We use it for code scanning, security scanning, and finding vulnerabilities.
I am using its latest version. I have Fortify code scan on the cloud and Fortify WebInspect on-premise for a dynamic scan. So, SAST is on the cloud, and DAST is on-premise.
We use it for code scanning, security scanning, and finding vulnerabilities.
I am using its latest version. I have Fortify code scan on the cloud and Fortify WebInspect on-premise for a dynamic scan. So, SAST is on the cloud, and DAST is on-premise.
Reporting, centralized dashboard, and bird's eye view of all vulnerabilities are the most valuable features.
The vulnerability management part of it is very easy. We can suppress or comment on each vulnerability and assign a vulnerability to an individual risk owner, which makes the work easy.
It requires improvement in terms of scanning. The application scan heavily utilizes the resources of an on-premise server. 32 GB RAM is very high for an enterprise web application.
Its installation and maintenance are not easy. Its updates and upgrades are hard.
Its performance needs to be stabilized. It should also be able to find more vulnerabilities than other tools.
It is expensive. Its price needs to be improved.
I have been using this solution for five years.
Its performance is good, but it takes a lot of resources in terms of CPU utilization, so stability-wise, there are problems at times.
We have 70 to 80 users who use this solution. Its scalability is easy. You just need to add another server, if required.
We have contacted them for multiple issues. Sometimes, scanning didn't work, and the reports didn't come, so we had to escalate. My experience with them was fair. It wasn't great. We asked for remote control or remote setup, but they never provided that. There is no remote assistance. You need to upload the logs. They review and reply back on time. Their response time is very short, which is good, but if we need remote help, it is not easy. You don't get that immediately.
I have also been using AppScan. The performance of AppScan is good, but WebInspect has more features, such as a centralized dashboard and the ability to assign a risk into priorities. It is an enterprise and feature-rich tool, but performance-wise, AppScan is good.
The on-premise setup is complex. It requires the installation of a lot of tools, software, licenses, and on. Its installation is very complex as compared to the other tools in the market. It took us a week.
It requires some maintenance in terms of logs. It collects a lot of logs, and you need to remove those logs and keep updating the software. The update is not that regular, and you need to install the update manually on each of the servers. The update requires a lot of effort. It's not a simple auto-update feature.
We had to take help from the vendor. At one point, I was stuck, and the vendor had to install it. They were pretty supportive.
Its price is almost similar to the price of AppScan. Both of them are very costly.
Its price could be reduced because it can be very costly for unlimited IT scans, etc. I'm not sure, but it can go up to $40,000 to $50,000 or more than that.
While implementing WebInspect, it is always better to keep all the required software installed and ready. The installation of WebInspect has a lot of dependencies, such as .NET, Java, SQL database, etc. All of the data does not come in-built. So, the moment you start building it, if it creates a problem, you have to remove and reinstall everything from scratch and then come back, which takes a lot of time. So, it is better to have those prerequisites handy, pre-installed, and tested.
I would rate it a seven out of 10.
Fortify WebInspect can be deployed on the cloud or on-premise.
Fortify WebInspect is used as a vulnerability scanner for applications.
Fortify WebInspect could improve user-friendliness. Additionally, it is very bulky to use.
I have been using Fortify WebInspect for approximately one year.
The stability of Fortify WebInspect could improve.
Fortify WebInspect is a scalable solution, it is good for a lot of applications.
The technical support of Fortify WebInspect is great.
The initial setup of Fortify WebInspect is complex.
My advice to others using Fortify WebInspect is not to use it, there are better solutions in the market.
I rate Fortify WebInspect a five out of ten.
We primarily use the solution for web applications and tests.
It helped us much as it's a really good automated scanner with nice number of checks.
The solution is easy to use.
The initial setup is pretty straightforward and the deployment is quick.
The solution has good documentation.
The product is a good option for enterprise-level organizations.
The scanner could be better.
The out of bounds channel is missing and it makes it hard to nail down the vulnerabilities.
I hadn't been working with the solution for very long; I worked with it at my last company.
The first time we ran the module, it was okay, however, the next time we ran it, it almost crashed. For example, when I started the proxy, I tried to create some traffic from the application and nothing happened, but then, after that, everything began to hang. I'm not sure if this was an issue with a particular version or not. I'm not sure if it was some sort of bug.
Typically, if I have an issue, I contact my internal support team. They may directly contact technical support. However, I have not done so myself. Therefore, I can't speak to their responsiveness or knowledge levels.
I've used PortSwigger in the past, and it was a pretty good product as well.
