We performed a comparison between Fortify WebInspect and OWASP Zap based on real PeerSpot user reviews.
Find out in this report how the two Dynamic Application Security Testing (DAST) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The most valuable feature of this solution is the ability to make our customers more secure."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"It's a well-known platform for doing dynamic application scanning."
"The solution's technical support was very helpful."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
"The user interface is ok and it is very simple to use."
"Guided Scan option allows us to easily scan and share reports."
"Fortify WebInspect is a scalable solution, it is good for a lot of applications."
"The solution is good at reporting the vulnerabilities of the application."
"Stability-wise, I rate the solution a nine out of ten. I think it's stable enough. I don't see any crashes within the application, so its stability is high."
"The solution has tightened our security."
"The application scanning feature is the most valuable feature."
"The product helps users to scan and fix vulnerabilities in the pipeline."
"The vulnerabilities that it finds, because the primary goal is to secure applications and websites."
"The scalability of this product is very good."
"The stability of the solution is very good."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"Not sufficiently compatible with some of our systems."
"I'm not sure licensing, but on the pricing, it's a bit costly. It's a bit overpriced. Though it is an enterprise tool, there are other tools also with similar functionalities."
"The initial setup was complex."
"The scanner could be better."
"Lately, we've seen more false negatives."
"The solution needs better integration with Microsoft's Azure Cloud or an extension of Azure DevOps. In fact, it should better integrate with any cloud provider. Right now, it's quite difficult to integrate with that solution, from the cloud perspective."
"Online documentation can be improved to utilize all features of ZAP and API methods to make use in automation."
"I prefer Burp Suite to SWASP Zap because of the extensive coverage it offers."
"The documentation needs to be improved because I had to learn everything from watching YouTube videos."
"The forced browse has been incorporated into the program and it is resource-intensive."
"I would like to see a version of “repeater” within OWASP ZAP, a tool capable of sending from one to 1000 of the same requests, but with preselected modified fields, changing from a predetermined word list, or manually created."
"It would be beneficial to enhance the algorithm to provide better summaries of automatic scanning results."
"There are too many false positives."
"It needs more robust reporting tools."
Fortify WebInspect is ranked 2nd in Dynamic Application Security Testing (DAST) with 17 reviews while OWASP Zap is ranked 8th in Application Security Testing (AST) with 37 reviews. Fortify WebInspect is rated 7.0, while OWASP Zap is rated 7.6. The top reviewer of Fortify WebInspect writes "A powerful tool catering to multiple use cases that provides reasonably good technical support". On the other hand, the top reviewer of OWASP Zap writes "Great for automating and testing and has tightened our security ". Fortify WebInspect is most compared with PortSwigger Burp Suite Professional, Fortify on Demand, Acunetix, HCL AppScan and Qualys Web Application Scanning, whereas OWASP Zap is most compared with SonarQube, Acunetix, PortSwigger Burp Suite Professional, Qualys Web Application Scanning and Invicti. See our Fortify WebInspect vs. OWASP Zap report.
We monitor all Dynamic Application Security Testing (DAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.