Tripwire IP360 vs. Veracode

As of June 2019, Tripwire IP360 is ranked 9th in Vulnerability Management with 2 reviews vs Veracode which is ranked 1st in Application Security with 43 reviews. The top reviewer of Tripwire IP360 writes "A mature and evolving solution that has become the pinnacle point for anything that enters the network". The top reviewer of Veracode writes "Enables us to automatically submit each new build for scanning and get results directly into our JIRA". Tripwire IP360 is most compared with Tenable Nessus, Qualys Web Application Scanning and Acunetix Vulnerability Scanner. Veracode is most compared with SonarQube, Micro Focus Fortify on Demand and Checkmarx.
Cancel
You must select at least 2 products to compare!
Tripwire IP360 Logo
1,872 views|468 comparisons
Veracode Logo
49,257 views|21,812 comparisons
Most Helpful Review
Find out what your peers are saying about Qualys, Skybox Security, Rapid7 and others in Vulnerability Management. Updated: June 2019.
345,915 professionals have used our research since 2012.
Quotes From Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:

Pros
It's become the pinnacle point for anything that enters the network or anything that's passing through to production to first be affected by IP360, hardened, and up to standard. For our integrity management, one was deployed in the bank about two years ago and that's still going to expand the usage and the product itself. That will go hand in hand with training and expanding the product as for where it's deployed.

Read more »

I have used this solution in multiple projects for vulnerability testing and finding security leaks within the code.The most valuable feature comes from the fact that it is cloud-based, and I can scale up without having to worry about any other infrastructure needs.We are using the Veracode tools to expose the engineers to the security vulnerabilities that were introduced with the new features, i.e. a lot faster or sooner in the development life cycle.One of the valuable features is that it gives us the option of static scanning. Most tools of this type are centered around dynamic scanning. Having a static scan is very important.It has an easy-to-use interface.Veracode provides faster scans compared to other static analysis security testing tools.It has almost completely eliminated the presence of SQLi vulnerabilities.It gives feedback to developers on the effectiveness of their secure coding practices.

Read more »

Cons
The reporting functions can use improvement. There is room for growth because reporting functions differ a lot depending on what you're going to output. It depends on whether it's for technical or senior management and how it's interpreted. There could be growth within the reporting functionality side.

Read more »

Ideally, I would like better reporting that gives me a more concise and accurate description of what my pain points are, and how to get to them.I would like to see expanded coverage for supporting more platforms, frameworks, and languages.Veracode should make it easier to navigate between the solutions that they offer, i.e. between dynamic, static, and the source code analysis.We would like a way to mark entire modules as "safe." The lack of this feature hasn't stopped us previously, it just makes our task more tedious at times. That kind of feature would save us time.Veracode scans provide a higher number of false positives.The overall reporting structure is complicated, and it's difficult to understand the report.It needs more timely support for newer languages and framework versions.They should improve on the static scanning time.

Read more »

Pricing and Cost Advice
Information Not Available
They have just streamlined the licensing and they have a number of flexible options available, so overall it is quite good, albeit pricey.They just changed their pricing model two weeks ago. They went from a per-app license to a per-megabyte license. I know that the dynamic scan was $500 per app. Static analysis was about $4500 yearly. The license is only for the number of users, it doesn't matter what data you put in there. That was the old model. I do not know how the new model works.Veracode has been fair. We use their SaaS solution and it's just an annual subscription.No issues, the pricing seems reasonable.It is pricey. There is a lot of value in the product, but it is a costly tool.I recommend going for a one-year licensing with CA, because currently they are the leaders in this field with more features and a much better turn around time with a cheaper position, but there are a lot of new companies coming up in the market and they are building up their platforms.Costs are reasonable. No special infrastructure is required and the license model is good.I think the pricing is in line with the rest of the tools. I think you get what you pay for. It is certainly not inexpensive, but the value proposition is there. There are certainly cheaper tools, but I don't think we'd be getting the support that we get with those, and that is what separates this product from the others.

Read more »

report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
345,915 professionals have used our research since 2012.
Ranking
9th
Views
1,872
Comparisons
468
Reviews
1
Average Words per Review
529
Avg. Rating
6.0
1st
Views
49,257
Comparisons
21,812
Reviews
41
Average Words per Review
619
Avg. Rating
8.2
Top Comparisons
Compared 38% of the time.
Compared 46% of the time.
Compared 11% of the time.
Also Known As
IP360
Learn
Tripwire
Veracode
Overview

Tripwire IP360 delivers risk-based vulnerability assessment and asset discovery capabilities. With IP360, you get:

  • Comprehensive discovery and profiling of all network assets.
  • Highly scalable architecture with low network impact.
  • Advanced vulnerability scoring that identifies top risks.
  • Prioritized change results when used with Tripwire Enterprise.

Veracode is an application security company that offers an automated cloud-based service for securing web, mobile and third-party enterprise applications. Veracode provides multiple security analysis technologies on a single platform, including static analysis, dynamic analysis, mobile application behavioral analysis and software composition analysis.

Offer
Learn more about Tripwire IP360
Learn more about Veracode
Sample Customers
State of Iowa, State of Minnesota, U.S. CellularState of Missouri, Rekner
Top Industries
No Data Available
REVIEWERS
Financial Services Firm36%
Insurance Company18%
Consumer Goods9%
Retailer5%
VISITORS READING REVIEWS
Financial Services Firm32%
Healthcare Company10%
Software R&D Company10%
Manufacturing Company7%
Company Size
No Data Available
REVIEWERS
Small Business24%
Midsize Enterprise24%
Large Enterprise52%
VISITORS READING REVIEWS
Small Business12%
Midsize Enterprise16%
Large Enterprise72%
Find out what your peers are saying about Qualys, Skybox Security, Rapid7 and others in Vulnerability Management. Updated: June 2019.
345,915 professionals have used our research since 2012.
We monitor all Vulnerability Management reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.

Sign Up with Email