Try our new research platform with insights from 80,000+ expert users

PortSwigger Burp Suite Professional vs Qualys Web Application Scanning vs SonarQube Server (formerly SonarQube) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

As of May 2025, in the Application Security Tools category, the mindshare of PortSwigger Burp Suite Professional is 2.1%, up from 2.0% compared to the previous year. The mindshare of Qualys Web Application Scanning is 2.0%, down from 2.1% compared to the previous year. The mindshare of SonarQube Server (formerly SonarQube) is 24.5%, down from 27.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
 

Featured Reviews

Anuradha.Kapoor Kapoor - PeerSpot reviewer
Offers efficient scanning of entire websites but presence of false positive bugs, leading to time-consuming efforts in distinguishing real bugs from false alarms
We have found that so many times, false positive bugs are there, and then we spend a lot of time basically separating them from real bugs. So that's the reason we are looking for some other tool. So we were in discussion with Acunetix. Therefore, the false positive rate is, like, something that we would like to improve. What we are looking for is if this false positive rate goes down because we were OWASP Zap tool users, which was free anyway. But there were a lot of false positives there, and we used to spend a lot of time, like, for security reasons, reproducing those bugs for the development team to fix it. So then we thought, okay, why not we go with the tool? Even if it is not very expensive. But still, every year, we have to renew the license. And we got this tool. Again, we found that in this tool also, even if it is less, there are still a lot of false positive bugs out there. So we again have to spend so much time. So we hired a security tester, who was basically using Acunetix in his previous company for almost three years, and then you said that in that scanning is very slow. The scanning is also slow. Like, sometimes the site scan takes eight hours, six to eight hours. Yeah. And whereas in Acunetix, it took three to four hours. And plus, there are no false positives. I'm not saying none but there's very little. But here, the rate sometimes is very high. These are the two features I think we would like to improve further.
Kelvin Oladipo - PeerSpot reviewer
User-friendly scanning provides valuable vulnerability insights, but pricing improvements are needed
Qualys Web Application Scanning ( /products/qualys-web-application-scanning-reviews ) is user-friendly, easy to understand, easy to use, and easy to deploy. Credential scanning is very effective because it goes in-depth into the system, crawling the pages, and reporting on vulnerabilities. The product helps by providing options for remediating vulnerabilities it finds, making it really useful.
Wang Dayong - PeerSpot reviewer
Easy to integrate and has a plug-in that supports both C and C++ languages
The product provides false reports sometimes. It also fails to understand the context of the code. It reports that a line of code has issues without considering its relation with the previous line. The product should improve the report quality. While it asks us to improve the code quality, it would be good if it also suggests how to improve the quality.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We are mostly using it for scanning the entire website. So, we basically create a script with the entire website and then run it for different injections."
"In my area of expertise, I feel like it has almost everything I could possibly require at this moment."
"PortSwigger Burp Suite does not hamper the node of the server, and it does not shut down the server if it is running."
"Some of the extensions, available using Burp Extender, are also very good and we have found issues by using them."
"The feature that we have found most valuable is that it comes with pre-set configurations. They have a set of predefined options where you can pick one and start scanning. We also have the option of creating our own configurations, like how often do the applications need to be scanned."
"The solution is stable."
"You can scan any number of applications and it updates its database."
"BurpSuite helps us to identify and fix silly mistakes that are sometimes introduced by our developers in their coding."
"The most valuable features are the scheduled scanning, detailed reports, asset management, the knowledge database, and the overall product framework."
"Qualys Web Application Scanning is user-friendly, easy to understand, easy to use, and easy to deploy."
"I have found the detection of vulnerabilities tool thorough with good results and the graphical display output to be wonderful and full of colors. It allows many types of outputs, such as bar and chart previews."
"Licensing is the most valuable. Qualys provides the best licensing for companies. It is the best product for the development purposes of web applications. The product has a lot of integrations."
"We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
"Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
"It is a good product for website penetration testing to detect vulnerabilities."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"The most valuable feature is the security hotspot feature that identifies where your code is prone to have security issues."
"The most valuable features are the analysis and detection of issues within the application code."
"It is a very good tool for analysis and security vulnerability checking."
"SonarQube: Recording of issues over a period of time, with an indication of the addition in the new issues or the reduction of existing issues (which were fixed)."
"Code Convention: Using the tool to implement some sort of coding convention is really useful and ensures that the code is consistent no matter how many contributors."
"The solution has a plug-in that supports both C and C++ languages."
"Strong code evaluation for budget-minded clients."
"The code coverage feature is very good."
 