The initial setup is not complex. It's pretty straightforward. You just have to download it to the Microsoft server and you're done.
The total deployment may take an hour, or, at maximum, two.
I handled the implementation myself.
We used Acunetix and Netsparker with Burp Suite.
We're just customers. We don't have a business relationship with the company.
I would recommend WebInspect to enterprise-level organizations. to use. For a smaller company, I'd recommend something more automated. WebInspect has far more manual work, however, it does have good documentation.
Overall, I'd rate the solution eight out of ten.
We primarily use the solution to test web applications regularly.
The solution is able to detect a wide range of vulnerabilities. It's better at it than other products.
The solution is on the expensive side. It's something that clients comment on. If they could make it more reasonable, it would be better.
Lately, we've seen more false negatives.
I've been dealing with the solution for three years at this point.
The solution is largely stable. We've only noticed recently that there are more false negatives. I'm not sure if that means there's an issue or not.
In terms of scalability, many of our customers only have 20-30 websites and therefore one scanner fulfills their requirement. In that sense, we've never really tried to scale the product.
For the most part, WebInspect has pretty good technical support. Not all Micro Focus products have equally good support.
We suggest different solutions to our clients. Some might use Acunetix. We've also used ForeSite in the past as well.
The solution is rather expensive. It's not cheap. If you compare it to, for example, Acunetix, Acunetix is cheaper.
While we generally like WebINspect, if a client has a smaller budget, we might suggest Acunetix simply because it is cheaper. However, if a customer's priority was better scanning for their application, we would suggest WebInspect. We like to give our clients options and choices. We prefer to provide them with options that meet their needs and address their pain points.
Overall, I would rate the solution seven out of ten. If the price was a bit better, I would rate them higher.
This is a security testing tool that is used by our security team and the QA team.
The accuracy of its scans is great. Provided it does not freeze, or somebody from another team is not trying to use the same resources, it works well.
The integration with the Fortify code scanner is nice because you combine those two elements and get one output.
Our biggest complaint about this product is that it freezes up, and literally doesn't work for us. It may be in part the way we have it set up, or how we've licensed it.
It is awkward and not very friendly to work with.
The version that I am using is not capable of generating reports to HTML or PDF, so I can't share them. I have to get somebody else to log into the application and view the results themselves. Simply, I can't output a report that I can easily share.
We have been using WebInspect for about one year.
The experience that I have had is that it is not stable.
Scalability is probably fine if you buy more licenses.
I have not worked with their technical support.
Our licensing is such that you can only run one scan at a time, which is inconvenient. The licensing was bundled with Fortify so I'm sure that we paid for it in some context, although I don't know what the exact cost would be.
We are using this WebInspect in conjunction with Fortify. We're not using the client-host based deployment, but rather, a web-based one. The agent is not installed on my machine.
The suitability of this product depends on your use case. If you're trying to do what we're doing in QA and security then it's probably great. If, however, you want to do things on external sites then I would suggest an external cloud-based one.
I would rate this solution a four out of ten.
We use WebInspect for performance network application testing to be sure that we aren't creating any security issues.
The most valuable feature is the performance.
The user interface is ok and it is very simple to use.
There were times when we had to run the login sequence several times in order to capture it properly.
It took us between eight and ten hours to scan an entire site, which is somewhat slow and something that I think can be improved.
I have been using WebInspect for about one year.
The stability is good.
Scalability has only been an issue in that larger sites take a lot longer to scan.
I have not been in contact with technical support.
I have used Qualys in the past but more for vulnerability management in the infrastructure, as opposed to web application security.
The initial setup is straightforward and very simple. I simply download the file on my home laptop and started testing with it.
I can deploy this solution on my own.
I have been told by friends and colleagues that Acunetix is better, so I will be evaluating that solution in the future.
I would rate this solution a seven out of ten.
I am using WebInspect for finding vulnerabilities.
The most valuable feature is the static analysis.
Creating reports is very slow and it is something that should be improved.
In the future, I would like to see better integration between static analysis and dynamic analysis.
I have been working with WebInspect for one year.
We have never had a problem with stability.
This is a scalable solution. I performed an analysis of more than five million rows and it took perhaps three hours.
Technical support is a bit slow, as sometimes it takes too long to get responses. However, the support is good because our problem was fixed after just one interaction with them.
Prior to using WebInspect, I was using SonarQube. The problem with SonarQube is that they are not very good at analyzing ASP.NET applications, so I gave up on it.
The pricing is not clear and while it is not high, it is difficult to understand.
I would rate this solution an eight out of ten.
We use WebInspect for dynamic application security testing, and integrating that into all our needs.
