No more typing reviews! Try our Samantha, our new voice AI agent.

NGINX App Protect vs Veracode comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 16, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.3
Qualys TotalCloud effectively reduces costs and labor while enhancing asset visibility and risk management, boosting efficiency by up to 40%.
Sentiment score
5.8
NGINX App Protect offers notable ROI, enhancing security, integrating with CICD pipelines, and providing compliance and time-saving benefits.
Sentiment score
6.5
Veracode boosts ROI by reducing security breaches and costs, enhancing compliance, and integrating effective vulnerability detection and automation.
We are able to scan all our assets with less human intervention and achieve overall effective outcomes.
Dns architect at a outsourcing company with 5,001-10,000 employees
It has saved about 90% of our time.
Senior Consultant at a consultancy with 10,001+ employees
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
Security Manager at a consultancy with 10,001+ employees
The scanners of Veracode bring status of the weaknesses in the current infrastructure. It scans and provides reports regarding the servers, the network, and the applications running on those servers.
Senior Solutions Architect at IDS Comercial
Regarding price, the evaluation should focus on how efficiently they will recover their investment, considering the time saved through the use of Veracode Fix, for example, and the ability to fix code at dev time compared to the problems faced when fixing after the product is already deployed.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
We did see a return on investment with Veracode, as we segregated our remediation efforts, which reduced our time to delivery as well as the number of engineers needed to help us in delivering a secure solution.
DevSecOps Engineer at a tech services company with 11-50 employees
 

Customer Service

Sentiment score
6.7
Qualys TotalCloud support is knowledgeable but inconsistent, with some delays and varying service quality affecting customer satisfaction.
Sentiment score
5.8
NGINX App Protect's support is reliable and helpful, though costs and occasional delays affect accessibility for some users.
Sentiment score
7.2
Veracode's support is praised for expertise and responsiveness, though some report delays, improvements noted with dedicated managers.
They are helpful, respond to my queries, and can answer any question.
Developer at a consultancy with 10,001+ employees
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Service Manager, Security Operations at CDA IT SOLUTIONS
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
Works at a consultancy with 10,001+ employees
They were quick and efficient when we had issues.
Project Manager at a comms service provider with 10,001+ employees
I would rate the customer support a 9 on a scale of 1 to 10.
Tech Lead at a tech vendor with 51-200 employees
Access to the engineering team is crucial for faster feedback on the product fix process.
Principal Architect at a consultancy with 11-50 employees
I have communicated with the technical support of Veracode a couple of times, and this was a really great experience because these professionals know their material.
Application Security Specialist at Herrenknecht
They share detailed information via email, including screenshots or further clarification about the issue.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
 

Scalability Issues

Sentiment score
7.4
Qualys TotalCloud efficiently scales across multi-cloud environments, supporting diverse needs for small and large teams with minimal issues.
Sentiment score
6.1
NGINX App Protect offers strong scalability praised by users, despite challenges with policy limits and deployment delays.
Sentiment score
7.4
Veracode is praised for effective scalability across diverse needs, though costs and complexity can increase with scaling.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
CIO at a venture capital & private equity firm with 11-50 employees
Our organization currently uses it to manage over 1200 web applications.
Analyst, Information Security at Infosys
It is absolutely scalable, and I would rate its scalability as nine out of ten.
retired at a consultancy with 10,001+ employees
The scalability of NGINX App Protect is good and open source at its best.
Tech Lead at a tech vendor with 51-200 employees
Cloud solutions are easier to scale than on-premise solutions.
Senior Solutions Architect at IDS Comercial
It has a good capacity to scale effectively.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
Implementing these features into our normal CI/CD was good, so I can say that scalability is really good.
Application Security Specialist at Herrenknecht
 

Stability Issues

Sentiment score
8.4
Qualys TotalCloud is praised for its stability, 99.9% uptime, reliable performance, and responsive support for resolving issues.
Sentiment score
8.4
Users praise NGINX App Protect's stability and reliability, outperforming competitors, handling high traffic efficiently, and receiving high ratings.
Sentiment score
7.8
Veracode is generally stable with minor glitches, but could improve speed and communication for enhanced reliability.
Overall, the support provided has been excellent.
Analyst, Information Security at Infosys
It has a lot of scanning mechanisms, which are agentless APIs, eBPF, and cloud agents, that are highly reliable.
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
It is a stable solution, which is why we chose it.
CIO at a venture capital & private equity firm with 11-50 employees
It is a quality solution, and I would rate its stability as eight out of ten.
IT Architect at a financial services firm with 10,001+ employees
If the Veracode server is down, we experience many issues during the scan.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
I have observed that it is not that reliable in terms of security because Veracode was not able to find some security threats in our application that existed since the product was developed.
Software Development Engineer II at Rocket Software
It's not that easy to onboard, but once they have been onboarded on the platform, and the pipeline configured alongside the product configured, it works effectively.
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
 

