Try our new research platform with insights from 80,000+ expert users
SANGAM GOEL - PeerSpot reviewer
Chief Executive Officer at GS2 CYBER SECURITY
Real User
Continuously updated, fair pricing, and offers a free community version
Pros and Cons
  • "It's good testing software."
  • "The initial setup is a bit complex."

What is our primary use case?

We are using the solution for web application testing. From Burp Suite, we can test the application security. We have a team of system auditors, and our auditors use Burp Suite.

What is most valuable?

We are working with the community version, and it provides all the features we need.

It's good testing software. 

For application security, Burp Suite is one of the best solutions. It has all the proxy and all the features so that we can test all the application's vulnerabilities. 

They have an extension feature, so at intervals, they provide extensions that provide some helpful updates. They continuously update the product, and they continuously provide extensions. Through the extensions, we get new features at regular intervals.

The pricing is fine. 

We can customize and configure as needed.

We found the product to be quite stable. 

What needs improvement?

It's already great. There isn't anything needed for improvement. 

The initial setup is a bit complex. 

For how long have I used the solution?

I've used the solution for three years. 

Buyer's Guide
PortSwigger Burp Suite Professional
May 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is very stable and reliable. There are no bugs or glitches. It doesn't crash or freeze. 

What do I think about the scalability of the solution?

The solution can scale. It's per system. If you are using it on 100 systems, you must install it on all 100 systems. It's not like you install a central product, and you scale. It's not the client-server architecture; you must install it on every system if you want to test.

We have two or three users on the solution.

How are customer service and support?

We've never escalated any issues to technical support. I've never directly dealt with them.

Which solution did I use previously and why did I switch?

This is among the best in comparison to all other tools. If we compare it to Zap, et cetera, Burp Suite is the best among those. There's also Nikto and lots of tools available. We prefer to work with Burp as Burp Suite is like a framework. It has lots of tools in-built. Therefore, we can do multiple tasks on a single platform from a single framework. It's like a one-stop shop.

How was the initial setup?

The solution is a little bit complex. It's not exactly straightforward. 

The deployment itself was a pretty easy process. It was quick.

We do not find it difficult to maintain the solution.

What about the implementation team?

We handled the initial setup ourselves in-house. 

What's my experience with pricing, setup cost, and licensing?

We use the community version. It's free.

Pricing is not very high. It was around $200.

They have some licenses, and features and they have some different categories. I need to go through the sites, however, I know they have different versions.

What other advice do I have?

We are using Burp Suite. We are not selling Burp Suite.

At this time, we're using the most up-to-date version of the product.

I'd recommend the solution to others. I would rate it ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Siddharth-Singhal - PeerSpot reviewer
Consultant at a consultancy with 10,001+ employees
Real User
Offers multiple features including automation of tasks but is somewhat lacking in stability
Pros and Cons
  • "Enables automation of different tasks such as authorization testing."
  • "The solution lacks sufficient stability."

What is our primary use case?

We use PortSwigger to find simple bugs via authorization and authentication testing. It's about preventing attacks. Burp Suite enables you to drill down and check all test cases, irrespective of the application on which it's built. We are customers of PortSwigger and I'm a consultant.

What is most valuable?

Port Swigger enables automation of different tasks such as authorization testing. New extensions come in every day which can be used in Burp Suite while testing. 

What needs improvement?

In general, there's not much to complain about but the stability of the tool is not good enough. I know that the RAM utilization is something they're working on but using a scan currently takes up too much memory. Resource utilization is an issue because when you're application testing, there are multiple threats and multiple application requests that are going in the backend.

For how long have I used the solution?

I've been using this solution for four years. 

What do I think about the stability of the solution?

The stability could be improved. 

What do I think about the scalability of the solution?

The scalability is quite good because PortSwigger can be used by multiple users through Jenkins and other things. 

How are customer service and support?

The technical support is quite good. 

