive."
"​Although the pricing can be a little high, it is worth the protection and security that it offers.​"
"The price of Imperva Web Application Firewalls is expensive compared to others."
"The tool's pricing is good."
"The price is high compared to other solutions like FortiWeb."
"Everybody complains about the price of this solution."
"The license is on a yearly basis."
"The cost is somewhere around $10,000 a site. For every site, you pay individually. For every DNS entry, you have you pay."
"The price is pretty fair."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"The licensing cost depends on the number of users."
"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
report
Use our free recommendation engine to learn which Distributed Denial-of-Service (DDoS) Protection solutions are best for your needs.
892,611 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
10%
Comms Service Provider
10%
Computer Software Company
8%
Manufacturing Company
8%
Financial Services Firm
13%
Manufacturing Company
8%
Computer Software Company
7%
Comms Service Provider
6%
Manufacturing Company
11%
University
10%
Financial Services Firm
10%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise11
Large Enterprise26
By reviewers
Company SizeCount
Small Business88
Midsize Enterprise25
Large Enterprise67
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise2
Large Enterprise1
 

Questions from the Community

Which is the best DDoS protection solution for a big ISP for monitoring and mitigating?
Cloudflare. We are moving from Akamai prolexic to Cloudflare. Cloudflare anycast network outperforms Akamai static GR...
Which would you choose - Cloudflare DNS or Quad9?
Cloudflare DNS is a very fast, very reliable public DNS resolver. It is an enterprise-grade authoritative DNS service...
What is your experience regarding pricing and costs for Cloudflare?
The tool's pricing is moderate. I rate the product’s pricing a five out of ten, where one is cheap, and ten is expens...
Which Web Application Firewall (WAF) would you recommend? R&S or Imperva?
Imperva is a strong choice, given their security focus and ongoing R&D into the product in areas such as bot mana...
What is your experience regarding pricing and costs for Imperva DDoS?
The pricing, setup costs, and licensing of Imperva DDoS are reasonable for the amount of technical capabilities provi...
What needs improvement with Imperva DDoS?
I would like to see improvements in the pooling of threats and attacks, possibly to enlarge the scale of indicators o...
What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price is not high, but for Japanese customers, localization may incur additional costs.
What needs improvement with Rapid7 AppSpider?
For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese repor...
What is your primary use case for Rapid7 AppSpider?
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who r...
 

Also Known As

Cloudflare DNS
Imperva Bot Management, Imperva Web Application Firewall, Imperva API Security
AppSpider
 

Overview

 

Sample Customers

Trusted by over 9,000,000 Internet Applications and APIs, including Nasdaq, Zendesk, Crunchbase, Steve Madden, OkCupid, Cisco, Quizlet, Discord and more.
Hitachi, BNZ, Bitstamp, Moz, InnoGames, BTCChina, Wix, LivePerson, Zillow and more.
Microsoft
Find out what your peers are saying about Radware, NETSCOUT, Cloudflare and others in Distributed Denial-of-Service (DDoS) Protection. Updated: April 2026.
892,611 professionals have used our research since 2012.