No more typing reviews! Try our Samantha, our new voice AI agent.

OpenText Static Application Security Testing vs Tenable Security Center comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.8
OpenText Static Application Security Testing received mixed reviews, praising cost savings and partnerships, but highlighting challenges in quantifying ROI.
Sentiment score
6.5
Tenable Security Center boosts ROI by minimizing costs, enhancing security, reducing manpower needs, and preventing costly data breaches.
If we cannot adjust how to operate the solution, then it becomes very difficult, so hearing and initial tuning are very important.
Marketing Expert at J's communication
Through the use of Tenable Security Center, my clients achieve more efficient patching and gain visibility and understanding of security operations, leading to improved resilience and infrastructure insight.
Solution engineer at EXPERTience
 

Customer Service

Sentiment score
6.7
Generally positive with dedicated teams, though some seek improvements in ticket system and responsiveness for OpenText support.
Sentiment score
7.4
Tenable Security Center customer support is responsive and knowledgeable, with U.S. support rated higher than the European counterpart.
The technical support has been good because we always received answers to our questions.
Manager at DTEK
The customer service and support for Fortify Static Code Analyzer are better than those for LoadRunner.
CTO at Marco Technology
When we could not resolve an issue with the vendor, we referred to them and raised a ticket, which usually resulted in good support from their team.
Head of Information Security at a consultancy with 1,001-5,000 employees
Longer response times and less thorough assistance.
Solution engineer at EXPERTience
 

Scalability Issues

Sentiment score
7.8
OpenText SAST is scalable for various project sizes but needs improvement in speed and infrastructure management.
Sentiment score
8.0
Tenable Security Center is praised for its seamless scalability, adaptability, and integration, accommodating diverse organizational needs and sizes effectively.
Fortify Static Code Analyzer integrates well and is scalable.
CTO at Marco Technology
I can scale it extensively with the use of agents, allowing scanning in restrictive environments and loosely connected devices.
Solution engineer at EXPERTience
Scalability is a bit limited with Tenable Security Center.
Cyber Security Consultant at a tech services company with 1-10 employees
 

Stability Issues

Sentiment score
7.5
OpenText Static Application Security Testing is reliable and stable, with improvements since version 19.10, and benefits from proper training.
Sentiment score
8.0
Tenable Security Center is highly stable and reliable, handling large tasks efficiently with users rating its stability highly.
The stability of Fortify Static Code Analyzer is generally good.
CTO at Marco Technology
I would rate the product stability as an eight.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The stability of the solution is outstanding.
Solution engineer at EXPERTience
 

Room For Improvement

OpenText SAST faces high costs, complex use, false positives, and needs better integration, language support, and feature enhancements.
Users desire improved reporting, third-party integration, interface design, vulnerability handling, web scanning, pricing, support, and user-friendly features.
We would appreciate if the AI could give us more information about improvements and reduce the number of false positives, but this solution doesn't have this function yet.
Manager at DTEK
While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
It should be easier to install, perhaps through a container-based approach where everything is combined into one image or pack of containers.
CTO at Marco Technology
It's important for Tenable to catch up on testing capabilities that are present in solutions like Qualys.
Cyber Security Consultant at a tech services company with 1-10 employees
The reports and plugins for reports and scans could benefit from enhancements.
IT Helpdesk at a manufacturing company with 51-200 employees
Translating reports into European languages is especially relevant in Central Eastern Europe, where clients often require reports in local languages.
Solution engineer at EXPERTience
 

Setup Cost

Enterprise users find OpenText Static Application Security Testing's pricing high but consider it economical compared to other major solutions.
Tenable Security Center is costly per asset, with options including subscription and perpetual licenses, generally pricier than competitors.
My experience with the pricing, setup costs, and licensing has been good.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The pricing of Fortify Static Code Analyzer is good, with a flexible model that allows customers to choose a setup that suits their needs.
CTO at Marco Technology
Tenable Security Center is quite expensive, particularly for the CEE region, causing us to lose cases due to its pricing.
Solution engineer at EXPERTience
The product is somewhat pricey, reflecting its valuable features and status as a high-quality solution in the vulnerability management market.
IT Helpdesk at a manufacturing company with 51-200 employees
The price of Tenable Security Center is not so high; it's relatively a cheaper solution.
Marketing Expert at J's communication
 

Valuable Features

OpenText SAST enhances security by automating vulnerability detection, integrating across tools, and providing detailed remediation and compliance guidance.
Tenable Security Center offers comprehensive vulnerability management with intuitive tools, strong integration, and flexible compliance for effective threat detection.
Fortify Static Code Analyzer has the capability of giving fewer false positives compared to other tools.
Lead Information Security Analyst at a financial services firm with 10,001+ employees
The most valuable feature of Fortify Static Code Analyzer is its extensive language support, covering many languages from legacy ones to the newest.
CTO at Marco Technology
The most impactful feature of Fortify Static Code Analyzer in identifying vulnerabilities is the ratio of total number of vulnerabilities to false positives.
Manager at DTEK
We obtained good reports showing when patches were closed and the details of each patch, including who executed it and everything related to the patching process until it was closed.
Head of Information Security at a consultancy with 1,001-5,000 employees
The most effective feature of Tenable Security Center for detecting vulnerabilities is its capability for critical mapping.
Cyber Security Consultant at a tech services company with 1-10 employees
Tenable Security Center is a relatively very good solution, and I don't think it needs improvement; it's a perfect solution.
Marketing Expert at J's communication
 

