No more typing reviews! Try our Samantha, our new voice AI agent.

OWASP Zap vs OpenText Core Application Security vs PortSwigger Burp Suite Professional comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of June 2026, in the Static Application Security Testing (SAST) category, the mindshare of OpenText Core Application Security is 3.2%, down from 4.3% compared to the previous year. The mindshare of OWASP Zap is 2.9%, down from 5.1% compared to the previous year. The mindshare of PortSwigger Burp Suite Professional is 3.0%, up from 2.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
PortSwigger Burp Suite Professional3.0%
OpenText Core Application Security3.2%
OWASP Zap2.9%
Other90.9%
Static Application Security Testing (SAST)
 

Featured Reviews

Himanshu_Tyagi - PeerSpot reviewer
Lead Cybersecurity at TBO
Supports secure development pipelines and improves issue detection but limits internal visibility and needs broader dashboard integration
If you have an internal team and you want your internal team to validate false positives, basically to determine whether it's a valid issue or an invalid issue, then I wouldn't recommend it much. That was the only reason we migrated from Fortify on Demand to another solution. Fortify has another tool which is Fortify WebInspect. On Demand is the outsourcing solution, and WebInspect you can use with your in-house team, which is basically the product developed by the Fortify team. For automated scanning, Fortify helps a lot. Regarding the visibility for the internal team, everyone is moving toward the DevSecOps side, and Fortify team has made good progress that you can integrate into your CICD pipeline. One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together. If you have one tool that works for different solutions, it helps a lot. They are doing good, but they should invest more on the AI side as well because AI security is evolving these days. On the cloud side, they have already made good progress, but I believe they should explore the new area related to AI security as well.
Amit Beniwal - PeerSpot reviewer
Project Manager at Al Hassan LLC
Simplifies vulnerability discovery and has high quality support
There are areas for improvement with OWASP Zap, particularly in the alignment of vulnerabilities concerning CVSS scores. Sometimes, a vulnerability initially categorized as high severity may be reduced to medium or low over time after security patches are applied. This alignment with the present severity score and CVSS score could be improved.
MH
Penetration Tester & Information Security Expert at a comms service provider with 11-50 employees
Dedicated browser and repeater have improved my proxy testing and manual vulnerability checks
I'm hoping perhaps for something to make it easier, such as to define things where if a message or a response is such and such, automatically make a request that is such and such. Perhaps something like this because otherwise, nowadays we have to do it manually. Perhaps they can automate it a bit more. Perhaps they could add some automation to things, to see what we do manually, which it has the tools to do manually, and perhaps enable with a click of a button to do things automatically. I'm not too sure which, but I'm sure they can from a product management point of view, do things that we need to do two, three, or four steps manually regarding specific testing. For instance, we want to check something specific if it's this or if it's that. Perhaps to define it once and have it more automatic, perhaps.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The vulnerability detection and scanning are awesome features."
"The SAST feature is the most valuable."
"Overall, it is a very good tool and it works well for what it is designed for."
"It helps deploy and track changes easily as per time-to-time market upgrades."
"The features that I have found most valuable include its security scan, the vulnerability finds, and the web interface to search and review the issues."
"I use the solution in my company for security code scans."
"The static code analyzers are the most valuable features of this solution."
"t's a cloud-based solution, so there was no installation involved."
"You can run it against multiple targets."
"The reporting is quite intuitive, which gives you a clear indication of what kind of vulnerability you have that you can drill down on to gather more information."
"The HUD is a good feature that provides on-site testing and saves a lot of time."
"The solution has tightened our security and that of our clients who depend on it."
"Two features are valuable. The first one is that the scan gets completed really quickly, and the second one is that even though it searches in a limited scope, what it does in that limited scope is very good. When you use Zap for testing, you're only using it for specific aspects or you're only looking for certain things. It works very well in that limited scope."
"The product has improved our application security engagement, helps with our in-house review so we sometimes don't need an external third-party tester, and once we get it from OWASP Zap, we have an idea of the inherent vulnerabilities in the application, which is a plus to save cost and improve our application accuracy practice."
"The community edition updates services regularly. They add new vulnerabilities into the scanning list."
"OWASP is quite matured in identifying the vulnerabilities."
"The solution is reliable, it is very stable."
"The automated scan is what I find most useful because a lot of customers will need it. Not every domain will be looking for complete security, they just need a stamp on the security key. For these kinds of customers, the scan works really well."
"We use the solution for vulnerability assessment in respect of the application and the sites."
"This solution provides a very good mechanism for fixing interval time; for example, we can create a schedule, and the schedule runs on time, PortSwigger Burp Suite does not hamper the node of the server and does not shut down the server if it is running, it is quite fast and easy to install as well, and it is also a budget-friendly tool."
"The most valuable features are Burp Intruder and Burp Scanner."
"The most valuable feature of PortSwigger Burp Suite Professional is the advanced features, user-friendly interface, and integration with other tools."
"The Spider is the most useful feature. It helps to analyze the entire web application, and it finds all the passes and offers an automated identification of security issues."
"The solution is quite helpful for session management and configuration."
 

