2020-12-17T09:14:00Z

What alternatives are there for Fortify WebInspect and Fortify SCA?

Dear All, 

Can you suggest 2 or 3 products that could compete with:

1. Fortify WebInspect 

2. Fortify Static Code Analyzer

I need suggestions for similar products so I could compare for my consultant project. 
Thanks in advance for the advice.

Regards

4
PeerSpot user
4 Answers
Russell Rothstein - PeerSpot reviewer
CEO at PeerSpot
Vendor
2020-12-17T18:26:06Z
Dec 17, 2020

According to the IT Central Station community, the most popular alternatives to Fortify WebInspect are Micro Focus Fortify on Demand, OWASP Zap, PortSwigger Burp, and HCL AppScan. Hope that's helpful!

Dec 21, 2020

@Russell Rothstein Thank You russel

PeerSpot user
Search for a product comparison in Software Composition Analysis (SCA)
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D
Reseller
Top 5Leaderboard
2021-02-11T12:09:19Z
Feb 11, 2021

I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.

TR
Founder at Saltworks Security
Real User
2021-01-18T15:02:18Z
Jan 18, 2021

Rendra, 


You need to ask yourself a few questions: 
1. Do I know is the technology stack (languages) that needs to be supported? 
2. Do I have access to the Source Code, just Binaries OR Both? 
3. Do I need to support SCA(FOSS) 
4. Do I need a unified Dashboard for reporting for SAST, DAST & SCA? 
5. What is the size of the experienced team I have to support this? 


For a DAST solution: 
1. What is the size of the experienced team I have to support this? 
2. Do I want the DAST to integrate with other tools (BurpSuite, MetaSploit, WAF, etc) 
3. Do I want the DAST to automate from a Postman Script, Jenkins Build Server, JIRA, ServiceNow, etc. 
4. Do I need a unified Dashboard for reporting for SAST, DAST & SCA? 


Instead of asking who can compete with Fortify, it might be better to ask who can compliment Fortify OR what did I dislike most about Fortify. Then find some others who will give you a fair and unbiased opinion. 


When you look at the top 4 players in the market being Fortify, VeraCode, Checkmarx, Synopsys.... what do you see? Then ask why? (Hint...all top leadership and top sales begin at Fortify) 


Hope this helps.

OV
CEO at MergeBase
Vendor
2020-12-18T19:17:15Z
Dec 18, 2020

Fortify Static Code Analyzer is actually NOT an SCA (Software Composition Analysis) tool! It competes more with Checkmarx and Veracode

TR
Founder at Saltworks Security
Real User
Jan 18, 2021

@Oscar Van Der Meer Fortify SCA (Static Code Analyzer) was around way before SCA (Software Composition Analysis). There are various integrations with Software Composition Analysis (SonaType, BlackDuck, Snyk, WhiteSource, and OWASP Dependency Checker & Track. The reason behind it is to allow customers the flexibility to  integrate with the tool the line of business chooses within the corporation. 

PeerSpot user
Learn what your peers think about Fortify WebInspect. Get advice and tips from experienced pros sharing their opinions. Updated: September 2023.
735,226 professionals have used our research since 2012.
Related Questions
GO
Director Information Security at Coast Capital Savings Credit Union
Aug 10, 2023
Hello community,  I am the Director of Information Security at a large financial services firm. I am currently researching Fortify WebInspect and PortSwigger Burp Suite Enterprise Edition. Which solution do you prefer and why? Thank you for your help.
JC
Information Technology Associate at Auray Technology Corp.
Aug 21, 2023
Hello peers,  I am an Information Technology Associate at a small tech services company. I am currently researching DAST solutions. Which solution do you prefer: Fortify WebInspect or HCL AppScan? Can you please provide a comparison between the two? Thank you.
See 1 answer
Anne Cubarrubia - PeerSpot reviewer
Editor at PeerSpot
Aug 21, 2023
People may prefer Fortify WebInspect to HCL AppScan because Fortify WebInspect has more features and is more scalable. However, if you prioritize affordability and ease of use and configuration, some say that HCL AppScan is the better option. Here is a comparison of the two DAST solutions for your reference: Fortify WebInspect Pros: Wide range of features, including static analysis, dynamic analysis, and interactive analysis Easy to use and configure Good integration with other security solutions Cons: Can be expensive Not as scalable as some other DAST solutions HCL AppScan Pros: Affordable Easy to use and configure Good integration with other HCL security solutions Cons: Limited feature set Not as scalable as Fortify WebInspect
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
Apr 19, 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to better connect with peers and other independent experts who provide advice without vendor bias. Our users have ranked these solutions according to their valuable features, and discuss which features they like most and why. You can read user reviews for the Top 5 Software Composition Analysis (SCA...
NC
Content Manager at PeerSpot (formerly IT Central Station)
Apr 11, 2022
The world of technology is constantly undergoing both evolutions and revolutions. It is always difficult to know just what kinds of changes and innovations each year is going to bring. The fields of Development and Operations (DevOps) and Development, Security, and Operations (DevSecOps) are two examples where the best people can do is offer their predictions of what might be in store. PeerSp...
Moderator
it_user72771 - PeerSpot reviewer
Info Sec Consultant at Size 41 Digital
Real User
Top 5
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
Apr 19, 2022
Top 5 Software Composition Analysis (SCA) Solutions 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to...
NC
Content Manager at PeerSpot (formerly IT Central Station)
Apr 11, 2022
PeerSpot Users' DevOps and DevSecOps predictions 2022
The world of technology is constantly undergoing both evolutions and revolutions. It is always di...
Download Free Report
Download our free Fortify WebInspect Report and get advice and tips from experienced pros sharing their opinions. Updated: September 2023.
DOWNLOAD NOW
735,226 professionals have used our research since 2012.