Categories and Ranking

OpenText Static Application...
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
19
Ranking in other categories
Static Code Analysis (7th)
Tenable Security Center
Average Rating
8.2
Reviews Sentiment
7.2
Number of Reviews
56
Ranking in other categories
Vulnerability Management (8th), Cloud Security Posture Management (CSPM) (12th), Risk-Based Vulnerability Management (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. OpenText Static Application Security Testing is designed for Static Code Analysis and holds a mindshare of 5.0%, down 11.4% compared to last year.
Tenable Security Center, on the other hand, focuses on Risk-Based Vulnerability Management, holds 7.5% mindshare, down 12.6% since last year.
Static Code Analysis Mindshare Distribution
ProductMindshare (%)
OpenText Static Application Security Testing5.0%
Veracode11.3%
Checkmarx One9.1%
Other74.6%
Static Code Analysis
Risk-Based Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Tenable Security Center7.5%
Qualys VMDR9.7%
Rapid7 InsightVM7.8%
Other75.0%
Risk-Based Vulnerability Management
 

Featured Reviews

DK
Lead Information Security Analyst at a financial services firm with 10,001+ employees
Focuses on detailed scans to find critical vulnerabilities while ensuring minimal false positives
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less than the current latest version. It would be really helpful to include trending vulnerabilities and how to manage them. While it includes all the OWASP top factors, AI has come into the picture, so those updates should also be considered. I haven't thought much about additional features for improvement since I am using it daily. Most of our work revolves around scanning and providing the results, which sometimes feels like a crunch. However, I believe rule pack updates should be implemented. It feels easy to upgrade to the latest version as well.
reviewer1534134 - PeerSpot reviewer
Head of Information Security at a consultancy with 1,001-5,000 employees
Centralized analytics have strengthened patch visibility and support efficient regulatory reporting
From my experience, I assess the product's analytics capabilities as successful. It helped us significantly with patching and managing the risk of the patching process across all our environments, including network devices with Windows and Unix systems. The product covered several environments and gave us exactly what we needed in our environment. Tenable Security Center's centralized platform helped with risk assessment and management across our IT environments. It covered the patching process, and we previously faced many issues regarding how to patch different environments, how to monitor the patching process, and whether it was successful or not. We obtained good reports showing when patches were closed and the details of each patch, including who executed it and everything related to the patching process until it was closed. This gave us good details about the process which helped us significantly in our reporting and even in audits, whether internal or external. We learned how to close audit issues safely and successfully. We used the dashboards for real-time threat insights and extracted several dashboards from Tenable Security Center. We use these dashboards in our cybersecurity dashboard and committees that we have. These dashboards are part of our committees, especially the cybersecurity committee and other committees that we attend.
report
Use our free recommendation engine to learn which Static Code Analysis solutions are best for your needs.
905,526 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
26%
Manufacturing Company
9%
Computer Software Company
8%
Government
6%
Financial Services Firm
12%
Manufacturing Company
11%
Government
8%
Computer Software Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise3
Large Enterprise11
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise12
Large Enterprise27
 

Questions from the Community

What is your experience regarding pricing and costs for Fortify Static Code Analyzer?
My experience with the pricing, setup costs, and licensing has been good. We have the scan machines, and we are planning to request more from Micro Focus now. We have calls every month or every oth...
What needs improvement with Fortify Static Code Analyzer?
I think Fortify Static Code Analyzer could be improved by updating the number of rule packs according to the latest vulnerabilities we find each year. We have updated to a version that is one less ...
What is your primary use case for Fortify Static Code Analyzer?
Our main use cases for Fortify Static Code Analyzer typically involve trying to figure out the critical vulnerabilities. It depends on the type of scans that we are doing, whether it is a release s...
What is your experience regarding pricing and costs for Tenable SC?
The price of Tenable Security Center is not so high; it's relatively a cheaper solution.
What needs improvement with Tenable SC?
We did conduct a long implementation which relates to what I think can be improved about Tenable Security Center. In some cases, we needed to refer back to Tenable itself, and in other cases, we ne...
What is your primary use case for Tenable SC?
The typical use case for Tenable Security Center is that it is an on-premise solution, and it can use the agent and active scanning, which is needed by governmental organizations and manufacturers,...
 

Also Known As

Fortify Static Code Analysis SAST
Tenable.sc, Tenable Unified Security, Tenable SecurityCenter
 

Overview

 

Sample Customers

Information Not Available
IBM, Sempra Energy, Microsoft, Apple, Adidas, Union Pacific
Find out what your peers are saying about Veracode, Checkmarx, Perforce and others in Static Code Analysis. Updated: June 2026.
905,526 professionals have used our research since 2012.