Try our new research platform with insights from 80,000+ expert users
reviewer1508730 - PeerSpot reviewer
Founder and Director at a financial services firm with 1-10 employees
Real User
Great reporting with good crawling capability and offers a simple setup
Pros and Cons
  • "The solution has a pretty simple setup."
  • "The pricing of the solution is quite high."

What is our primary use case?

We primarily use the solution for security testing - specifically for web-application security. 

What is most valuable?

The crawling capability is excellent.

The product has very good reporting capabilities. They give you multiple reporting options.

The solution has a variety of different extensions that you can use.

The solution has a pretty simple setup.

What needs improvement?

The pricing of the solution is quite high. It would be ideal for the customers if they could lower the costs involved in their subscription.

We have new tools in R language programming platforms that are coming up. The solution needs to ensure its compatible with that language.

For how long have I used the solution?

I've been using the solution for about two years at this point.

Buyer's Guide
PortSwigger Burp Suite Professional
May 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.

What do I think about the stability of the solution?

We use this solution every day. I don't have any issues with the solution. There aren't bugs or glitches. It doesn't crash or freeze. It's reliable.

What do I think about the scalability of the solution?

I'm a consultant. I tend to use the tool for my clients. I only have one license on my computer. I don't need to scale the product.

The solution is scalable, however. There's a different version for that aspect. You have Community, Professional, and Enterprise editions. Each has different capabilities.

How are customer service and support?

The solution offers good support services. There's also the product team that can assist. Overall, I've been happy with the level of service I've received.

Which solution did I use previously and why did I switch?

I've worked with other solutions, such as Acutenix. As a consultant, I always have two to three tools for running and validating for testing. There is no plus or minus to each tool, really. The process itself would be more like using multiple tools to find out whether it appears in all the tools or not.

How was the initial setup?

The initial setup is not overly complex. It's easy and straightforward. A company shouldn't have any issues with the implementation process.

The deployment takes a maximum of an hour, actually. If you have to configure some prerequisites, it is one hour tops. There are advanced setups, however, how advanced the implementation depends on the client environment. If a company has an advanced setup, it could take some time. 

Ultimately, the solution is installed directly onto my laptop.

The maintenance process is pretty minimal. The yearly subscription keeps everything updated. They will notify you if there is an upgrade that needs to be addressed.

What's my experience with pricing, setup cost, and licensing?

The pricing of the solution is quite high. Costs are based on their subscription model. The pricing affects whether a client will engage with me and the solution or not. It could be a deal-breaker. Budgets are often tight.

What other advice do I have?

The solution has an annual subscription model, and therefore you'll have to keep updating the new version. It's part of the package. They release a new version and that is covered under your subscription.

I'm a consultant. I buy tools from multiple vendors. I provide development assessment services for my clients.

This is one more product in the suite of tools or applications, which are used for testing. Anyone at any sized company could use this solution.

I'd recommend this solution. It's one more tool to have in your bag.

I would rate the solution at a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Consultant
PeerSpot user
reviewer1293489 - PeerSpot reviewer
IT Security Analyst at a tech services company with 11-50 employees
Real User
Stable, easy to set up, and speeds up our vulnerability assessment and penetration testing
Pros and Cons
  • "I find the attack model quite amazing, where I can write my scripts and load my scripts as well, which helps quite a bit. All the active scanning that it can do is also quite a lot helpful. It speeds up our vulnerability assessment and penetration testing. Right now, I am enjoying its in-browser, which also helps quite a bit. I'm always confused about setting up some proxy, but it really is the big solution we all want."
  • "I am from Brazil. The currency exchange rate from a dollar to a Brazilian Real is quite steep. It is almost six to one. It would be good if it can be sold in the local currency, and its price is cheaper for us."

What is our primary use case?

I'm a junior cybersecurity analyst, and I'm helping the seniors to do some testing. Meanwhile, I'm also getting trained with the tool. I mostly use it for vulnerable apps assessment and some auditing. Other analysts use it for penetration testing.

We are using the latest version. We downloaded it three days ago.

What is most valuable?