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup is not that difficult because there's good documentation on the PortSwigger website. Our employees each installed on their own machine, it's an executable file. 

What was our ROI?

Return on investment is good because it's a globally known product. All our  customers know Burp Suite. There's a return on investment because it's a major tool necessary for performing any manual or automation testing.

What's my experience with pricing, setup cost, and licensing?

The licensing cost depends on the number of users. One person can use the tool on a single laptop that can be shared between multiple users under a single license. We have around 15 users. We pay an annual license fee that includes technical support, it's not that expensive. They also provide a free community version. 

What other advice do I have?

I recommend this solution and rate it seven out of 10 because it offers multiple features.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
PortSwigger Burp Suite Professional
May 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
856,873 professionals have used our research since 2012.
Mouli Siramdasu - PeerSpot reviewer
Associate Consultant at ATOS
Vendor
Reliable with helpful support and documentation
Pros and Cons
  • "The solution is stable."
  • "Sometimes the solution can run a little slow."

What is our primary use case?

The solution is primarily used for scanning the webpage and for the incoming traffic for the application.

What is most valuable?

The solution is most valuable for finding and developing the application. If there is leakage of data or some external links, we can deal with it.

The solution is stable.

The scalability is good.

The solution offers helpful technical support and has excellent documentation.

What needs improvement?

Sometimes the solution can run a little slow. When we’re cracking passwords, we have issues with responsiveness.

For how long have I used the solution?

I used the solution for one year.

What do I think about the stability of the solution?

Mostly the solution is stable. Sometimes while using the password cracker, it took some time. Sometimes it gets a bit slow by adding up the number of rules. It took some time to crack the passwords of applications.

What do I think about the scalability of the solution?

It is pretty easy to scale the product.

We had ten to 12 people using the solution. It was a small environment.

How are customer service and support?

Technical support was excellent. They were very fast. They also offered good documentation which was very helpful to have on hand.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I started with Burp Suite. I’ve only used that. I haven't used anything other than that.

How was the initial setup?

For the setup, on my end, I just got access via the organization when I first started using it. I haven't set up the entire cloud, the Burp Suite cloud. I used it by using some credentials only. Therefore, I'm not that good at setting up the enrollment.

The entire setup was done on the cloud. There were only three to four people needed for deployment and maintenance. They are well experienced in those areas.

What about the implementation team?

The deployment part was entirely done by another team. We, as a team, used to test the application. We didn't know much about how the setup was arranged.

What's my experience with pricing, setup cost, and licensing?

I’m not aware of the pricing side of things. It might have been paid monthly, however, I don’t know much more than that.

What other advice do I have?

My company was parters with Portswigger.

I’m not sure which version of the solution we were using.

Everyone seems very happy with the solution. There are some learning modules as well so that we can go into the tool and understand it well. I would suggest the solution to my colleagues.

I’d rate the solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
VinothKumar5 - PeerSpot reviewer
Senior Consultant at Hexaware Technologies Limited
Reseller
Effective automatic scanning, Academy portal for learning, and reliable
Pros and Cons
  • "The automated scan is what I find most useful because a lot of customers will need it. Not every domain will be looking for complete security, they just need a stamp on the security key. For these kinds of customers, the scan works really well."
  • "There could be an improvement in the API security testing. There is another tool called Postman and if we had a built-in portal similar to Postman which captures the API, we would be able to generate the API traffic. Right now we need a Postman tool and the Burp Suite for performing API tests. It would be a huge benefit to be able to do it in a single UI."

What is our primary use case?

The solution is for web security testing and the primary use is to eliminate the false positives.

How has it helped my organization?

This solution has helped our company in many ways. PortSwigger Acadamy has given us the knowledge to be able to do deeper tests. The effectiveness of the tests is directly proportional to your knowledge about security testing. Even if you do not have this knowledge at the beginning you still you can perform some kind of testing. If you do not know how to choose your payload then it is going to suggest the built-in payloads to which you can perform those test attacks.

