We performed a comparison between HCL AppScan and Mend.io based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It comes with all of the templates that we need. For example, we are a company that is regulated by PCI. In order to be PCI compliant, we have a lot of checks and procedures to which we have to comply."
"For me, as a manager, it was the ease of use. Inserting security into the development process is not normally an easy project to do. The ability for the developer to actually use it and get results and focuses, that's what counted."
"We are now deploying less defects to production."
"The most valuable feature of HCL AppScan is scanning QR codes."
"The most valuable feature of the solution is the scanning or security part."
"The solution offers services in a few specific development languages."
"It identifies all the URLs and domains on its own and then performs tests and provides the results."
"The product is useful, particularly in its sensitivity and scanning capabilities."
"Its ease of use and good results are the most valuable."
"Our dev team uses the fix suggestions feature to quickly find the best path for remediation."
"There are multiple different integrations there. We use Mend for CI/CD that goes through Azure as well. It works seamlessly. We never have any issues with it."
"The solution boasts a broad range of features and covers much of what an ideal SCA tool should."
"Enables scanning/collecting third-party libraries and classifying license types. In this way we ensure our third-party software policy is followed."
"The dashboard view and the management view are most valuable."
"Mend has reduced our open-source software vulnerabilities and helped us remediate issues quickly. My company's policy is to ensure that vulnerabilities are fixed before it gets to production."
"The most valuable feature is the unified JAR to scan for all langs (wss-scanner jar)."
"The databases for HCL are small and have room for improvement."
"Visibility is an issue for us. Our partners do not know we have integrations with some of IBM products."
"I would like to see the roadmap for this product. We are still waiting to see it as we have only so many resources."
"One thing which I think can be improved is the CI/CD Integration"
"They could add a software component analysis tool."
"A desktop version should be added."
"It has crashed at times."
"Scans become slow on large websites."
"The UI can be slow once in a while, and we're not sure if it's because of the amount of data we have, or it is just a slow product, but it would be nice if it could be improved."
"If anything, I would spend more time making this more user-friendly, better documenting the CLI, and adding more examples to help expand the current documentation."
"Mend supports most of the common package managers, but it doesn't support some that we use. I would appreciate it if they can quickly make these changes to add new package managers when necessary."
"The initial setup could be simplified."
"The UI is not that friendly and you need to learn how to navigate easily."
"It should support multiple SBOM formats to be able to integrate with old industry standards."
"They're working on a UI refresh. That's probably been one of the pain points for us as it feels like a really old application."
"I would like to see the static analysis included with the open-source version."
HCL AppScan is ranked 15th in Application Security Tools with 41 reviews while Mend.io is ranked 5th in Application Security Tools with 29 reviews. HCL AppScan is rated 7.8, while Mend.io is rated 8.4. The top reviewer of HCL AppScan writes " A stable and scalable product useful for application security scanning". On the other hand, the top reviewer of Mend.io writes "Easy to use, great for finding vulnerabilities, and simple to set up". HCL AppScan is most compared with SonarQube, Veracode, Acunetix, OWASP Zap and Invicti, whereas Mend.io is most compared with SonarQube, Black Duck, Snyk, Veracode and Coverity. See our HCL AppScan vs. Mend.io report.
See our list of best Application Security Tools vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.