Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

HCL AppScan provides comprehensive templates for compliance needs like PCI.
It allows simultaneous scanning of multiple websites, enhancing efficiency.
It facilitates the integration of security checks into the development process.
It offers advanced vulnerability identification with detailed remediation steps.
It has strong integration with the SDLC, especially during the coding phase.

CONS

HCL AppScan needs to improve its handling of false positives.
Security features should be enhanced in HCL AppScan.
Performance optimization is required for faster scanning in HCL AppScan.
HCL AppScan should improve its CI/CD integration capabilities.
Integrating HCL AppScan with other tools presents challenges.
 

HCL AppScan Pros review quotes

it_user634890 - PeerSpot reviewer
Chief information with 5,001-10,000 employees
Mar 29, 2017
It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply.
it_user634947 - PeerSpot reviewer
Application Security Consultant at a financial services firm with 10,001+ employees
Mar 29, 2017
It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.
PN
Security Consultant at a consultancy with 10,001+ employees
Dec 24, 2017
IBM AppScan has made our work easy, as we can do four to five scans of websites at a time, which saves time when it comes to vulnerability.
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,425 professionals have used our research since 2012.
it_user841920 - PeerSpot reviewer
Business Development Manager at a tech services company with 10,001+ employees
Mar 21, 2018
The static scans are good, and the SaaS as well.
it_user841956 - PeerSpot reviewer
Director Of Product Cyber Security at a aerospace/defense firm with 10,001+ employees
Mar 21, 2018
For me, as a manager, it was the ease of use. Inserting security into the development process is not normally an easy project to do. The ability for the developer to actually use it and get results and focuses, that's what counted.
SeniorSe47a0 - PeerSpot reviewer
Senior Security Specialist at a transportation company with 10,001+ employees
Mar 22, 2018
I like the recording feature.
TH
Director For Security Products at a manufacturing company with 10,001+ employees
Mar 22, 2018
It has certainly helped us find vulnerabilities in our software, so this is priceless in the end.
it_user842904 - PeerSpot reviewer
CTO at Anzen
Mar 22, 2018
Usually when we deploy the application, there is a process for ethical hacking. The main benefit is that, the ethical hacking is almost clean, every time. So it's less cost, less effort, less time to production.
SeniorCl3552 - PeerSpot reviewer
Senior Cloud Architect at a tech company with 1,001-5,000 employees
Mar 25, 2018
It provides a better integration for our ecosystem.
JS
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
May 15, 2019
This solution saves us time due to the low number of false positives detected.
 

HCL AppScan Cons review quotes

it_user634890 - PeerSpot reviewer
Chief information with 5,001-10,000 employees
Mar 29, 2017
We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices.
it_user634947 - PeerSpot reviewer
Application Security Consultant at a financial services firm with 10,001+ employees
Mar 29, 2017
We would like to integrate with some of the other reporting tools that we're planning to use in the future.
PN
Security Consultant at a consultancy with 10,001+ employees
Dec 24, 2017
It has crashed at times.
Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,425 professionals have used our research since 2012.
it_user841920 - PeerSpot reviewer
Business Development Manager at a tech services company with 10,001+ employees
Mar 21, 2018
There is not a central management for static and dynamic.
it_user841956 - PeerSpot reviewer
Director Of Product Cyber Security at a aerospace/defense firm with 10,001+ employees
Mar 21, 2018
I think being able to search across more containers, especially some of the docker elements. We need a little tighter integration there. That's the only thing I can see at this point.
SeniorSe47a0 - PeerSpot reviewer
Senior Security Specialist at a transportation company with 10,001+ employees
Mar 22, 2018
It's a little bit basic when you talk about the Web Services. If AppScan improved its maturity on Web Services testing, that would be good.
TH
Director For Security Products at a manufacturing company with 10,001+ employees
Mar 22, 2018
​IBM Security AppScan Source is rather hard to use​.
it_user842904 - PeerSpot reviewer
CTO at Anzen
Mar 22, 2018
I would love to see more containers. Many of the tools are great, they require an amount of configuration, setup and infrastructure. If most the applications were in a container, I think everything would be a little bit faster, because all our clients are now using containers.
SeniorCl3552 - PeerSpot reviewer
Senior Cloud Architect at a tech company with 1,001-5,000 employees
Mar 25, 2018
Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products.
JS
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
May 15, 2019
IBM Security AppScan needs to add performance optimization for quickly scanning the target web applications.