No more typing reviews! Try our Samantha, our new voice AI agent.

OpenText Core Application Security vs Pentest-Tools.com comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 29, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

OpenText Core Application S...
Ranking in Static Application Security Testing (SAST)
9th
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
64
Ranking in other categories
Application Security Tools (10th)
Pentest-Tools.com
Ranking in Static Application Security Testing (SAST)
25th
Average Rating
8.0
Reviews Sentiment
4.6
Number of Reviews
2
Ranking in other categories
Penetration Testing Services (8th)
 

Mindshare comparison

As of August 2026, in the Static Application Security Testing (SAST) category, the mindshare of OpenText Core Application Security is 3.2%, down from 4.1% compared to the previous year. The mindshare of Pentest-Tools.com is 0.5%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
OpenText Core Application Security3.2%
Pentest-Tools.com0.5%
Other96.3%
Static Application Security Testing (SAST)
 

Featured Reviews

Himanshu_Tyagi - PeerSpot reviewer
Lead Cybersecurity at TBO
Supports secure development pipelines and improves issue detection but limits internal visibility and needs broader dashboard integration
If you have an internal team and you want your internal team to validate false positives, basically to determine whether it's a valid issue or an invalid issue, then I wouldn't recommend it much. That was the only reason we migrated from Fortify on Demand to another solution. Fortify has another tool which is Fortify WebInspect. On Demand is the outsourcing solution, and WebInspect you can use with your in-house team, which is basically the product developed by the Fortify team. For automated scanning, Fortify helps a lot. Regarding the visibility for the internal team, everyone is moving toward the DevSecOps side, and Fortify team has made good progress that you can integrate into your CICD pipeline. One thing I would highlight is if Fortify can focus more on the centralized dashboard of the tools because nowadays, tools such as SentinelOne also exist for identifying security issues, but they have a centralized dashboard that merges their cloud solution and application security side solution together. If you have one tool that works for different solutions, it helps a lot. They are doing good, but they should invest more on the AI side as well because AI security is evolving these days. On the cloud side, they have already made good progress, but I believe they should explore the new area related to AI security as well.
SangramGupta - PeerSpot reviewer
Security Consultant at Deloitte
Platform has strengthened attack surface visibility and vulnerability validation but needs better remediation tracking
Pentest-Tools.com could improve in a couple of areas. First, the reporting flexibility could be enhanced. Second, there should be additional automation for remediation tracking since it currently lacks automation for this, requiring me to track remediations manually using the reports. Third, deeper integration with vulnerability management workflows could be beneficial, as I should have more options for integrating the tool with other security pen testing or application scanning tools. Regarding Pentest-Tools.com's AI capabilities, I believe there should be proper boundaries managed by their team in terms of governance and security, especially when the tool provides false positive vulnerabilities. These should also be detected on the governance side and resolved within the tool rather than manually, indicating an area for improvement in governance and compliance. In terms of the accuracy and reliability of Pentest-Tools.com's AI-generated output, I feel it can provide comprehensive output and reports. However, as it is AI-generated, the pentester or user should thoroughly check and validate the output before presenting it to stakeholders or the remediation team.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The static code analyzer provides views from a security perspective and it is easy to use compared to others."
"HP Fortify on Demand provides an independent review of third-party applications, allowing organizations to test software before purchasing, and also allowing software vendors to demonstrate the security of their software."
"The features I found most valuable is that it is very configurable and the installation was also very easy."
"Micro Focus WebInspect and Fortify code analysis tools are fully integrated with SSC portals and can instantly register to error tracking systems, like TFS and JIRA."
"The UL is easy to use compared to that of other tools, and it is highly reliable. The findings provide a lower number of false positives."
"The implementation of Micro Focus Fortify on Demand was simple, since it is on the cloud everything is automatic."
"One of the valuable features is the ability to submit your code and have it run in the background. Then, if something comes up that is more specific, you have the security analyst who can jump in and help, if needed."
"It has saved us a lot of time as we focus primarily on programming rather than tool operational work."
"Pentest-Tools.com has positively impacted my organization in two significant ways."
"If you have a lean DevOps or IT team that needs robust security scanning and professional reporting for compliance or vulnerability management without spending weeks learning CLI security tools or paying exorbitant enterprise fees, Pentest-Tools.com is easily one of the best SaaS solutions available."
 