I find the attack model quite amazing, where I can write my scripts and load my scripts as well, which helps quite a bit. All the active scanning that it can do is also quite a lot helpful. It speeds up our vulnerability assessment and penetration testing. Right now, I am enjoying its in-browser, which also helps quite a bit. I'm always confused about setting up some proxy, but it really is the big solution we all want.

What needs improvement?

I am from Brazil. The currency exchange rate from a dollar to a Brazilian Real is quite steep. It is almost six to one. It would be good if it can be sold in the local currency, and its price is cheaper for us. 

For how long have I used the solution?

I have been using PortSwigger Burp for six months now.

What do I think about the stability of the solution?

I have found no issues so far with its stability. I can't complain anything about it.

What do I think about the scalability of the solution?

I can't say much about that because we are going to transition to cloud management. I don't know for sure how it is going to scale up. We are still in the testing and planning stages. We currently have approximately five users, and our team is still growing.

How are customer service and technical support?

I haven't yet used their technical support.

How was the initial setup?

The initial setup is completely easy. It took a day to deploy.

What's my experience with pricing, setup cost, and licensing?

It is expensive for us in Brazil because the currency exchange rate from a dollar to a Brazilian Real is quite steep.

What other advice do I have?

It is a really big solution. There are so many modules. You got to have some training to do it properly and go through a lot of documentation.

I would rate PortSwigger Burp a nine out of ten. I haven't found anything to complain about, but there is always some room for improvement.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
PortSwigger Burp Suite Professional
May 2025
Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
857,028 professionals have used our research since 2012.
reviewer1471662 - PeerSpot reviewer
Lead Software Architect at a tech services company with 201-500 employees
Real User
Excellent Community version for skills mapping that is easy to setup and is stable
Pros and Cons
  • "The extension that it provides with the community version for the skills mapping is excellent."
  • "Currently, the scanning is only available in the full version of Burp, and not in the Community version."

What is our primary use case?

We use this solution when we develop any of our software applications and host it with the website for external clients. All of the applications go through the vulnerability scanner.

What is most valuable?

Burp Suite is very helpful. The extension that it provides with the community version for the skills mapping is excellent.

What needs improvement?

The interface for external clients needs improvement.

Currently, the scanning is only available in the full version of Burp, and not in the Community version.

I would like the scanning included for free also.

For how long have I used the solution?

We have been using this solution for a year and a half.

What do I think about the stability of the solution?

It's a stable solution. We have not had any issues.

How are customer service and technical support?

I have not contacted technical support. 

We have not experienced any issues where we couldn't resolve them using our internal team.

We have not required any technical support.

Which solution did I use previously and why did I switch?

When we compare it to other programs that we have such as OWAP Zap, we found Burp to be more suitable.

How was the initial setup?

The initial setup is straightforward.

It is very easy to automate. It requires some configuration that has you follow step by step instructions. 

It can take four to five hours to go live.

Anyone with minimal knowledge and training can use this tool.

What's my experience with pricing, setup cost, and licensing?

We are using the community version, which is free.

Which other solutions did I evaluate?

We evaluated OWASP Zap, which was fully open-source.

We use the community version and found that Burp was easier and more useful.

The interface is better in PortSwigger Burp.

What other advice do I have?

I would rate PortSwigger Burp an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1458246 - PeerSpot reviewer
Cyber Security Analyst at a tech services company with 11-50 employees
Real User
Good reporting, useful features, and great scalability
Pros and Cons
  • "The reporting part is the most valuable. It also has very good features. We use almost all of the features for different kinds of customers and needs."
  • "One thing that is not up to the mark in PortSwigger is web application testing. I found some issues with its performance and reporting. They should work on these and give us a better outcome."

What is our primary use case?

We are an auditing company. We use this solution for auditing purposes for the infrastructure of our customers.

What is most valuable?

The reporting part is the most valuable. It also has very good features. We use almost all of the features for different kinds of customers and needs. 

What needs improvement?

One thing that is not up to the mark in PortSwigger is web application testing. I found some issues with its performance and reporting. They should work on these and give us a better outcome.

For how long have I used the solution?

I have been using this solution for more than a year.

What do I think about the stability of the solution?

It is stable. We didn't have any issues.

What do I think about the scalability of the solution?

Its scalability is great. We have almost five users who are using the product, and they're happy with this product. 

How are customer service and technical support?

We've got very good support from their team.