You do not need to be an expert to use the solution, an intermediate skilled person can use it and over time they can become an expert. Sometimes it is difficult to find skilled employees to start working in this field for your company but with PortSwigger the new employee does not have to be an expert because they are able to grow quite quickly in their knowledge.

What is most valuable?

The automated scan is what I find most useful because a lot of customers will need it. Not every domain will be looking for complete security, they just need a stamp on the security key. For these kinds of customers, the scan works really well.

What needs improvement?

There could be an improvement in the API security testing. There is another tool called Postman and if we had a built-in portal similar to Postman which captures the API, we would be able to generate the API traffic. Right now we need a Postman tool and the Burp Suite for performing API tests. It would be a huge benefit to be able to do it in a single UI.

In a future release, if there could be some kind of autonomous function, or user behavior prediction that would be beneficial.

For how long have I used the solution?

I have been using this solution for approximately three years.

What do I think about the stability of the solution?

The solution has not had any crashes or any problems. It is reliable.

What do I think about the scalability of the solution?

The solution is scalable. There are types of operations we can do and it has good peak performance.

How are customer service and technical support?

PortSwigger has something called Academy where you can go to learn about many things related to security testing.

How was the initial setup?

The installation is very easy.

What's my experience with pricing, setup cost, and licensing?

The solution used to be expensive. However, they have reduced the price to approximately $400.00 which is reasonable.

Which other solutions did I evaluate?

I have evaluated Zap.

What other advice do I have?

My advice to others just starting out with security testing is to evaluate Zap, which is open-source, to allow them to get an understanding of the processes. Then once they have an understanding they should look into PortSwigger Burp Suite Professional. This solution would win in comparison with its features and would be a very good choice after they have some experience.

I rate PortSwigger Burp Suite Professional an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Senior Business Development Manager at Intouch World
Reseller
Top 5
Enables efficient cost management and supports in-depth penetration testing
Pros and Cons
  • "The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency."

    What is our primary use case?

    I primarily use PortSwigger Burp Suite Professional for penetration testing of applications.

    What is most valuable?

    The most valuable features of PortSwigger Burp Suite Professional are its ease of use and its cost efficiency.

    What needs improvement?

    The dashboard of PortSwigger Burp Suite Professional could be made more user-friendly.

    For how long have I used the solution?

    I have been using PortSwigger Burp Suite Professional for about eight to nine years.

    What do I think about the stability of the solution?

    PortSwigger Burp Suite Professional is a very stable tool, and I would rate its stability as eight out of ten.

    What do I think about the scalability of the solution?

    I would rate the scalability of PortSwigger Burp Suite Professional as eight out of ten.

    How are customer service and support?

    The technical support for PortSwigger Burp Suite Professional is pretty good, and I would give it a nine.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup of PortSwigger Burp Suite Professional is straightforward.

    What's my experience with pricing, setup cost, and licensing?

    I find the price of PortSwigger Burp Suite Professional to be very cost-efficient.

    What other advice do I have?

    I would recommend PortSwigger Burp Suite Professional to others. I would rate the overall solution as eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer: Reseller
    Flag as inappropriate
    PeerSpot user
    Khasim Mirza - PeerSpot reviewer
    Security Consultant - Cyber & Information Security at Kinetic IT
    Real User
    Top 10
    Helps with penetration testing and web application testing
    Pros and Cons
    • "The tool provides complimentary services. It allows you to add a lot of extensions, and you can get extensions quite often. It is quite a flexible application."

      What is our primary use case?

      We use the solution for penetration testing, web application testing, etc.

      How has it helped my organization?

      We use the tool to test the application security, like APIs. It is one of the major tool for any security or to test web applications.

      What is most valuable?

      The tool provides complimentary services. It allows you to add a lot of extensions, and you can get extensions quite often. It is quite a flexible application.

      What needs improvement?