Room For Improvement

Qualys TotalCloud needs UI/UX enhancements, better integrations, compliance reporting, Windows container security, AI threat prediction, and pricing clarity.
NGINX App Protect needs enhancements in automation, UI, security, performance, and support, with complex setup and integration issues.
Veracode is criticized for high costs, licensing rigidity, false positives, slow UI, and limited integration and language support.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Analyst, Information Security at Infosys
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Project Lead at Persistent Systems
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Senior Information Security Engineer at a consultancy with 10,001+ employees
There was more information from F5 regarding hardware requirements and specifications to deploy the service.
IT Architect at a financial services firm with 10,001+ employees
For now, I think NGINX App Protect is good, but maybe I would like to see the logging feature added.
Dev Ops Engineer at BARQ Systems
The GUI and web GUI configuration could be improved to be easier to manage and use.
Dev Ops Engineer at adesso AG
If it could be integrated directly with code repositories such as Bitbucket or GitHub, without the need to create a pipeline to upload and decode code, it would simplify the code scan process significantly.
We had issues with scanning large applications. Scanning took a lot of time, so we kept it outside the DevOps pipeline to avoid delaying deployments.
Lead Automation Quality Engineer in Leading UK Bank at a consultancy with 10,001+ employees
A nice addition would be if it could be extended for scenarios with custom cleansers.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
 

Setup Cost

Qualys TotalCloud offers competitive pricing for large enterprises, providing flexible, cost-effective solutions with comprehensive features and benefits.
NGINX App Protect offers reasonable annual pricing, ranging from $25,000 to $400,000, aligning with industry-leading solutions.
Veracode's pricing is high and complex, valued by enterprises but expensive for smaller businesses with flexible options.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Senior Manager at a financial services firm with 10,001+ employees
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
IT Manager at a consultancy with 10,001+ employees
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
Vice President at Inspira Enterprise
It's not the most expensive solution.
Senior Solutions Architect at IDS Comercial
Overall, Veracode's pricing is lower and more scalable than many alternatives in the market.
DevSecOps Engineer at a tech services company with 1,001-5,000 employees
If there's a security gap, you'll never know the cost or effect.
 

Valuable Features

Qualys TotalCloud enhances cloud security with risk prioritization, automation, and visibility, boosting efficiency in vulnerability management and remediation.
NGINX App Protect provides comprehensive security features including automation, real-time threat detection, DDoS protection, and flexible deployment options.
Veracode offers effective security analysis, CI/CD integration, multi-language support, and detailed reports for secure, compliant software development.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
Works at a consultancy with 10,001+ employees
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
Developer at a consultancy with 10,001+ employees
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
Senior Consultant at a consultancy with 10,001+ employees
The most valuable feature is the ability to operate in a DevOps environment and to be configured through API and pipeline by the developers themselves.
IT Architect at a financial services firm with 10,001+ employees
Some threats like injection and running scripts, SQL injections, these all get stopped and rejected by the server.
Dev Ops Engineer at BARQ Systems
Detecting bots and blocking IPs have proven effective for securing applications.
Project Manager at a comms service provider with 10,001+ employees
It offers confidence by preventing exposure to vulnerabilities and helps ensure that we are not deploying vulnerable code into production.
Site Leader (India) at Industrial Scientific
The best features in Veracode include static analysis and the early detection of vulnerable libraries; it integrates with tools such as Jenkins.
It fixes issues directly in the IDE while you're doing it.
IT App Security Senior Analyst at a transportation company with 10,001+ employees
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Ranking in Container Security
11th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (10th), Cloud Workload Protection Platforms (CWPP) (9th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
NGINX App Protect
Ranking in Container Security
27th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
27
Ranking in other categories
Web Application Firewall (WAF) (20th), API Security (9th)
Veracode
Ranking in Container Security
13th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (3rd), Software Composition Analysis (SCA) (2nd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (3rd)
 

