HCL AppScan Valuable Features
MS
MukeshSaha
Associate Principal, Software Engineering at LTI - Larsen & Toubro Infotech
AppScan's most valuable features include its ability to identify vulnerabilities accurately, provide detailed remediation steps, and the newly introduced AI-powered features that enhance its functionality further. These features collectively aim to improve security by introducing efficient AI solutions.
View full review »The platform has valuable security features, helping us identify sensitive code issues and the possibility of internal applications' exposure to external threats.
View full review »The most valuable feature of the solution is the scanning or security part.
Buyer's Guide
HCL AppScan
June 2025

Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,579 professionals have used our research since 2012.
The product has valuable features for static and dynamic testing. It is one of the leaders in the market amongst SAST solutions.
View full review »CV
CRISTIANO VIEIRA SILVA
Mechanical maintenance technician at SAQ
The most valuable feature of HCL AppScan is its integration with the SDLC, particularly during the coding phase. This allows for scanning during code construction, which is beneficial. However, I also find the DAF and penetration testing features valuable, especially for discovering vulnerabilities like those in the OWASP Top Ten.
The most valuable feature of the solution stems from the fact that it is good to run the scan faster. You can basically run the scan and take a break at work since the tool will compute the results, which makes the product quite intuitive. HCL AppScan doesn't require constant monitoring.
View full review »SG
SHIRDI SAIRAM GATTU
Application Security Engineer at a transportation company with 1,001-5,000 employees
It depends on the application, but it's generally a very user-friendly tool. Anyone can easily learn how to scan and boost their security.
View full review »The reporting part is the most valuable feature.
View full review »RR
Ramy Ragab
Head of Data Link at Telecom Egypt
The product is useful, particularly in its sensitivity and scanning capabilities. Additionally, it allows for investigation while the developer is writing the code. It is a more efficient process compared to other tools like App Scan.
View full review »PD
Pratiksha Doshi
Director at KPMG
SAST is the only feature that works using the on-prem version. It's becoming very difficult for us to integrate it with the other SecOps solutions. It is a very good solution but only when using the standard version.
View full review »There are many features that are valuable. such as the APIs. API calls in AppScan, and similar to Burp Suite enterprise edition, which is also for API scans. I can trigger the scan ware API.
The HCL AppScan turnaround time for Burp Suite or any new feature request is pretty good, and that is why we are sticking with the HCL.
View full review »The UI was very intuitive. It was very easy to understand. It was very easy to scan the websites, see the results, and deliver them to higher management.
View full review »JH
Jeon Hyunguk
Security Engineer at KEPCO KDN
The solution is easy to use. It is useful for finding basic information about systems.
View full review »JB
Jagadeesh B
Solutions Architect at IBM
The scanning is quite good. It's good for helping us seek out vulnerabilities and fixing hot spots.
The pricing is fine.
It's on a managed cloud, and that makes it very easy. It's straightforward to use.
The solution has been stable, and we haven't really had downtime.
It's stable.
Technical support is helpful.
The most valuable feature of the solution is Postman. As a security engineer, Postman allows me to specify exactly what information I need to scan for, rather than just dropping all information and running a scan. I can also use it to do some information gathering before scanning. This allows me to specify APIs and scan accordingly. The feature also saves us time.
The most valuable feature of HCL AppScan is scanning QR codes.
View full review »The security and the dashboard are the most valuable features.
View full review »The dynamic scan, the DAST tool, dynamic applications scanning and testing tool, is great.
It was easy to set up.
It's a stable solution.
The product is easy to scale.
The solution is affordable and reasonably priced.
View full review »AppScan is within the top three or four static analyzers. Its features include support for many languages.
The product has a relatively reasonable scan time.
There's extensive functionality with custom rules and a custom knowledge base.
View full review »CV
CRISTIANO VIEIRA SILVA
Mechanical maintenance technician at SAQ
Compared to other tools only AppScan supports special language.
View full review »The solution offers services in a few specific development languages.
View full review »It's a good product. It's automated crawler identifies all urls and performs security tests. It has a very rich test cases which ensures pretty good coverage in terms of security testing. The UI is user friendly and intuitive.
View full review »JS
Jamal Uddin Shaikh
Cybersecurity Architecture and Technology Lead at a tech company with 51-200 employees
The most valuable feature is that it achieves a very low false-positive detection rate.
View full review »SC
Sungmin Chun
Chief researcher at INSEC Security
AppScan seems to be very good at detecting reflected XSS vulnerabilities. This increases the security of web applications that are in operation.
View full review »Scalability, and it's a very powerful tool.
View full review »The static scans are good, and the SaaS as well.
Its integration from a UI perspective. You can easily find particular features and functions through the UI.
For its first initial release, the integration was pretty good.
View full review »I think it's easy to use and gives back some pretty good results, certainly for vulnerabilities.
View full review »We leverage it as a quality check against code.
View full review »It helps you to enforce security practices, beyond the reach of just operations and training. So give the training, but besides that you can detect some deviations in the development process. I think that's the most valuable of all the features.
View full review »TH
TimHill
Director For Security Products at a manufacturing company with 10,001+ employees
The most valuable feature is the web scan from our perspective. Being able to quickly find the vulnerabilities if any developer has inadvertently put them in. The source scan is of value, but it is so hard to use that it is of less value.
View full review »There's a recording feature that I really like. You pass through the login pages. If you record the login part, it becomes very fast with the solution.
View full review »For me, as a manager, it was the ease of use. Inserting security into the development process is not normally an easy project to do. The ability for the developer to actually use it and get results and focuses, that's what counted.
View full review »It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code.
View full review »PN
Prasoon Nigam
Security Consultant at a consultancy with 10,001+ employees
Many features are valuable but some features stand out, like using our own scripts, and capturing the authentication.
It is easy it is to use. It is quick to find things, because of the code scanning tools. It's quite simple to use and it is very good the way it reports the findings.
View full review »We are currently using it in the integration of our agile process so we can find any breaches in the apps while they're in the development process. We can then fix breaches before they go into a production environment.
It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply.
That being said, we have to be very rigorous about what we are protecting, such as the type of data and the code itself. Having those features in the app is a huge must.
View full review »The most valuable feature of this product is its capability to detect XSS and SQL injection.
View full review »Buyer's Guide
HCL AppScan
June 2025

Learn what your peers think about HCL AppScan. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
859,579 professionals have used our research since 2012.