Cons

"The Visual Studio plugin seems to hang when a scan is run on big projects. I would expect some improvements there."
"Temenos's (T-24) info basic is a separate programming interface, and such proprietary platforms and programming interfaces were not easily supported by the out-of-the-box versions of Fortify."
"It needs to support more languages."
"Technical support is 6/10. I find the Internet to be more helpful at times than their own tech support in finding answers."
".NET code scanning is still dependent on building the code base before running any scan. Also, it's dependent on an IDE such as Visual Studio."
"There are frequent complaints about false positives from Fortify. One day it may pass a scan with no issues, and the next day, without any code changes, it will report vulnerabilities such as password exposure."
"The reporting capabilities need improvement, as there are some features that we would like to have but are not available at the moment."
"We have some stability issues, but they are minimal."
"The documentation needs to be improved because I had to learn everything from watching YouTube videos."
"The documentation is lacking and out-of-date, it really needs more love."
"OWASP should work on reducing false positives by using AI and ML algorithms. They should expand their capabilities for broader coverage of business logic flaws and complex issues."
"We're currently moving away from OWASP to PortSwigger Burp Suite Professional; it's more user-friendly with a better interface."
"The documentation is lacking and out-of-date, it really needs more love."
"As security evolves, we would like DevOps built into it. As of now, Zap does not provide this."
"The product reporting could be improved."
"Right now, I can't give it off to a team and expect them to give me a report that I'm happy with."
"There could be an improvement in the API security testing."
"Even though I started working with PortSwigger Burp Suite Professional, I think I may have run the Scanner once, but I prefer to run ZAP because I'm more used to it and I think it checks many more vulnerabilities."
"Integration is a big problem."
"The solution is not easy to set it up. You need a lot of knowledge."
"I would like to see the return of the spider mechanism instead of the crawling feature. Burp Suite's earlier version 1.7 had an excellent spider option, and it would be beneficial if Burp incorporated those features into the current version. The crawling techniques used in the current version are not as efficient as those used in earlier versions."
"Currently, the scanning is only available in the full version of Burp, and not in the Community version."
"The use of system memory is an area that can be improved because it uses a lot."
"It should provide a better way to integrate with Jenkins so that DAST (dynamic application security testing) can be automated."
 

Pricing and Cost Advice

"Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten."
"Despite being on the higher end in terms of cost, the biggest value lies in its abilities, including robust features, seamless integration, and high-quality findings."
"The price is fair compared to that of other solutions."
"The licensing was good because the licenses have the heavy centralized server."
"It is quite expensive. Pricing and the licensing model could be improved."
"The subscription model, on a per-scan basis, is a bit expensive. That's another reason we are not using it for all the apps."
"Fortify on Demand is moderately priced, but its pricing could be more flexible."
"I believe the rental license is not too expensive, but it provides a lot of information about the vulnerabilities."
"As Zap is free and open-source, with tons of features similar to those of commercial solutions, I would definitely recommend trying it out."
"This is an open-source solution and can be used free of charge."
"The tool is open source."
"The solution’s pricing is high."
"The tool is open-source."
"It is highly recommended as it is an open source tool."
"OWASP Zap is free to use."
"It's free. It's good for us because we don't know what the extent of our use will be yet. It's good to start with something free and easy to use."
"This solution requires a license. It is expensive but you receive a lot of functionality for the price."
"It's a lower priced tool that we can rely on with good standard mechanisms."
"This is a value for money product."
"The platform's pricing is reasonable."
"It is expensive for us in Brazil because the currency exchange rate from a dollar to a Brazilian Real is quite steep."
"I rate the pricing a four out of ten."
"The solution used to be expensive. However, they have reduced the price to approximately $400.00 which is reasonable."
"We have one license. The price is very nominal."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
896,563 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
13%
Government
7%
Computer Software Company
7%
Computer Software Company
11%
Financial Services Firm
9%
University
9%
Manufacturing Company
8%
Government
10%
Financial Services Firm
9%
Computer Software Company
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise8
Large Enterprise46
By reviewers
Company SizeCount
Small Business11
Midsize Enterprise11
Large Enterprise22
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise14
Large Enterprise35
 

Questions from the Community

What is your experience regarding pricing and costs for Micro Focus Fortify on Demand?
In comparison with other tools, they're competitive. It is not more expensive than other solutions, but their pricing...
What needs improvement with Micro Focus Fortify on Demand?
Areas for improvement should be contextualized post the OpenText acquisition, but back when I was working with Micro ...
What is your primary use case for Micro Focus Fortify on Demand?
For OpenText Core Application Security, I currently support a couple of my clients who are using Fortify on Demand fo...
Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available...
What is your experience regarding pricing and costs for OWASP Zap?
OWASP might be cost-effective, however, people prefer to use the free edition available as open source.
What needs improvement with OWASP Zap?
The improvement that has to be done for APIs focuses on manual activities where the feature exists, but it is not at ...
What is your experience regarding pricing and costs for PortSwigger Burp Suite Professional?
The cost of PortSwigger Burp Suite Professional is reasonable at approximately $500 per year per user.
What needs improvement with PortSwigger Burp Suite Professional?
I'm hoping perhaps for something to make it easier, such as to define things where if a message or a response is such...
What is your primary use case for PortSwigger Burp Suite Professional?
I have used the Intruder tool in PortSwigger Burp Suite Professional at least once or twice. It is used to fuzz param...
 

Also Known As

Micro Focus Fortify on Demand
No data available
Burp
 

Overview

 

Sample Customers

SAP, Aaron's, British Gas, FICO, Cox Automative, Callcredit Information Group, Vital and more.
1. Google 2. Microsoft 3. IBM 4. Amazon 5. Facebook 6. Twitter 7. LinkedIn 8. Netflix 9. Adobe 10. PayPal 11. Salesforce 12. Cisco 13. Oracle 14. Intel 15. HP 16. Dell 17. VMware 18. Symantec 19. McAfee 20. Citrix 21. Red Hat 22. Juniper Networks 23. SAP 24. Accenture 25. Deloitte 26. Ernst & Young 27. PwC 28. KPMG 29. Capgemini 30. Infosys 31. Wipro 32. TCS
Google, Amazon, NASA, FedEx, P&G, Salesforce
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: May 2026.
896,563 professionals have used our research since 2012.