

OpenText Core Application Security and Rapid7 AppSpider are key players in application security, with OpenText generally leading due to its extensive support and active user base.
Features: OpenText Core Application Security offers robust compliance, static and dynamic scanning, and centralized management, while providing 24/7 support and seamless integration into development processes. Rapid7 AppSpider is recognized for efficient vulnerability management, detailed compliance reporting, and its strong integration capabilities.
Room for Improvement: OpenText users suggest enhancing reporting visuals, scan times, integration with bug tracking systems, and reducing false positives. Rapid7 AppSpider users look for faster scans, better mobile application integration, and clarity in reporting.
Ease of Deployment and Customer Service: Both products support on-premises, hybrid, and cloud deployments. OpenText's support is more reliable, although sometimes slow, while Rapid7's customer service receives high ratings despite being considered average overall.
Pricing and ROI: OpenText Core Application Security is seen as costly but offers substantial value through its features and flexible licensing. Rapid7 AppSpider's pricing is fair, though additional localization costs may apply. Both solutions positively impact security risk reduction, despite some dissatisfaction with licensing complexity.
| Product | Market Share (%) |
|---|---|
| OpenText Core Application Security | 3.6% |
| Rapid7 AppSpider | 0.5% |
| Other | 95.9% |


| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 8 |
| Large Enterprise | 43 |
| Company Size | Count |
|---|---|
| Small Business | 11 |
| Midsize Enterprise | 2 |
| Large Enterprise | 1 |
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
SPAs, APIs, mobile—the evolution of application technology is measured in months, not years. Is your web application security testing tool designed to keep up? AppSpider lets you collect all the information needed to test all the apps so that you aren’t left with gaping application risks.
Our dynamic application security testing (DAST) solution crawls to the deepest, darkest corners of even the most modern and complex apps to effectively test for risk and get you the insight you need to remediate faster. With AppSpider on your side (or, rather, all of your sides), you’ll be able to scan all the apps today and always be ready for whatever comes next.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.