Our primary use case for this solution is to perform application security testing.
Senior Security Engineer at a insurance company with 10,001+ employees
More accurate than other solutions we are using but can sometimes be slow to perform
Pros and Cons
- "This tool is more accurate than the other solutions that we use, and reports fewer false positives."
- "There is a lot to this product, and it would be good if when you purchase the tool, they can provide us with a more extensive user manual."
What is our primary use case?
How has it helped my organization?
I don't have specific metrics but I can say that using this tool adds value.
What is most valuable?
There are several features that I like about this solution. The most valuable feature is that it has support for add-ons where we can add extra little scripts to the tool to perform more automated testing.
I like using the Repeater feature to perform proxy testing, and the Repeaters have dashboards now. The add-ons are compatible with the dashboards, as well.
What needs improvement?
There is a lot to this product, and it would be good if when you purchase the tool, they can provide us with a more extensive user manual. This would help us to better understand the product, and we would not need to buy a separate book.
In the next release, I want to see it more interactive and have more multitasking with some faster features. Sometimes scanning takes a long time, so they need to add more tricks to reduce the time spent in security testing.
Buyer's Guide
PortSwigger Burp Suite Professional
October 2025

Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,829 professionals have used our research since 2012.
For how long have I used the solution?
More than one year.
What do I think about the stability of the solution?
Stability-wise it is good.
What do I think about the scalability of the solution?
It is possible to work on multiple projects at the same time. I have tried five or six, and it is working fine. I would agree that the scalability is very good, and we have not found a limit yet.
We have approximately thirty users for this solution and they are the testers. As our team grows, we'll need to buy more licenses.
How are customer service and support?
We have used technical support three times, and each time received an email within twenty-four hours. They first try to understand the problem, and then after this, they provide step by step instructions for what to do. It's pretty easy.
Which solution did I use previously and why did I switch?
We have always used Burp Suite because it is a well-known tool.
How was the initial setup?
This solution is very easy to install and understand.
For a single user, it will take thirty to forty-five minutes. For our organization, it took between eight and nine hours.
What about the implementation team?
We handled the implementation and deployment ourselves.
What was our ROI?
We have seen ROI with this product.
What's my experience with pricing, setup cost, and licensing?
The cost is approximately $500 for a single license, and there are no additional costs beyond the standard licensing fees.
Which other solutions did I evaluate?
We considered using OWASP Zed Attack Proxy, which is open source. We decided to use this alongside the current solution, and also with IBM Security AppScan.
This tool is more accurate than the other solutions that we use and reports fewer false positives.
What other advice do I have?
They are steadily improving things and adding features to this product. It was only three months ago when they added the dashboard support. Before that, they only had passive and active scanning to perform the testing part. It now has a complete website of scanning features which were previously not there.
I would rate this solution a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Security Analyst at a tech services company with 201-500 employees
Very Well Suited for Personal Use
Pros and Cons
- ""The product is very good just the way it is; It has everything already well established and functions great. I can't see any way for this current version to be improved.""
- "The Initial setup is a bit complex."
What is our primary use case?
My primary use case for this solution is designed around my own personal use. Burp Suite is a graphical tool for testing Web application security. The tool is written in Java.
How has it helped my organization?
I use Burp Suite on my laptop in my room for my personal research study. Since I don't use it for corporate work or company research purposes I can't comment on how it has improved my organization.
What is most valuable?
In my opinion, all of the features seem to be of equal value really. I'm currently using the latest version.
What needs improvement?
The product is very good just the way it is; It has everything already well established and functions great. I can't see any way for this current version to be improved.
For how long have I used the solution?
One to three years.
What do I think about the stability of the solution?
My impressions of the stability of the solution are quite good.
What do I think about the scalability of the solution?
My impressions of the scalability of the solution are good.
Which solution did I use previously and why did I switch?
At work, I use an open source SAP solution. It's a free tool. It's a fully automated tool and it's fully furnished. Currently, I'm the only user and it's my job to analyze this product.
How was the initial setup?
The initial setup was somewhat complex, to be honest.
What's my experience with pricing, setup cost, and licensing?
My only advice for anyone looking for a personal use case for testing Web application security is this is a good option.
Which other solutions did I evaluate?
Before choosing this tool, no, I didn't evaluate any other options. I know what I wanted and I'm very happy with it.
What other advice do I have?
It's actually a very good product. It's pretty automated and it's easy to work with. No additional features need to be added because it's already an extraordinary tool. So there's no need for additional improvement.
