Skip to main content
TrustRadius
HCL AppScan

HCL AppScan
Formerly from IBM

Overview

What is HCL AppScan?

AppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.

Read more
Recent Reviews

TrustRadius Insights

HCL AppScan has been highly regarded by organizations seeking to secure their mobile and web applications. Users have found the tool …
Continue reading
Read all reviews
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is HCL AppScan?

AppScan (formerly Rational AppScan) is an application security testing solution acquired by HCL Technologies from IBM in late 2018. Appscan supports both dynamic (DAST) and static (SAST) application security testing.

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

87 people also want pricing

Alternatives Pricing

What is SonarQube?

SonarQube is a code quality and vulnerability solution for development teams that integrates with CI/CD pipelines to ensure the software you produce is secure, reliable, and maintainable.

What is Rapid7 AppSpider?

AppSpider, from Boston-based Rapid7, is an application security and testing offering based on technology acquired from NT OBJECTives (their similarly named software NTOSpider, acquired with the company during April, 2015).

Return to navigation

Product Demos

HCL AppScan: Issue Management Gateway Workflow Overview

YouTube

HCL AppScan Source V10: Scan a GoLang Application

YouTube

Bring Code to Scan into AppScan Source

YouTube

HCL AppScan Standard: Setting Up Your First Scan (v 10.0.0)

YouTube

Setting up HCL License Server for AppScan

YouTube

HCL AppScan on Cloud: Azure DevOps Plug-In Demo

YouTube
Return to navigation

Product Details

What is HCL AppScan?

HCL AppScan Video

Every decision counts in for our partner @ScuderiaFerrari. When you trust the quality and security of your software, you can be sure that you are planning efficiently and real-time decision making it takes to win races. #HCLAppScan #ScuderiaFerrari Read more about our partne...
 Show More

HCL AppScan Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(23)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

HCL AppScan has been highly regarded by organizations seeking to secure their mobile and web applications. Users have found the tool invaluable for performing Dynamic Application Scans, enabling them to navigate through sites and identify potential vulnerabilities or fixes. The application offers a range of configurations, allowing users to customize their security measures based on their specific needs and capacity. This flexibility has made HCL AppScan a popular choice for conducting in-depth security assessments as part of vulnerability management programs. Users have compared HCL AppScan with other products and free alternatives, noting that the test patterns have become standardized across different solutions. The tool has not only helped teams reduce errors but also ensured adherence to security best practices throughout the software development cycle. Additionally, HCL AppScan provides holistic visibility into the security posture of applications, safeguarding them from threats, vulnerabilities, and compliance violations. Supporting a wide array of languages, this well-engineered source code analysis tool is highly regarded for its static application security testing capabilities. Users have found it easy to share reports generated by HCL AppScan with development members, facilitating collaboration and problem-solving. Furthermore, the tool has been used to pinpoint application vulnerabilities in web applications as well as ensure patching compliance and identify new vulnerabilities. Overall, HCL AppScan has emerged as a reliable solution for organizations looking to proactively address security concerns within their applications.

Users have made the following recommendations based on their experiences with HCL AppScan:

  1. Use IBM AppScan for comprehensive security testing. It provides a wide range of security testing capabilities, including SAST, DAST, Mobile app Security Testing, and IAST. IBM AppScan is suitable for mobile-based organizations and offers support for multiple programming languages. It can easily integrate with CI/CD pipelines, making it suitable for organizations adopting DevOps practices.

  2. Perform thorough testing to identify all vulnerabilities. While IBM AppScan is considered a great product, it may not identify all vulnerabilities. To ensure maximum effectiveness, users recommend conducting proper tests and utilizing specific use cases before moving into production.

  3. Benefit from IBM's expertise in software solutions. IBM is a leader in providing software solutions, and users believe that IBM AppScan is a prime example of their pioneering work. They recommend using IBM AppScan to identify security issues and vulnerabilities within applications. The comprehensive report generated by IBM AppScan helps in understanding and addressing these issues effectively.

In summary, users recommend using IBM AppScan for its wide range of security testing capabilities, suggest thorough testing to identify vulnerabilities, and highlight the benefits of IBM's expertise in software solutions.

Reviews

(1-2 of 2)
Companies can't remove reviews or game the system. Here's why
Score 7 out of 10
Vetted Review
Verified User
Incentivized
This application helps to perform Dynamic Application Scan, in which the HCL AppScan dynamically navigates through the site and finds any vulnerabilities or fixes that can be done to prevent any future attack. The best thing about this application is the variety of configurations we can do depending on the scenario and the ping capacity.
  • Test the application
  • Explore the application for vulnerabilities
  • Runs automatic scans
  • It can have a FAQ session in the Application itself.
  • It can recommend the fix for the error that occurred during the scan.
  • Like its storing multiple manuals explore, It should have the capability of storing multiple logins.
I would say that HCL AppScan is very simple to understand and use since it uses a user-friendly interface and the terminologies that are used in the interface of the application is very clear. We can automate a scan with any third party like Jenkins. The fact, I don't like is the time takes to execute the application, it should be better.
  • Automate the scan
  • Instant and detailed report
  • The configurations in the application
  • The time takes to execute the scan.
  • Sometime it pings the DB much frequently that it may come down.
  • It does not sends any notification referring that the scan is completed.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
HCL AppScan (formerly from IBM) is an application security solution that helps my team to review security flaws and bugs in developing applications. HCL AppScan is a source code analysis tool usually known as Static Application Security Testing (SAST) Tool. The solution is well-engineered and is rated among the leaders in the market. It helped my team reduce errors and ensure we followed security best practices in our software development cycle.
  • Vulnerability reporting
  • Static code analysis
  • Remediation
  • DevSecOps
  • Reduce number of false poitives
  • Add automation tools to reduce manual effort
  • improve user experience
  • prepare dynamic dashboards
HCL AppScan (formerly from IBM) is well suited for reducing security flaws in my team's secure code development. The software identifies a lot of issues automatically which helps us reduce delivery time and prevent security breaches. HCL AppScan (formerly from IBM) lacks innovation and automation functionalities, while other tools offer artificial intelligence-driven analysis that helps the team reduce time and money. Also, there is a need to reduce false-positives generated by the solution
  • DevSecOps
  • Static Code Analyzer
  • Application security reporting
  • Reduced manual effort by 20-30%
  • Integrate 3-4 security solutions with other tools in the system
  • prevent sql injection attacks in our business
Both solutions are decent, however, I had team members who had the experience working with HCL AppScan. Also, the product was priced nominally which suited our budget. Further, HCL AppScan's user community was bigger and many learning resources were freely available which helped junior peers learn quickly and eliminate any issues.
Return to navigation