Which solution did I use previously and why did I switch?

We previously used some open-source applications, but later on, we found out that, unfortunately, they are not good products. We had to use the applications of all other products separately in our environment, but PortSwigger can do all things itself. That's why we switched to PortSwigger.

How was the initial setup?

The initial setup was very simple.

What about the implementation team?

I implemented it on my own.

What's my experience with pricing, setup cost, and licensing?

It has a yearly license. I am satisfied with its price.

Which other solutions did I evaluate?

We did consider one more product and had a discussion about the product features. We found PortSwigger to be the best match for our business.

What other advice do I have?

It is a very good product. You must try it once.

I would rate PortSwigger Burp a nine out of ten. I am satisfied with this product. It is a great experience.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Compliance Manager at a tech services company with 201-500 employees
Real User
Evaluate and ensure the security of web-based applications
Pros and Cons
  • "In my area of expertise, I feel like it has almost everything I could possibly require at this moment."
  • "A lot of our interns find it difficult to get used to PortSwigger Burp's environment."

What is our primary use case?

We're a software development company. We specialize in ensuring application security for our customers. For each and every application we release, we issue a certificate explaining that the application is up to date and that all security testing has been successfully completed. In that certificate, we also mention that PortSwigger is one of the tools that we used to test the application.

Presently, we have three users. In the future, regarding product testing, I am thinking of hiring another two people, which will make us a team of five. Currently, we're releasing a lot of applications. 

Primarily we have three users, but keep in mind, we only have a single environment, which we need to improve and expand. 

What is most valuable?

The traffic interception capabilities are great. Spidering also produced some good results for us.

What needs improvement?

A lot of our interns find it difficult to get used to PortSwigger Burp's environment. The environment should be improved a little bit. Once you get used to it, it's fine, but it should be more simplified for newcomers. This would save us from constantly having to brief our interns. 

What do I think about the stability of the solution?

The stability is good; so far, we haven't come across any bugs.

What do I think about the scalability of the solution?

We use some different tools for web application testing, like Nmap and others. If PortSwigger Burp could actually scale up for web application scanning, that would be really good. This way, instead of using different tools, we could easily rely on one tool for all testing.

How are customer service and technical support?

We haven't had any reason yet to contact technical support. Aside from support, they should hold consistent webinars and offer updates, briefings, and panel discussions. This would greatly enhance our knowledge.

Otherwise, the technical support is good enough. We haven't required their assistance yet, but soon we'll be needing assistance and information surrounding the latest improvements and updates.

How was the initial setup?

The initial setup can be complex. It needs to be deployed in between the traffic. They should include some case-scenarios to help, like a scenario-based briefing, that would really help and add a lot of value for the initial application tester. 

What's my experience with pricing, setup cost, and licensing?

It's a very unique way of pricing. It varies depending on the type of testing you are performing. Manual testing is expensive, but as we don't have another option, it seems to be fair.

What other advice do I have?

I would definitely recommend PortSwigger Burp. I've actually recommended it to some of my colleagues, students, and interns. I'm really comfortable and happy with it; besides, there are no other products to compare it to. 

On a scale from one to ten, I would give this solution a rating of eight.

If they included example scenarios and hosted educational webinars, I would give this solution a rating of ten.

In my area of expertise, I feel like it has almost everything I could possibly require at this moment. Generally, I don't come across situations like that, so I am very happy with it.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Security Researcher at a financial services firm with 5,001-10,000 employees
Real User
Feature-rich and intuitive with good support, and it is reasonably-priced
Pros and Cons
  • "There is no other tool like it. I like the intuitiveness and the plugins that are available."
  • "The use of system memory is an area that can be improved because it uses a lot."

What is our primary use case?

We used this solution as a proxy. It's a software that intercepts HTTP requests. You can modify them on your system for testing web applications.

What is most valuable?

It's an amazing tool. We can work with it automatically, or we can work with it manually.

There is no other tool like it. I like the intuitiveness and the plugins that are available.

The plugins are similar to integration. I can create my own login and use it.

What needs improvement?

The use of system memory is an area that can be improved because it uses a lot. They need to reduce the amount of system memory it uses.

For how long have I used the solution?

I have been working with PortSwigger Burp for four years.

