

PortSwigger Burp Suite Professional and OpenText Core Application Security compete in the cybersecurity market, each offering unique benefits and facing distinct challenges. Based on feature strengths such as automatic vulnerability detection and integration capabilities, PortSwigger holds an upper hand in feature extensiveness, while OpenText excels in integration and dashboard offerings.
Features: PortSwigger Burp Suite Professional is renowned for features like Proxy, Repeater, and Intruder that enhance vulnerability detection and user customization. OpenText Core Application Security stands out with its integration capabilities, comprehensive dashboards, and enhanced support for code scanning, focusing on application security.
Room for Improvement: PortSwigger Burp Suite Professional users suggest enhancements in API scanning and a reduction of false positives to streamline manual verification processes. OpenText Core Application Security could improve existing systems integration and dynamic testing features, addressing concerns with support response times and high false-positive rates.
Ease of Deployment and Customer Service: PortSwigger Burp Suite Professional is typically deployed on-premises, while OpenText Core Application Security offers flexible hybrid and cloud-based deployment options. PortSwigger receives positive feedback for its comprehensive documentation and active community support, whereas OpenText, noted for responsive support, has room to improve in response speed.
Pricing and ROI: PortSwigger Burp Suite Professional is considered cost-effective with a reasonable subscription model that suits small to medium businesses, though some users mention rising costs. OpenText Core Application Security is perceived as pricier with a complex subscription model, but its robust feature set provides considerable value, offering effective ROI for addressing specific security needs over time.
I had direct interaction with them, which facilitated how we onboarded Fortify.
Support tickets often stay open for one month to three months, which leads to customer frustration.
The technical support from PortSwigger is excellent.
The technical support for PortSwigger Burp Suite Professional is pretty good, and I would give it a nine.
If a customer wants to know the tools and the technology used for their application to scan their application, they provide less information on that.
PortSwigger Burp Suite Professional is very stable.
PortSwigger Burp Suite Professional is a very stable tool, and I would rate its stability as eight out of ten.
It would be beneficial if Fortify could check for CVEs (Common Vulnerabilities and Exposures) in third-party libraries, which I currently use a separate dependency checker tool for.
One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together.
It would be better for Fortify on Demand if they could analyze not only the security pillar but also maintainability, portability, and reliability, covering all pillars of ISO 25000.
Some AI features might be added.
The dashboard of PortSwigger Burp Suite Professional could be made more user-friendly.
The pricing for PortSwigger is very cheap, and there are benefits in terms of time and cost savings.
I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.
Fortify helps me find serious issues, such as developers inadvertently leaving access tokens, including API access tokens, in the source code.
On demand you have two levels of reports: the first from the tool, which is the same as we can get from Fortify on-premises, and a next level reporting made by experts from OpenText, leading to a more condensed and precise report as level three.
Additionally, you can integrate Fortify in CICD pipeline, so you get real-time updates about the security issues in your pipeline.
The most valuable feature of Burp Suite Professional is its ability to schedule tasks for scanning websites.
I especially value the features for penetration testing.
The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency.
| Product | Market Share (%) |
|---|---|
| PortSwigger Burp Suite Professional | 2.4% |
| OpenText Core Application Security | 3.2% |
| Other | 94.4% |


| Company Size | Count |
|---|---|
| Small Business | 17 |
| Midsize Enterprise | 8 |
| Large Enterprise | 44 |
| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 14 |
| Large Enterprise | 35 |
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
Burp Suite Professional, by PortSwigger, is the world’s leading toolkit for web security testing. Over 52,000 users worldwide, across all industries and organization sizes, trust Burp Suite Professional to find more vulnerabilities, faster. With expertly-engineered manual and automated tooling, you're able to test smarter - not harder.
PortSwigger is the web security company that is enabling the world to secure the web. Over 50,000 security engineers rely on our software and expertise to secure their world.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.