      Reporting could be improved. If you use any AI feature, you can go out and take and provide more in-depth information.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for over ten years. We are using the latest version of the solution.

      What do I think about the stability of the solution?

      The product is highly stable.

      I rate the solution’s stability an eight out of ten.

      What do I think about the scalability of the solution?

      The solution is scalable.

      Five users are using this solution.

      I rate the solution’s scalability an eight out of ten.

      How are customer service and support?

      Customer support respond immediately.

      How would you rate customer service and support?

      Positive

      How was the initial setup?

      The initial setup is easy and take you around ten minute, provided you have downloaded the application.

      I rate the initial setup a nine out of ten, where one is difficult, and ten is easy.

      What about the implementation team?

      The tool was deployed in-house.

      What's my experience with pricing, setup cost, and licensing?

      worth the money spent.

      Which other solutions did I evaluate?

      Yes, there many tools, and also a free tool i.e ZAP

      What other advice do I have?

      it does give you ability to run easily  various attack types , such as Sniper, Pitchfork attack, Battering RAM, Cluster bomb and various other attack types, which can be used to test Web application. 
      Overall, I rate the solution an eight out of ten.

      Which deployment model are you using for this solution?

      On-premises

      If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Rooshan Naeem - PeerSpot reviewer
      Security Engineer at Eon Health
      Real User
      Top 5
      The solution helps us when testing applications
      Pros and Cons
      • "It is useful for scanning and tracing activities."
      • "Improvement should be done as per the requirements of customers."

      What is our primary use case?

      I have been using this solution for quite a long time. The features and request tampering are different. This solution helps us when testing applications. It is a flexible tool.

      What is most valuable?

      It is useful for scanning and tracing activities.

      What needs improvement?

      Improvement should be done as per the requirements of customers. 

      For how long have I used the solution?


      What do I think about the stability of the solution?

      I would rate the stability an eight out of ten. 

      What's my experience with pricing, setup cost, and licensing?

      The solution is reasonably priced. 

      What other advice do I have?

      Overall, I would rate the solution a nine out of ten. 

      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Akshay Waghmare - PeerSpot reviewer
      Manager at a consultancy with 10,001+ employees
      Real User
      Top 5Leaderboard
      A stable and user-friendly solution that can be used for manual penetration testing
      Pros and Cons
      • "PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up."
      • "The technical support team's response time is mostly delayed and should be improved."

      What is our primary use case?

      We use PortSwigger Burp Suite Professional for manual penetration testing.

      What is most valuable?

      PortSwigger Burp Suite Professional is one of the best user-friendly solutions for getting the proxy set up.

      What needs improvement?

      The technical support team's response time is mostly delayed and should be improved.

      For how long have I used the solution?

      I have been using PortSwigger Burp Suite Professional for six to seven years.

      What do I think about the stability of the solution?

      PortSwigger Burp Suite Professional is a stable solution.

      What do I think about the scalability of the solution?

      Around 500 to 600 users are using the solution in our organization.

      How was the initial setup?

      The solution’s initial setup is quite easy.

      What was our ROI?

      PortSwigger Burp Suite Professional is worth its price.

      What's my experience with pricing, setup cost, and licensing?

      PortSwigger Burp Suite Professional is an expensive solution.

      What other advice do I have?

      Users should get the professional version for the solution because the community and the free edition do not have many things to offer. They should explore as much as possible, go for the web code application, and do the manual penetration testing.

      PortSwigger Burp Suite Professional allows us to do everything from setting the proxy to getting our own browser. Some features were not there in Burp Suite earlier. We had to attach Chrome to the Burp Suite to the proxy, but now they have given everything in a single bundle.

      Overall, I rate PortSwigger Burp Suite Professional ten out of ten.

      Which deployment model are you using for this solution?

      On-premises
      Disclosure: My company does not have a business relationship with this vendor other than being a customer.
      PeerSpot user
      Buyer's Guide
      Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.
      Updated: May 2025
      Buyer's Guide
      Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.