No more typing reviews! Try our Samantha, our new voice AI agent.

Rapid7 Penetration Testing Services vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Rapid7 Penetration Testing ...
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
1
Ranking in other categories
Penetration Testing Services (9th)
Veracode
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
208
Ranking in other categories
Application Security Tools (3rd), Static Application Security Testing (SAST) (2nd), Container Security (8th), Software Composition Analysis (SCA) (3rd), Static Code Analysis (1st), Dynamic Application Security Testing (DAST) (1st), Application Security Posture Management (ASPM) (1st)
 

Mindshare comparison

Rapid7 Penetration Testing Services and Veracode aren’t in the same category and serve different purposes. Rapid7 Penetration Testing Services is designed for Penetration Testing Services and holds a mindshare of 1.9%, down 2.3% compared to last year.
Veracode, on the other hand, focuses on Application Security Tools, holds 4.6% mindshare, down 10.3% since last year.
Penetration Testing Services Mindshare Distribution
ProductMindshare (%)
Rapid7 Penetration Testing Services1.9%
HackerOne14.1%
Bugcrowd12.5%
Other71.5%
Penetration Testing Services
Application Security Tools Mindshare Distribution
ProductMindshare (%)
Veracode4.6%
SonarQube16.3%
Checkmarx One9.9%
Other69.2%
Application Security Tools
 

Featured Reviews

Gabriel Woolverton - PeerSpot reviewer
Penetration Tester at a tech consulting company with 1-10 employees
Wide range of coverage and free
A useful improvement would be to have white papers for specific vulnerabilities readily available. It seems like they are not always linked when you are looking for a vulnerability identifier in the database. It would be useful to ensure that that information is readily available. That way, if you need to dive deeper into a vulnerability, you would have the capability to do so basically right there on the website.
reviewer2703864 - PeerSpot reviewer
Head of Security Architecture at a healthcare company with 5,001-10,000 employees
Onboarding developers successfully while improving code security through IDE integration
Regarding room for improvement, we have some problems when onboarding new projects because the build process has to be done in a certain way, as Veracode analyzes the binaries and not the code by itself alone. If the process is not configured correctly, it doesn't work. That's one of the things that we are discussing with Veracode. Something positive that we've been able to do is submit formal feature requests to them, and they are working on them; they've already solved some of them. This encourages us to propose new ideas and improvements. Another improvement that we asked for this use case is to be able to configure how Veracode Fix proposes and fixes because sometimes it makes proposals using libraries that go against our architecture design made by the enterprise architecture team. For example, we want them to propose using another library, and that's something we already asked Veracode, and they are working on it. We want to specify when you see this kind of vulnerability, you can only propose these two options.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The initial setup is very straightforward. This is not a tool that you have to set up yourself. All you have to do is just access their web-based vulnerability database application, which is open source and available to pretty much anyone."
"Rapid7's wide range of coverage, in terms of vulnerabilities and exploits linked to vulnerabilities, is its most valuable feature."
"The result was amazing, enabling us to find everything that could potentially create a problem for us."
"One thing we like is the secret detection feature. It has helped us to discover keys stored in our settings file as a TXT document. We can address that vulnerability by using encryption. We can even scan Docker images for vulnerabilities. Static analysis is another good feature of Veracode because we can run a security scan during development to identify the vulnerabilities."
"My experience with Veracode across the board every time, in all products, the technology, the product, the service, and the salespeople are fabulous."
"On the whole, Veracode has improved the quality of our code and the end product."
"Veracode has saved us the cost of hundreds of employee hours by streamlining our vulnerability discovery process in legacy code, and by improving the quality of code released into production."
"Another feature of Veracode is that they provide e-learning, but the e-learning is not basic, rather it is quite advanced... in the e-learning you can check into best practices for developing code and how to prevent improper management of some component of the code that could lead to a vulnerability. The e-learning that Veracode provides is an extremely good tool."
"The static code analyzer portion is adequate."
"Veracode provides faster scans compared to other static analysis security testing tools."
 

Cons

"A useful improvement would be to have white papers for specific vulnerabilities readily available. It seems like they are not always linked when you are looking for a vulnerability identifier in the database."
"A useful improvement would be to have white papers for specific vulnerabilities readily available."
"We have some constraints interacting with Veracode self-support. I'm not talking about their technical support. I'm talking about self-support. We sometimes have a hard time communicating with them."
"The solution recently doubled in price over the past year, which is why I've decided to move away from it."
"In the last month or so, I had a problem with the APIs when doing some implementations. The Veracode support team could be more specific and give me more examples. They shouldn't just copy the URL for a doc and send it to me."
"It needs more timely support for newer languages and framework versions."
"I've seen slightly better static analysis tools from other companies when it comes to speed and ease of use."
"It would be nice if Veracode were bundled with some preferred vendors like Salesforce and offered at a discount."
"I noticed there is no integration with Bamboo."
"There is also a size limit of 100 MB so we cannot upload files that are larger than that. That could be improved. Also, the duration of the scan is a bit too long."
 

Pricing and Cost Advice

Information not available
"It's worth the value"
"Its pricing is fair."
"Depending on the number of users, my company makes payments toward the solution's licensing costs."
"The price of Veracode Static Analysis is on the higher side."
"It is pricey. There is a lot of value in the product, but it is a costly tool."
"Veracode is expensive. Some of its products are expensive. I don't think it's way more expensive than its competitors. The dynamic is definitely worth it, as I think it's cheaper than the competitors. The static scan is a little bit more expensive, around 20 percent more expensive. The manual pen test is more expensive, but it is an expensive service because it's a manual pen test and we also do retests. I don't think it is way more expensive than the competitors, but it's about 15 to 20 percent more expensive."
"The pricing is fair. You get a lot out of the product."
"It is very reasonably priced compared to what we were paying our previous vendor. For the same price, we are getting much more value and reducing our AppSec costs from 40 to 50 percent."
report
Use our free recommendation engine to learn which Penetration Testing Services solutions are best for your needs.
885,728 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
University
10%
Manufacturing Company
7%
Educational Organization
7%
Financial Services Firm
16%
Computer Software Company
11%
Manufacturing Company
10%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise45
Large Enterprise114
 

Questions from the Community

Ask a question
Earn 20 points
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
What do you like most about Veracode Static Analysis?
I like its integration with GitHub. I like using it from GitHub. I can use the GitHub URL and find out the vulnerabilities.
What is your experience regarding pricing and costs for Veracode Static Analysis?
My experience with pricing, setup cost, and licensing for Veracode is that it is fairly moderate.
 

Also Known As

No data available
Crashtest Security , Veracode Detect
 

Overview

 

Sample Customers

Motorola, Liberty wines, Kaman Corporation
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about Horizon3.ai, HackerOne, Bugcrowd and others in Penetration Testing Services. Updated: March 2026.
885,728 professionals have used our research since 2012.