

Parasoft SOAtest and OpenText Core Application Security compete in the software deployment and security testing category. Parasoft SOAtest has an edge in test automation and API testing, while OpenText Core is preferred for its detailed application security insights.
Features: Parasoft SOAtest offers rapid functional test setup using WSDL and XSD, robust integration with data sources, and comprehensive end-to-end testing capabilities across multiple protocols. OpenText Core excels in in-depth vulnerability scanning, efficient source code analysis, and robust integration with development platforms.
Room for Improvement: Parasoft SOAtest could benefit from a more user-friendly interface, improved reporting, and better integration with CI/CD tools. OpenText Core needs faster scan times, enhanced dynamic testing, and improvements in managing false positives.
Ease of Deployment and Customer Service: Parasoft SOAtest is primarily deployed on-premises, backed by strong customer service though with occasional delays. OpenText Core offers flexible cloud deployment options, with generally good customer service but challenges in resolving complex issues.
Pricing and ROI: Parasoft SOAtest is considered expensive but offers high ROI due to its automation capabilities. OpenText Core has flexible pricing yet is costly; however, its security insights justify the expense for many users.
There is definitive ROI if OpenText Core Application Security is deployed properly; it substantially reduces efforts in securing the solution while averting various application-related risks.
Tasks that previously took four or five minutes can now be completed in 20 to 30 seconds with the help of the tool.
We found Parasoft SOAtest to be quick in building up test patterns, allowing us to create complex tests efficiently.
I had direct interaction with them, which facilitated how we onboarded Fortify.
Support tickets often stay open for one month to three months, which leads to customer frustration.
The technical support from OpenText is very good.
OpenText Core Application Security is highly scalable; it is running on the cloud, and elasticity is one of the best points of a cloud environment.
If a customer wants to know the tools and the technology used for their application to scan their application, they provide less information on that.
Fortify is superior to many solutions because of its scalability and that it does not require massive compute capabilities for its SAST and sandboxing features.
OpenText Core Application Security is stable and has minimal downtime, benefitting from AWS cloud availability.
In particular use cases with numerous steps, it experiences crashes.
I would say OpenText Core Application Security is not very user-friendly in terms of price; it is quite high.
It would be beneficial if Fortify could check for CVEs (Common Vulnerabilities and Exposures) in third-party libraries, which I currently use a separate dependency checker tool for.
One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together.
It did not support enough of the protocols or cryptography formats we needed, which led us to create our own solutions.
One improvement would be to integrate it with modern technologies such as AI, so we can generate test cases by providing the details so that it can generate the structure, and later the person working can modify and enhance it.
In terms of improvements for Parasoft SOAtest, some features could be added or perhaps existing areas could be improved, such as lowering prices.
Parasoft SOAtest is expensive, but it was acquired because the company was dissatisfied with Quick Test Pro.
Additionally, you can integrate Fortify in CICD pipeline, so you get real-time updates about the security issues in your pipeline.
On demand you have two levels of reports: the first from the tool, which is the same as we can get from Fortify on-premises, and a next level reporting made by experts from OpenText, leading to a more condensed and precise report as level three.
The integration of OpenText Core Application Security with existing systems for security operations benefits us by providing vulnerability management and quality gates; without both, we will always have vulnerable applications running for our customers.
Parasoft SOAtest improves the quality of the application, increases security and security compliance, and it is a cost-effective tool.
Parasoft SOAtest is very good at ensuring tests don't pass or fail until they genuinely pass or fail.
The best feature of Parasoft SOAtest is the extension tool where we can write our custom scripts.
| Product | Mindshare (%) |
|---|---|
| OpenText Core Application Security | 3.0% |
| Parasoft SOAtest | 0.7% |
| Other | 96.3% |

| Company Size | Count |
|---|---|
| Small Business | 18 |
| Midsize Enterprise | 8 |
| Large Enterprise | 45 |
| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 3 |
| Large Enterprise | 23 |
OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
Parasoft SOAtest delivers fully integrated API and web service testing capabilities that automate end-to-end functional API testing. Streamline automated testing with advanced codeless test creation for applications with multiple interfaces (REST & SOAP APIs, microservices, databases, and more).
SOAtest reduces the risk of security breaches and performance outages by transforming functional testing artifacts into security and load equivalents. Such reuse, along with continuous monitoring of APIs for change, allows faster and more efficient testing.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.