What do I think about the stability of the solution?

We can say that it is stable, but it is using a lot of RAM.

What do I think about the scalability of the solution?

It's a scalable solution.

We have more than 30 users in our organization.

How are customer service and technical support?

Technical support is good, they have a good response time.

How was the initial setup?

The initial setup is straightforward.

This solution requires no maintenance.

What's my experience with pricing, setup cost, and licensing?

PortSwigger is reasonably-priced. It's fair.

What other advice do I have?

They have more features than I can use and I need more time to utilize this solution 100%.

I highly recommend it because everybody in Web Applications Security is using it.

I would rate PortSwigger Burp a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1223976 - PeerSpot reviewer
Cyber Security Specialist at a university with 10,001+ employees
Real User
Intruder and automatic scanning features help secure our internal applications pre-production
Pros and Cons
  • "The most valuable features are Burp Intruder and Burp Scanner."
  • "There should be a heads up display like the one available in OWASP Zap."

What is our primary use case?

This is a solution for which I provide services to our customers and I also use it personally.

As part of our organization, we build internal applications. Before they are put into production, we run a suite of security tests to ensure that our applications are not vulnerable to any known issues. We use PortSwigger Burp for testing, as well as OSASP Zap. We do similar tests in multiple tools to make sure that we cover the entire set of use cases.

I have this solution deployed as one user on a single machine, which is used by a designated security tester.

What is most valuable?

The most valuable features are Burp Intruder and Burp Scanner.

The automatic scanning feature is helpful.

What needs improvement?

The interface for the automatic scan can be improved because it is easy for technical users, but the business users have trouble with it. There is documentation but the interface should be more user-friendly.

There should be a heads up display like the one available in OWASP Zap. I think that it would be a very good addition.

For how long have I used the solution?

I have worked with PortSwigger Burp for about ten years.

What do I think about the stability of the solution?

This solution is stable and we have had no major problems.

What do I think about the scalability of the solution?

We have had no issues with scalability, although we are using a standalone installation with only a single user. We may expand usage in the future.

Which solution did I use previously and why did I switch?

We also have OWASP Zap and we continue to use these two tools.

Zap has a heads up display within its own browser, which is a very good feature. Zap is also completely free, whereas Burp has a free version but it also has licenses available.

For the most part, we use open-source solutions, which are free of charge.

How was the initial setup?

The initial setup is simple and very straightforward. We were not setting up a server, so it took perhaps five minutes to get up to speed and begin using it.

What's my experience with pricing, setup cost, and licensing?

There are different licenses available that include a free version.

What other advice do I have?

We do have problems with some of the add-ons that we install from the marketplace. They may not be available or out of support, so when you want to install them, they are not there.

This is a very nice tool and anybody can use it, from beginner to expert level. There are some simple and straightforward settings with documentation that is very clear. If you follow the steps you can easily get up to speed within five minutes for a single user.

I would rate this solution an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1170114 - PeerSpot reviewer
Director at a consultancy with 10,001+ employees
Real User
Offers good application security features and is reasonably priced
Pros and Cons
  • "The most valuable feature is the application security. It also has a reasonable price."
  • "The Burp Collaborator needs improvement. There also needs to be improved integration."

What is most valuable?

The most valuable feature is the application security. It also has a reasonable price. 

It has an end product and a repeater. Other solutions don't offer options like these. 

What needs improvement?

The Burp Collaborator needs improvement. There also needs to be improved integration. 

For how long have I used the solution?

I have been using PortSwigger Burp for the past six years. 

What do I think about the stability of the solution?

It's not so stable. Some of the security aspects aren't so stable. 

What do I think about the scalability of the solution?

Burp is scalable. 

We have around 150 users using Burp at my company. We use it daily.  

How are customer service and technical support?

I haven't needed to contact their technical support. 

How was the initial setup?

The initial setup is simple. It only takes two to three minutes. 

What about the implementation team?

We are consultants so we do the implementation ourselves. 

It only requires one person for the implementation and maintenance. 

What's my experience with pricing, setup cost, and licensing?

It costs 39,000 including taxes per year. 

What other advice do I have?

I would recommend this solution to somebody considering Burp. 

I would rate it an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.
Updated: May 2025
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros sharing their opinions.