Mindshare comparison

As of October 2026, in the Container Security category, the mindshare of Qualys TotalCloud is 1.8%, up from 1.1% compared to the previous year. The mindshare of NGINX App Protect is 0.6%, up from 0.3% compared to the previous year. The mindshare of Veracode is 2.7%, down from 3.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Container Security Mindshare Distribution
ProductMindshare (%)
Qualys TotalCloud1.8%
Veracode2.7%
NGINX App Protect0.6%
Other94.9%
Container Security
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
Valerio Guaglianone - PeerSpot reviewer
Dev Ops Engineer at adesso AG
Long-term web protection has supported reliable traffic management but needs a simpler interface
NGINX App Protect is a good product. I have used both versions from F5 -also the free version- (I mean the NGINX/NGINX One/App Protect free trial period), and I think it is a good product. It's stable, affordable, and easy to manage. NGINX App Protect is a comprehensive security solution that combines advanced WAF, DoS protection, API security, and DevSecOps automation in a lightweight, scalable package ideal for modern cloud-native architectures. The adaptive machine learning capabilities are truly commendable, as the solution can establish traffic baselines and detect anomalies in real time. It automatically adjusts security policies, minimizing the need for manual intervention and reducing false positives. Additionally, it supports scalable deployment across diverse environments, including on-premises, cloud, Kubernetes, and containers, offering both flexibility and scalability I have experience with the web server, F5 load balancer, and similar products provided by Ergon, for eg. the web application firewall and the Microgateway for K8S. I'm also familiar with F5 BIG-IP products.
YS
Software Development Engineer II at Rocket Software
Monthly scans have provided baseline security but still miss critical vulnerabilities
Veracode can improve to stand in this market. They do not have to do much; they just need to improve their UI experience and add more documentation within the application rather than just creating documentation pages on different websites. They need to ensure their web application guides whoever uses it. Since whoever uses Veracode must be a technical person, they just need to guide them to the actual points. They can also improve their security capabilities by adding more filters to identify what vulnerabilities their application has. They need to improve their scanning engine to scan for more critical defects. Also, the integration part can be enhanced by adding features to integrate with a CLI, such as introducing a CLI version or a Jenkins plugin. If such features exist, they should show it as a pop-up, signaling that they have a new feature. Currently, it feels Veracode from two years ago is still the same, so that is something Veracode needs to improve. They can improve the security part. Some of the severe security issues were never caught by Veracode in the reports. In fact, I have never seen any high or critical severity issues pop up in my Veracode report. That is one thing they can improve on their scanning ability to catch high severity issues. Next is integration; Veracode does not provide any tools to integrate with Jenkins or CLI. I do not even know if there is any CLI for Veracode that I can use to automate in my pipeline. The last thing is the UI interface that they have, as it is a bit confusing. I remember we did not have the capability to handle authentications of our internal application. We had to write Selenium code using a Selenium IDE. To write a Selenium script for a Veracode scan, you have to download a Selenium IDE, record it, and then paste that file into Veracode. I can see that Selenium IDE is already decommissioned, so it is no longer used by anyone. Still, we have to use it because Veracode only supports that kind of file for Selenium to automate. They can add more ways to authenticate our application using normal JavaScript or Python or Shell script. I feel these are the four main points. They can document it more by adding tooltips into the application that explain why a parameter is required and what other options are available. For the same example with the Selenium script, they can add a link to their documentation that explains what other kinds of scripts can be written for authentication. I feel they can also make the UI more intuitive so that whoever uses it can guide themselves, as whoever uses Veracode is already a technical person.
report
Use our free recommendation engine to learn which Container Security solutions are best for your needs.
915,287 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Comms Service Provider
12%
Financial Services Firm
11%
Manufacturing Company
8%
Construction Company
8%
Financial Services Firm
14%
Manufacturing Company
13%
Outsourcing Company
9%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise6
Large Enterprise35
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise7
Large Enterprise14
By reviewers
Company SizeCount
Small Business70
Midsize Enterprise46
Large Enterprise114
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What is your experience regarding pricing and costs for NGINX App Protect?
I will not be able to answer about my experience with pricing, setup cost, and licensing for NGINX App Protect, as so...
What needs improvement with NGINX App Protect?
I did not face any issues with NGINX App Protect. The only issue that we had is that someone was trying to install th...
What is your primary use case for NGINX App Protect?
I have been dealing with NGINX App Protect and the WAF policy. I usually recommend NGINX App Protect for banking and ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed Ap...
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

Qualys TotalCloud with FlexScan
NGINX WAF, NGINX Web Application Firewall
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about NGINX App Protect vs. Veracode and other solutions. Updated: September 2026.
915,287 professionals have used our research since 2012.