We performed a comparison between Ixia BreakingPoint and OWASP Zap based on real PeerSpot user reviews.
Find out in this report how the two Static Application Security Testing (SAST) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The DDoS testing module is useful and quick to use."
"The solution has many protocols and options, making it very flexible."
"There is a virtual version of the product which is scaled to 100s of virtual testing blades."
"The most valuable feature of Ixia BreakingPoint is the ransomware and malware database for simulated attacks."
"We use Ixia BreakingPoint for Layer 7 traffic generation. That's what we like."
"I like that we can test cloud applications."
"It is a scalable solution."
"Simple to use, good user interface."
"The best feature is the Zap HUD (Heads Up Display) because the customers can use the website normally. If we scan websites with automatic scanning, and the website has a web application firewall, it's very difficult."
"ZAP is easy to use. The automated scan is a powerful feature. You can simulate attacks with various parameters. ZAP integrates well with SonarQube."
"We use the solution for security testing."
"Two features are valuable. The first one is that the scan gets completed really quickly, and the second one is that even though it searches in a limited scope, what it does in that limited scope is very good. When you use Zap for testing, you're only using it for specific aspects or you're only looking for certain things. It works very well in that limited scope."
"Stability-wise, I rate the solution a nine out of ten. I think it's stable enough. I don't see any crashes within the application, so its stability is high."
"Fuzzer and Java APIs help a lot with our custom needs."
"This solution has improved my organization because it has made us feel safer doing frequent deployments for web applications. If we have something really big, we might get some professional company in to help us but if we're releasing small products, we will check it ourselves with Zap. It makes it easier and safer."
"The price could be better."
"I would appreciate some preconfigured network neighborhoods, which are predefined settings for testing networks."
"The production traffic simulations are not realistic enough for some types of DDoS attacks."
"The integration could improve in Ixia BreakingPoint."
"The solution originally was hard to configure; I'm not sure if they've updated this to make it simpler, but if not, it's something that could be streamlined."
"They should improve UI mode packages for the users."
"The quality of the traffic generation could be improved with Ixia BreakingPoint, i.e. to get closer to being accurate in what a real user will do."
"The solution is somewhat unreliable because after we get the finding, we have to manually verify each of its findings to see whether it's a false positive or a true finding, and it takes time."
"It needs more robust reporting tools."
"There are too many false positives."
"It would be nice to have a solid SQL injection engine built into Zap."
"The documentation is lacking and out-of-date, it really needs more love."
"It doesn't run on absolutely every operating system."
"The reporting feature could be more descriptive."
"If there was an easier to understand exactly what has been checked and what has not been checked, it would make this solution better. We have to trust that it has checked all known vulnerabilities but it's a bit hard to see after the scanning."
Ixia BreakingPoint is ranked 23rd in Static Application Security Testing (SAST) with 8 reviews while OWASP Zap is ranked 7th in Static Application Security Testing (SAST) with 37 reviews. Ixia BreakingPoint is rated 8.4, while OWASP Zap is rated 7.6. The top reviewer of Ixia BreakingPoint writes "Works better for testing traffic, mix profile, and enrollment scenarios than other solutions". On the other hand, the top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". Ixia BreakingPoint is most compared with Spirent CyberFlood and Synopsys Defensics, whereas OWASP Zap is most compared with SonarQube, Acunetix, Qualys Web Application Scanning, PortSwigger Burp Suite Professional and Veracode. See our Ixia BreakingPoint vs. OWASP Zap report.
See our list of best Static Application Security Testing (SAST) vendors.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.