Great product. I rate this product a 9 out of 10 for its total package of value-added features.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
PortSwigger Burp Suite Professional
October 2025

Learn what your peers think about PortSwigger Burp Suite Professional. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,829 professionals have used our research since 2012.
Senior Information Security Analyst at a tech services company with 10,001+ employees
Thanks to the availability in executable JAR format -- this makes it a highly portable solution
Pros and Cons
- "I personally love its capability to automatically and accurately detect vulnerabilities. So, I would say it is the Burp scanner that is THE most powerful, valuable, and an awesome feature."
- "The one feature that I would like to see in Burp is active scanning of REST based web services. A lot of organizations are providing APIs to access their services to support different business models like SaaS. Scanning these APIs is still a challenge for many security product companies."
What is our primary use case?
Primarily, I use it for scanning the applications and as a proxy to capture and manipulate the application traffic. That is the most useful set of features I have seen in this tool.
How has it helped my organization?
The customer is almost all the time results-oriented and they want them real quick.
Burp gives my organization a great authentic source of information on the security posture of web infrastructure.
PortSwigger launched a feature called Burp Extender, which enables organizations to use their own third-party code and integrate with Burp to use its capabilities and create their own customized results. This way, organizations do not need to worry about changing the reporting format and all. They will just get better results.
What is most valuable?
Burp is the best web application penetration testing tool that I have ever used.
Although all the features of Burp are very useful, I personally love its capability to automatically and accurately detect vulnerabilities. So, I would say it is the Burp scanner that is THE most powerful, valuable, and an awesome feature.
Another, very interesting and quite extensible feature is Intruder. The way you can customize your payloads to suit your penetration testing needs is simply outstanding.
The best thing is that all features are available just out-of-the-box and at a very nominal price.
What needs improvement?
The one feature that I would like to see in Burp is active scanning of REST based web services. A lot of organizations are providing APIs to access their services to support different business models like SaaS. Scanning these APIs is still a challenge for many security product companies. Even Burp does not have a direct and easy way of scanning REST based web services.
There is a capability to scan SOAP based web services provided there is a WSDL available. So, to conclude active web services scanning is something that I would like to see as an improvement in Burp.
For how long have I used the solution?
More than five years.
What do I think about the stability of the solution?
No. Quite stable. The executable JAR file is quite better since there is no installation required.
What do I think about the scalability of the solution?
I have only used it as a single user. But many of my colleagues use it and I have never heard of any such issues.
How are customer service and technical support?
Apologies. Never Tried.
Which solution did I use previously and why did I switch?
I have used a lot of tools for web application scanning and penetration testing -- like Qualys WAS, Nikto, OWASP ZAP proxy, Paros Proxy, DirBuster, Burp, etc.
The reason for switching to Burp is the capabilities of this tool. The scanner is very powerful and the way it integrates with third-party code is really cool. Other tools simply do not have these capabilities.
How was the initial setup?
Quite straightforward. Thanks to the availability in executable JAR format -- this makes it a highly portable solution.
What about the implementation team?
I have implemented as an inhouse one. There is no installation as such since the solution is an executable jar file. User just need to double click and start using it.
What's my experience with pricing, setup cost, and licensing?
This is a value for money product.
Which other solutions did I evaluate?
I am a consistent user of web application scanners and penetration testing solutions.
I have used Qualys WAS, OWASP ZAP, sqlmap, Paros Proxy, and Nikto. But nothing stands close to Burp, because this tool has everything in one single portable powerful package.
What other advice do I have?
If you are looking for a single web application penetration testing solution at low cost, definitely give it a try. You can request a trial of the pro version from PortSwigger if you would like to see the scanner capability in action.
They will, of course, require organizational contacts. Almost all the other features are available in the free version, also.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Penetration Testing Advisor at a tech services company with 1,001-5,000 employees
The real power of the product lies in the modules that aid in manual testing.
What is most valuable?
- Intruder - allows inserting predefined or custom payloads at chosen locations inside requests and analyzing results using custom filters;
- Repeater - allows reissuing requests to manually verify reported issues, changing parameters or issuing a specific sequence of requests to test for logic flaws;
- Extender - allows installing additional modules from the BApp store, created by the community in Java, Python or Ruby;
How has it helped my organization?
It provides unique features that help me quickly identify and exploit security vulnerabilities in web applications.
What needs improvement?
Some extra features are not available in the core product (WSDL parsing, SOAP calls, Error checks, Authorization bypass), but additional modules created by the community can be easily installed from the BApp store through Extender, or you can write your own in Java, Python or Ruby.