In terms of its most valuable features, it is scalable and very easy to use.
Right now, it's kind of bulky. There are a lot of newer generation tools coming out that are easier.
Also, when it comes to the installation and deployment, they inspect the enterprise. It was ok with the scale, but still I think they can make it a little lighter in nature.
I have been using WebInspect for around six, seven years.
It's quite a stable product.
WebInspect is a scalable product. We have users in the double digits, around 10-15 users. At any time there are a couple of project users, so I would say around eight to ten.
We require one person maximum for deployment and maintenance.
I have been satisfied with my experience with the customer support.
I previously used AppScan. We switched due to an overall change in our organization in Azure. IBM sold this to HCL so there is no IBM grant attached to it.
The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex.
The first time we deployed it, it really took awhile because of some issues on our side and on their side. Installation can last for more than three days.
Our team implemented it along with some of the other professional departments.
We did evaluate AppScan for this task. Both solutions are good. We also evaluated Oracle of course, but it is purely a SaaS solution and that's the reason it was not considered.
Yes, I would recommend WebInspect. It is a good product, comparable to AppScan. It is quite scalable, and good cost/value with the support and backing from Micro Focus. It's good and I definitely recommend it.
On a scale of one to ten, I would give it an eight.
We primarily use the solution for dynamic application scanning.
It's a well-known platform for doing dynamic application scanning.
The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective.
The solution is stable.
We've yet to test the scalability of the solution, so I can't comment on how scalable it is just yet. Right now, we have our DevOps team working with it, about three to five people.
We've never been in touch with technical support.
Right now we are in the middle integration, so I'm not sure how much time it's going to take. We haven't yet scanned any of our endpoints, and I'm not sure how much complexity will be involved during the process.
We're using the public cloud deployment model. Our provider is Microsoft.
We just chose the solutions for dynamic scanning and static scanning, but we haven't performed any scanning yet.
I'd recommend it; I'd rate the solution seven out of ten.
We primarily use the application for web application scanning.
I've found the centralized dashboard the most valuable. For management, it helps a lot to have abilities at the central level.
The solution needs improvements from the scanning and the technical perspective.
In the next release, we would love to see smooth scale mobile testing - if it has similar to testing with wider applications for different technologies as well because people are moving towards mobile. If the solution can integrate AI and also understand the application by itself, this will be great.
Stability wise, the tool is stable, but the tool still requires some improvements in the latest technology websites. For example, if there is a single website or e-commerce website, it is still trying to understand a lot of the applications while it scans. It is not that smooth with complex websites. We have about 80-100 users on the solution.
So far technical support is good. It is fair enough. They haven't got a response or turn around time. From the support perspective, it is good.
I haven't used any different solution here, but in another organization, I have used multiple application scanning products. I've used IBM scan. I have used SecuRex. Those were good as well.
The initial setup is pretty good. They have a step by step guide and everything is given. It sets up with the environment but it requires a lot of memory and the system requires a lot of memory. That is the only negative, normally if you have a three-way scanner, it would run smoothly on even a small configuration laptop. This was a delicate setup.
I'm not sure about the licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools with similar functionalities. The pricing is a little more costly than other regular solutions. There are only two such products that are this costly. This and IBM. The rest of the application scanners are not as costly.
I am currently evolving, going through the product. We have yet to go through all the features and functionalities of the product. The way it checks for vulnerabilities helps a lot. It makes the most of the check for vulnerabilities. The centralized dashboard for the management is good but I'm still looking into it. That and other features we are yet to be discovered. I'm still trying to get to know all the features.
Looking at an enterprise level product is good. With it, you get a centralized board, you have a management view, enroll management and access management. Everything is there. But still, check your requirements, what you need. If you use it for a certain amount of applications, you might not need such a heavy tool.
Our requirement is 10 or 20 times more than a regular company and hence we went with an enterprise solution and had somebody who could implement this. If your requirement is a little less, it might just call for some other scanners based on your requirements.
If you do need such an extensive requirement, ensure that you also have the data servers and systems for such tools. It will be easy to implement in any environment if you do.
I would rate this solution 7 out of 10.

I believe the reviewer or the forum organizer has posted this review in the wrong area, or confused Fortify's WebInspect product (DAST) with their Static Code Analyzer ("Fortify SCA") product (SCA).
+++++++++
Fortify general: www.microfocus.com/en-us/solutions/application-security
SCA: www.microfocus.com/en-us/products/static-code-analysis-sast/overview
WebInspect: www.microfocus.com/en-us/products/webinspect-dynamic-analysis-dast/overview