We performed a comparison between Klocwork and PortSwigger Burp Suite Professional based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time."
"There is a central Klocwork server at our headquarter in France so we connect the client directly to the server on-premises remotely."
"On-the-fly analysis and incremental analysis are the best parts of Klocwork. Currently, we are using both of these features very effectively."
"There's a feature in Klocwork called 'on-the-fly analysis', which helps developers to find and fix the defects at the time of development itself."
"The most valuable feature of Klocwork is finding defects while you're doing the coding. For example, if you have an IDE plug-in of Klocwork on Visual Studio or Eclipse, you can find the faults; similar to using spell check on Word, you can find out defects during the development phase, which means that you don't have to wait till the development is over to find the flaws and address the deficiencies. I also find language support in Klocwork good because it used to support only C, C++, C#, and Java, but now, it also supports Java scripts and Python."
"The reporting helps us understand the trend of our results and whether we improve over time. We can see the history within Klocwork's server architecture and know that we're making things better. It creates a great story for our management. We can demonstrate value and how our software is developing over time."
"I like not having to dig through false positives. Chasing down a false positive can take anywhere from five minutes for a small easy one, then something that is complicated and goes through a whole bunch of different class cases, and it can take up to 45 minutes to an hour to find out if it is a false positive or not."
"One can increase the number of vendors, so the solution is scalable."
"We are mostly using it for scanning the entire website. So, we basically create a script with the entire website and then run it for different injections."
"The extension that it provides with the community version for the skills mapping is excellent."
"This tool is more accurate than the other solutions that we use, and reports fewer false positives."
"The initial setup is simple."
"BurpSuite helps us to identify and fix silly mistakes that are sometimes introduced by our developers in their coding."
"The Repeater and the BApp extensions are particularly useful. Certain extensions, such as the Active Scan extensions and the Autoracer extension, are very good."
"Once I capture the proxy, I'm able to transfer across. All the requested information is there. I can send across the request to what we call a repeater, where I get to ready the payload that I send to the application. Put in malicious content and then see if it's responding to it."
""The product is very good just the way it is; It has everything already well established and functions great. I can't see any way for this current version to be improved.""
"Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report."
"We bought Klocwork, but it was limited to one little program, but the program is now sort of failing. So, we have a license for usage on a program that is sort of failing, and we really can't use the license on anything else."
"Under NIST cybersecurity standards, we must address vulnerabilities within a specified time after discovering them. When we try to propagate those updates and fixes through the system, it would be nice if the clients could reconnect to the existing server or have the server dynamically updated in some way. I know that isn't easy, but maybe processes could be enhanced to make that more streamlined from a DevOps perspective."
"We'd like to see integration with Agile DevOps and Agile methodologies."
"Klocwork has to improve its features to stay ahead of other free solutions."
"I hope that in each new release they add new features relating to the addition of checkers, improving their analysis engines etc."
"This solution could be improved if they offered support of more languages including Ada and Golang. They currently only support seven languages."
"I would like to see better codes between projects and a more user-friendly desktop in the next release."
"The price could be better. The rest is fine."
"There needs to be better documentation provided. Currently, we need to buy books, or we need to review online some use cases from other professionals who have been using the solution to find out their experience. It is not easy to find out how to properly do a security assessment."
"Scanning needs to be improved in enterprise and professional versions."
"I would like to see the return of the spider mechanism instead of the crawling feature. Burp Suite's earlier version 1.7 had an excellent spider option, and it would be beneficial if Burp incorporated those features into the current version. The crawling techniques used in the current version are not as efficient as those used in earlier versions."
"A lot of our interns find it difficult to get used to PortSwigger Burp's environment."
"I need the solution to be more user-friendly. The solution needs to be user-friendly."
"I would like to see a more optimized solution, as it currently uses a lot of CPU power and memory."
"It should provide a better way to integrate with Jenkins so that DAST (dynamic application security testing) can be automated."
More PortSwigger Burp Suite Professional Pricing and Cost Advice →
Klocwork is ranked 19th in Application Security Tools with 20 reviews while PortSwigger Burp Suite Professional is ranked 12th in Application Security Tools with 54 reviews. Klocwork is rated 8.0, while PortSwigger Burp Suite Professional is rated 8.6. The top reviewer of Klocwork writes "Their technical team helps us get the most out of the solution, but we've faced some stability problems in our environment". On the other hand, the top reviewer of PortSwigger Burp Suite Professional writes "The solution is versatile and easy to deploy, but it needs to give more detailed security reports". Klocwork is most compared with SonarQube, Coverity, Polyspace Code Prover, CodeSonar and Checkmarx, whereas PortSwigger Burp Suite Professional is most compared with OWASP Zap, Fortify WebInspect, Acunetix, HCL AppScan and Qualys Web Application Scanning. See our Klocwork vs. PortSwigger Burp Suite Professional report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.