Cons

"In the Professional version, we cannot link it with the CI/CD process."
"The use of system memory is an area that can be improved because it uses a lot."
"The number of false positives need to be reduced on the solution."
"The solution lacks sufficient stability."
"I would like to see the return of the spider mechanism instead of the crawling feature. Burp Suite's earlier version 1.7 had an excellent spider option, and it would be beneficial if Burp incorporated those features into the current version. The crawling techniques used in the current version are not as efficient as those used in earlier versions."
"One area for improvement is the integrated browser, Chromium. Single Sign-On (SSO) methods like Microsoft authentication login sometimes fail and show errors. As a workaround, I have to use a different browser, such as Firefox, to log in and make Burp work."
"It would be beneficial to have privileged access management as a part of Burp Suite Professional."
"The technical support team's response time is mostly delayed and should be improved."
"In terms of the Policy Compliance model which they currently have, not all the platforms are being covered. If they could improve on the Policy Compliance model, since there are policies which are benchmarked against it, this will be helpful for us."
"I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus."
"There's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage."
"The product's pricing could be better."
"We receive false positives sometimes when using a solution that could be improved. However, the technical team provides us with the exact explanation why it was giving us that kind of error."
"The UI is not user-friendly and you don't have a yearly reporting facility where you can slice and dice in different jobs."
"The area of false positives could be improved. There are quite a number of false positives as compared to other solutions. They could probably fine tune the algorithm to be able to reduce the number of false positives being detected."
"Qualys Web Application Scanning is very complex to use, and its graphical interface is not very user-friendly."
"SonarQube could improve by adding automatic creation of tasks after scanning and more support for the Czech language."
"Depending on the tool's configuration, sometimes you get false alarms that are unimportant to you."
"I find it is light on the security side."
"It should be user-friendly."
"Expression of common vulnerabilities and exposures is not always current."
"The reporting can be improved."
"In terms of analysis and findings, other tools provide more in-depth insights and detailed steps to mitigate or handle issues."
"There are sometimes security breaches in our code, which aren't be caught by SonarQube. In the security area, SonarCube has to improve. It needs to better compete with other products."
 

Pricing and Cost Advice

"We pay a yearly licensing fee for the solution, which is neither cheap nor expensive."
"Our licensing cost is approximately $400 USD per year."
"It's a lower priced tool that we can rely on with good standard mechanisms."
"The pricing of the solution is cost-effective and is best suited for small and medium-sized businesses."
"PortSwigger Burp Suite Professional is an expensive solution."
"PortSwigger Burp Suite Professional is expensive compared to other tools."
"Pricing is not very high. It was around $200."
"The pricing of the solution is reasonable. We only need to pay for the annual subscription. I rate the pricing five out of ten."
"The cost is $30,000 USD for one year to cover WAS (Web Application Security) and the VM (Virtual Machine) security in a company with 200 employees."
"It is an expensive platform."
"Try the free trial of the product to understand the basic working mechanisms.​"
"Qualys Web Application Scanning's pricing is a bit expensive compared to other solutions available in the market."
"There are different options available with respect to licensing."
"The product is expensive, at least initially, in comparison to other products in this category."
"The product has a very good licensing model."
"Qualys WAS' pricing is competitive."
"Can try developer version for 14 days on the free trial."
"There is both a free and licensed version. The free version has limitations on development languages and support."
"SonarQube price is a little bit higher than Kiuwan's. Kiuwan also gives a little bit of flexibility in terms of pricing."
"We are using the Community edition of SonarQube."
"The price point on SonarQube is good."
"This solution is free."
"We use the tool's community edition."
"The beauty of this solution is the free open-source version is capable enough in doing pretty much what an enterprise-level version can do."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
851,823 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
13%
Government
12%
Manufacturing Company
7%
Computer Software Company
16%
Financial Services Firm
14%
Manufacturing Company
10%
Government
8%
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Is OWASP Zap better than PortSwigger Burp Suite Pro?
OWASP Zap and PortSwigger Burp Suite Pro have many similar features. OWASP Zap has web application scanning available...
What do you like most about PortSwigger Burp Suite Professional?
The solution helped us discover vulnerabilities in our applications.
What is your experience regarding pricing and costs for PortSwigger Burp Suite Professional?
I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.
What do you like most about Qualys Web Application Scanning?
The vulnerability management feature is a strong one. And also the patch management feature.
What needs improvement with Qualys Web Application Scanning?
I would like it to be cheaper because it is a bit expensive compared to competitors like Tenable Nessus ( /products/t...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and securi...
 

Also Known As

Burp
Qualys WAS
Sonar
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Google, Amazon, NASA, FedEx, P&G, Salesforce
BskyB, Cartagena, ClearPoint Learning Systems, Connect Group, du, Fortrex Technologies, HBOR, HDI, Highlights for Children, The Lithuanian State Enterprise Centre of Registers, City of Miami Beach, Microsoft, MidlandHR, MSCI Inc., Northern Arizona University, Ofgem, Olympus Europa, PhoneFactor, RTL Nederland, ThousandEyes, VGZ Organisatie B.V.
Information Not Available
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: May 2025.
851,823 professionals have used our research since 2012.