No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 AppSpider vs The Fastly Next-Gen WAF (powered by Signal Sciences) comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 AppSpider
Average Rating
7.8
Reviews Sentiment
6.7
Number of Reviews
14
Ranking in other categories
Static Application Security Testing (SAST) (29th)
The Fastly Next-Gen WAF (po...
Average Rating
7.6
Reviews Sentiment
4.8
Number of Reviews
4
Ranking in other categories
Web Application Firewall (WAF) (30th)
 

Mindshare comparison

Rapid7 AppSpider and The Fastly Next-Gen WAF (powered by Signal Sciences) aren’t in the same category and serve different purposes. Rapid7 AppSpider is designed for Static Application Security Testing (SAST) and holds a mindshare of 0.8%, up 0.5% compared to last year.
The Fastly Next-Gen WAF (powered by Signal Sciences), on the other hand, focuses on Web Application Firewall (WAF), holds 1.2% mindshare, up 0.9% since last year.
Static Application Security Testing (SAST) Mindshare Distribution
ProductMindshare (%)
Rapid7 AppSpider0.8%
SonarQube14.5%
Checkmarx One9.2%
Other75.5%
Static Application Security Testing (SAST)
Web Application Firewall (WAF) Mindshare Distribution
ProductMindshare (%)
The Fastly Next-Gen WAF (powered by Signal Sciences)1.2%
Imperva Application Security Platform7.4%
Fortinet FortiWeb5.4%
Other86.0%
Web Application Firewall (WAF)
 

Featured Reviews

HW
Marketing Expert at J's communication
Clients benefit from broad authentication and effective crawling but need localization improvements
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who require security assessments One of the most valuable features of AppSpider is its broad range of authentication identification, which is a key reason for its utilization.…
reviewer2161107 - PeerSpot reviewer
Staff Engineer at a retailer with 1,001-5,000 employees
Room for improvement with user interface while competitive pricing impresses
It is managed through Infrastructure as Code, so all configurations can be managed in the code itself, which is beneficial. Because it uses rules, it is easy to set up, and we have many different sites where the configurations are straightforward. Though the UI is not very interactive, which is a downside, we can manage many things. The UI is not very intuitive and could be better. However, we manage all the configurations through code, which is easy to maintain. It has extensive anomaly detection capabilities, so the traffic is classified into several categories where thresholds can be defined and customized based on false positives and false negatives. This is advantageous because you do not need to tweak it very often. Once you set it up, an audit once a quarter would suffice. Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Customer service has been quite good."
"It scans all the components developed within a web application."
"The initial deployment is very straightforward and simple."
"It does a scan that performs about 100 checks on web applications and produces a clear report on all of the vulnerabilities that are found."
"I like the ability the product has to detect vulnerabilities quickly, when it has been released in our environment, then displaying them to us."
"The most valuable feature is the reporting, which is compliant with international standards."
"The entire solution is interactive and has a point-and-click user experience, which makes it easy to find items or drill down on information, and you don't need specialized skills to use the product."
"When it is set up properly, it can do scanning on web apps with multiple engines automatically."
"Because The Fastly Next-Gen WAF (powered by Signal Sciences) is API-driven, we have integrations with the CI/CD pipeline through GitHub Actions, making it easy to integrate."
"Fastly (Signal Sciences) integrates and tags the intermittent traffic based on patterns. It generates signals and provides them in a dashboard where we can view them and decide whether to allow or deny traffic. It's a more advanced and easy-to-navigate dashboard."
"When configuring a web application firewall using Signal Sciences, we configure a rule whereby no one except a few people can access the application."
"The product's most valuable feature is its ability to set up the rules easily."
 

Cons

"The product needs to be able to scale for large companies, like ours. We have millions of IP addresses that need to be scanned, and the scalability is not great."
"The dashboard and interface are crucial and they need some improvement."
"Implementing Rapid7 AppSpider requires scanning and self-identification mechanisms. You can add different types of authentication to each scan."
"The product needs to be able to scale for large companies, like ours. We have millions of IP addresses that need to be scanned, and the scalability is not great."
"There are some glitches with stability, and it is an area for improvement."
"Support response times are slow and can be improved."
"The solution is too slow. It could take a full day to scan. Competitors are much faster."
"There are some glitches with stability, and it is an area for improvement."
"Even if we create some custom rules, Signal Sciences cannot capture some of the malicious traffic."
"The areas that could be improved in Signal Sciences include the effectiveness of rules, as many didn't function optimally and required custom rule-writing to address bypasses for WAF."
"The UI is not very intuitive and could be better."
"Fastly don't support caching for China users. That's the only feature lacking compared to Akamai."
 

Pricing and Cost Advice

"The price of Rapid7 AppSpider cost 9,000 annually but there is limited usage. Large companies are able to negotiate a better price or a better deal for the usage with the vendor."
"AppSpider is closed-source software and you need to acquire a license in order to use it."
"The licensing cost depends on the number of users."
"It is expensive if you want to buy the Enterprise version that is able to scan multiple applications at once."
"The price is pretty fair."
"The pricing is 50% less than Akamai."
"Signal Sciences is pretty cheap compared to other solutions."
"The product has an affordable cost."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
896,692 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
11%
University
10%
Financial Services Firm
10%
Computer Software Company
7%
Manufacturing Company
13%
Retailer
9%
Financial Services Firm
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business12
Midsize Enterprise2
Large Enterprise1
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Rapid7 AppSpider?
The price is not high, but for Japanese customers, localization may incur additional costs.
What needs improvement with Rapid7 AppSpider?
For Japanese customers, localization is needed. The product should offer a GUI in Japanese and provide Japanese reports for end-users.
What is your primary use case for Rapid7 AppSpider?
Our clients use AppSpider to address security concerns for their websites. It is particularly used by customers who require security assessments.
What is your experience regarding pricing and costs for Signal Sciences?
The pricing is very competitive compared to other providers. The pricing is definitely a factor in our decision-making process.
What needs improvement with Signal Sciences?
We do use it, but the UI can be improved as we mostly work through the CI/CD. It provides support, but sometimes it is hard to navigate unless you are very familiar with it.
What is your primary use case for Signal Sciences?
The CDN is for caching and The Fastly Next-Gen WAF (powered by Signal Sciences) is for protecting the servers from malicious traffic. They both perform different jobs and serve different purposes, ...
 

Also Known As

AppSpider
Signal Sciences Next-Gen WAF, Signal Sciences RASP
 

Overview

 

Sample Customers

Microsoft
Chef, Adobe, Datadog, Etsy, GrubHub, Vimeo, SendGrid, Under Armour, Duo, AppNexus
Find out what your peers are saying about SonarSource Sàrl, Checkmarx, Veracode and others in Static Application Security Testing (SAST). Updated: May 2026.
896,692 professionals have used our research since 2012.