We performed a comparison between PortSwigger Burp Suite Professional and Qualys Web Application Scanning based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The Spider is the most useful feature. It helps to analyze the entire web application, and it finds all the passes and offers an automated identification of security issues."
"With the Extender Tab, if you know how to code then you can create a plugin and add it to Burp."
"The way they do the research and they keep their profile up to date is great. They identify vulnerabilities and update them immediately."
"For pentesting scenarios, this is the number one tool. It can capture the request, and there are so many functions that are very good for that. For example, a black box satellite host."
"The extension that it provides with the community version for the skills mapping is excellent."
"There is no other tool like it. I like the intuitiveness and the plugins that are available."
"It was easy to learn."
"It is a time-saver application."
"The most valuable feature is that we are able to scan the services and put credentials like a user ID password. We can verify the vulnerability level."
"We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
"It is a cloud-based solution, so it is easy to scale."
"It is a very stable solution."
"By using QualysGuard, we are able to finish external scans with assured results in half the time."
"It is easy to use."
"It is a good product for website penetration testing to detect vulnerabilities."
"It combines both web application vulnerability management and internal vulnerability management on one platform and dashboard. Usually, you have to purchase separate tools."
"Scanning needs to be improved in enterprise and professional versions."
"The use of system memory is an area that can be improved because it uses a lot."
"The initial setup is a bit complex."
"It would be good if the solution could give us more details about what exactly is defective."
"The Burp Collaborator needs improvement. There also needs to be improved integration."
"Scanning APIs using PortSwigger Burp Suite Professional takes a lot of time."
"I need the solution to be more user-friendly. The solution needs to be user-friendly."
"The solution’s pricing could be improved."
"The solution needs to adjust its pricing. They should make it more affordable."
"There should be better visibility into the application."
"It should have better automatic reporting."
"The area of false positives could be improved. There are quite a number of false positives as compared to other solutions. They could probably fine tune the algorithm to be able to reduce the number of false positives being detected."
"Sometimes the response time is low because the handshake fails, and then you have to re-login and start again."
"They should try to include business logic vulnerabilities in the scanner testing."
"The product should allow users to upload their payloads."
"Deployment can be complicated."
More PortSwigger Burp Suite Professional Pricing and Cost Advice →
More Qualys Web Application Scanning Pricing and Cost Advice →
PortSwigger Burp Suite Professional is ranked 9th in Application Security Tools with 55 reviews while Qualys Web Application Scanning is ranked 19th in Application Security Tools with 31 reviews. PortSwigger Burp Suite Professional is rated 8.6, while Qualys Web Application Scanning is rated 7.8. The top reviewer of PortSwigger Burp Suite Professional writes "The solution is versatile and easy to deploy, but it needs to give more detailed security reports". On the other hand, the top reviewer of Qualys Web Application Scanning writes "A stable solution that can be used for infrastructure vulnerability scanning and web application scanning". PortSwigger Burp Suite Professional is most compared with OWASP Zap, Fortify WebInspect, Acunetix, HCL AppScan and SonarQube, whereas Qualys Web Application Scanning is most compared with OWASP Zap, Veracode, SonarQube, Fortify WebInspect and Tenable.io Web Application Scanning. See our PortSwigger Burp Suite Professional vs. Qualys Web Application Scanning report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.