For how long have I used the solution?
I have been using it for two years.
What do I think about the stability of the solution?
Spidering large websites can use a lot of memory and might result in a crash on systems with lower RAM.
What do I think about the scalability of the solution?
It's better to add only one website per project for the same reason as above.
How are customer service and technical support?
I didn't use technical support.
Which solution did I use previously and why did I switch?
I used many solutions but I found the best value, features and documentation in Burp.
How was the initial setup?
Starting Burp only involves running a .jar file. The latest version also comes with a executable installer. Setting up a project can be more complex, involving configuring the proxy, scope and different spidering/scanning options.
What's my experience with pricing, setup cost, and licensing?
I believe it has one of the lowest prices for commercial products ($~350 per user per year).
Which other solutions did I evaluate?
Before choosing this product, I evaluated free products - Arachni, OWASP ZAP, w3af, Vega - and commercial products - Acunetix, Qualys Web Application Scanner.
What other advice do I have?
If you expect a product in which you input your website and click a scan button, Burp is not for you. Burp Suite Pro can perform an automatic scan, but the real power of the product lies in the modules that aid in manual testing. A few weeks are usually needed to read the documentation and ramp-up on all the features, for someone without previous experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Systems Security Officer at a financial services firm with 1,001-5,000 employees
It helps capturing and modifying HTTP packets and variables, and observing the application’s response.
What is most valuable?
- HTTP proxy for packet capture
- Repeater
- Intruder
- Spider
- Decoder
- Comparer
How has it helped my organization?
Burp Suite is a versatile tool for manual web application penetration testing; mainly used by skilled ethical hackers to test security of web-based applications. It helps capturing and modifying HTTP packets and variables, and observing the application’s response. It allows fuzzing the variable in an intuitive way, repeating the same method, crawling a web application, and similar functionalities.
What needs improvement?
The professional edition of Burp Suite provides some automated pen-testing scripts to detect application vulnerabilities, like SQL injection, XSS, etc. However, this component is not extremely useful. The results need to be double-checked manually, and false positives are very common, i.e., the tool detects a vulnerability from the HTTP respond when a vulnerability does not actually exist.
For how long have I used the solution?
I have been using it for five years.
What do I think about the stability of the solution?
It is a tool used mostly for manual tasks, it is stable enough for that purpose.
What do I think about the scalability of the solution?
If you attempt to map a large website using the Spider component, it can take a long time, and the tool may crash.
How are customer service and technical support?
I have not used technical support, but online documentation and Help have always been sufficient.
Which solution did I use previously and why did I switch?
I have used Charles Proxy, CAT, and Fiddler as well, but found Burp easier to use.
For automated scanning, there are stronger alternatives to Burp, such as Acunetix, IBM AppScan, Nexpose, Qualys, etc.
How was the initial setup?
There is no setup needed. It is a Java app that does not need to be installed.
What's my experience with pricing, setup cost, and licensing?
The free version is one of the best proxy tools for manual testing. For automated testing, it provides the best value for money in the market.
Which other solutions did I evaluate?
I evaluated Charles Proxy, Fiddler, and Context App Tool (CAT), which are great HTTP proxies. I like CAT and Burp as the best free ones.
What other advice do I have?
To effectively use Burp, you will need someone with enough technical hands on skills in ethical hacking and penetration testing.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Security Consultant at a tech services company with 501-1,000 employees
It is the best all round solution for manual application testing but there are some stability problems directly related to Java.
What is most valuable?
- Proxy
- Repeater
- Intruder
- Extender API (and plug-ins)
- CSRF generator
How has it helped my organization?
This is by far the best application assessment tool I have used. It is more usable and has more features than most of the enterprise tools that cost 10-100 times as much.
For how long have I used the solution?
I've used it for five years.
What was my experience with deployment of the solution?
No issues encountered.
What do I think about the stability of the solution?
There are some memory issues, where the application runs out of memory and crashes. This is directly related to Java. This was improved after switching to 64-bit Java, but it still creeps up once in a while.
What do I think about the scalability of the solution?
No issues encountered.
How are customer service and technical support?
Customer Service:
It's excellent.
Technical Support:It's very good.
Which solution did I use previously and why did I switch?
I use many projects, but Burp is the best all round solution for manual application testing.
How was the initial setup?
It's very straightforward, you just have to double-click a Jar file.
What other advice do I have?