Cons

"Fortify on Demand could be improved with support in Russia."
"It could have a little bit more streamlined installation procedure. Based on the things that I've done, it could also be a bit more automated. It is kind of taking a bunch of different scanners, and SSC is just kind of managing the results. The scanning doesn't really seem to be fully integrated into the SSC platform. More automation and any kind of integration in the SSC platform would definitely be good. There could be a way to initiate scans from SSC and more functionality on the server-side to initiate desk scans if it is not already available."
"There are frequent complaints about false positives from Fortify."
"It does scanning for all virtual machines and other things, but it doesn't do the scanning for containers. It currently lacks the ability to do the scanning on containers. We're asking their product management team to expand this capability to containers."
"Micro Focus support is slow, and they should improve that."
"Micro Focus Fortify on Demand cannot be run from a Linux Agent. When we are coding the endpoint it will not work, we have to use Windows Agent. This is something they could improve."
"The biggest deficiency is the integration with bug tracker systems."
"When we sent a question about the product to their support team, we had to wait a while but they did send us a response eventually."
"Pentest-Tools.com could improve in a couple of areas. First, the reporting flexibility could be enhanced."
 

Pricing and Cost Advice

"It's a yearly contract, but I don't remember the dollar amount."
"Micro Focus Fortify on Demand licenses are managed by our IT team and the license model is user-based."
"Fortify on Demand is more expensive than Burpsuite. I rate its pricing a nine out of ten."
"The product's cost depends on the type of license."
"Fortify on Demand is affordable, and its licensing comes with a year of support."
"It is not more expensive than other solutions, but the pricing is competitive."
"Their subscriptions could use a little bit of a reworking, but I am very happy with what they're able to provide."
"Despite being on the higher end in terms of cost, the biggest value lies in its abilities, including robust features, seamless integration, and high-quality findings."
Information not available
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Manufacturing Company
11%
Construction Company
7%
Outsourcing Company
6%
Financial Services Firm
20%
Outsourcing Company
13%
Comms Service Provider
13%
Construction Company
12%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business18
Midsize Enterprise8
Large Enterprise46
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Micro Focus Fortify on Demand?
In comparison with other tools, they're competitive. It is not more expensive than other solutions, but their pricing is competitive. The licenses for Fortify On Demand are generally bought in unit...
What needs improvement with Micro Focus Fortify on Demand?
Areas for improvement should be contextualized post the OpenText acquisition, but back when I was working with Micro Focus, they focused heavily on enterprise-centric solutions. Now, after the acqu...
What is your primary use case for Micro Focus Fortify on Demand?
For OpenText Core Application Security, I currently support a couple of my clients who are using Fortify on Demand for their web application, CRM, and sales platform. Many good features of Fortify ...
What needs improvement with Pentest-Tools.com?
Pentest-Tools.com could improve with deeper native integrations with modern CI/CD pipelines and developer platforms such as Jira or GitHub Actions for automated issue tracking and remediation workf...
What is your primary use case for Pentest-Tools.com?
Our primary use case for Pentest-Tools.com is automated web application, external and internal network vulnerability scanning. Specifically, white-box testing for our internet-facing systems, endpo...
What advice do you have for others considering Pentest-Tools.com?
The user experience for non-security specialists using Pentest-Tools.com is excellent. If you have a lean DevOps or IT team that needs robust security scanning and professional reporting for compli...
 

Also Known As

Micro Focus Fortify on Demand
No data available
 

Overview

 

Sample Customers

SAP, Aaron's, British Gas, FICO, Cox Automative, Callcredit Information Group, Vital and more.
1. Google 2. Microsoft 3. Amazon 4. Facebook 5. Apple 6. IBM 7. Oracle 8. SAP 9. Cisco 10. HP 11. Dell 12. VMware 13. Red Hat 14. SUSE 15. Ubuntu 16. CentOS 17. Fedora 18. Arch Linux 19. Gentoo 20. Slackware 21. Mageia 22. OpenSUSE 23. Manjaro 24. PopOS 25. elementary OS 26. Linux Mint 27. Ubuntu MATE 28. Zorin OS 29. Deepin
Find out what your peers are saying about OpenText Core Application Security vs. Pentest-Tools.com and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.