You get many features with the free product, but the real power is unlocked with the Pro version. The intruder is an amazing tool and makes the entire product worth purchasing, and the ability to perform automatic backups is well worth the small price of this product as well.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Application Security Enginee at a tech vendor with 1,001-5,000 employees
Has valuable scanner functionality and a simple setup process
Pros and Cons
- "One useful function is the ability to send requests to the repeater without making actual requests through the browser, allowing me to modify requests easily."
- "One area for improvement is the integrated browser, Chromium. Single Sign-On (SSO) methods like Microsoft authentication login sometimes fail and show errors. As a workaround, I have to use a different browser, such as Firefox, to log in and make Burp work."
What is our primary use case?
We use the product primarily for application security. It helps us conduct scans and perform manual testing.
What is most valuable?
The platform's most valuable feature is the scanner. It also includes highly beneficial tools like the repeater and decoder. One useful function is the ability to send requests to the repeater without making actual requests through the browser, allowing me to modify requests easily. Additionally, the availability of various extensions, such as SQLite, adds to its value.
What needs improvement?
One area for improvement is the integrated browser, Chromium. Single Sign-On (SSO) methods like Microsoft authentication login sometimes fail and show errors. As a workaround, I have to use a different browser, such as Firefox, to log in and make Burp work.
I suggest adding a static code analysis feature to Burp. A plugin developers could install in their Integrated Development Environments (IDEs), like Visual Studio, would be incredibly useful. It would allow developers to perform code scanning as they write code.
For how long have I used the solution?
I have been working with PortSwigger Burp Suite Professional for almost ten years.
What do I think about the stability of the solution?
I rate the product stability an eight out of ten.
What do I think about the scalability of the solution?
There are approximately 10 to 15 users in my department or company using Burp. I rate the scalability an eight out of ten.
How are customer service and support?
The technical support team resolved my issue, though it was not immediate. Since this experience was years ago, I haven't raised any support tickets recently.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
One free tool that I consider a good competitor to Burp is OWASP ZAP.
While ZAP has the advantage of being open-source and cost-free, I would choose Burp for penetration testing. Burp is the best for this purpose, although ZAP is adequate for basic tasks, especially in companies where Burp Suite Professional is unavailable.
How was the initial setup?
The initial setup is simple. We use the desktop version, with the application installed on our local machines.
What's my experience with pricing, setup cost, and licensing?
The platform's pricing is reasonable. It is not very high, especially compared to other tools like Acunetix or Fortify, which are quite expensive.
What other advice do I have?
I recommend the solution to others and rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Cyber Security Analyst at a tech services company with 501-1,000 employees
Used to intercept requests and scan applications
Pros and Cons
- "The most valuable feature of PortSwigger Burp Suite Professional is the Burp Intruder tool."
- "The solution’s pricing could be improved."
What is our primary use case?
I use the solution to intercept requests and scan applications.
What is most valuable?
The most valuable feature of PortSwigger Burp Suite Professional is the Burp Intruder tool.
What needs improvement?
The solution’s pricing could be improved.
For how long have I used the solution?
I have been using PortSwigger Burp Suite Professional for around two to three years.
What do I think about the stability of the solution?
We have not faced any issues with the solution’s stability.
What do I think about the scalability of the solution?
Over 500 people are using the solution in our organization.
How was the initial setup?
The solution’s initial setup is easy.
What's my experience with pricing, setup cost, and licensing?
PortSwigger Burp Suite Professional is an expensive solution.
What other advice do I have?
I would recommend the solution to other users. Using PortSwigger Burp Suite Professional for the first time is not easy, but you can use it easily after using a demo version. The solution's Intruder tool has helped improve our security testing efficiency. The solution's Repeater tool has helped us with testing for web vulnerabilities.
Overall, I rate the solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Updated: October 2025
Product Categories
Application Security Tools Static Application Security Testing (SAST) Fuzz Testing ToolsPopular Comparisons
SonarQube Server (formerly SonarQube)
Checkmarx One
Coverity Static
GitHub Advanced Security
OpenText Core Application Security
SonarQube Cloud (formerly SonarCloud)
Sonatype Lifecycle
Qualys Web Application Scanning
Buyer's Guide
Download our free PortSwigger Burp Suite Professional Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Is OWASP Zap better than PortSwigger Burp Suite Pro?
- What is the biggest difference between OWASP Zap and PortSwigger Burp?
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the Top 5 cybersecurity trends in 2022?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- We're evaluating Tripwire, what else should we consider?
- Which application security solutions include both vulnerability scans and quality checks?
- Is SonarQube the best tool for static analysis?
- Why Do I Need Application Security Software?