Best solution for DevSecOps Application Security
December 19, 2022

Best solution for DevSecOps Application Security

Anonymous | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User

Overall Satisfaction with Micro Focus Fortify WebInspect

I have used Micro Focus Fortify WebInspect for scanning applications during runtime and finding OWASP TOP 10 vulnerabilities. I have used it to integrate with CICD pipeline to automate security scanning of applications and website
  • Detection of vulnerabilities
  • Scanning pipelines
  • Integration is super easy
  • Scanned cloud based applications
  • It should focus on microservices and develop features
  • Performance need to be improved
  • Multiple apps should be easy to scan in parallel thus saving time
  • Integration with CICD
  • Dashboard is great
  • DevSecOps management is great
  • DevSecOps helped in reducing efforts
  • License cost was less
  • We could roll out double the count of applications with implementation of WebInspect
Micro Focus Fortify WebInspect is better when it comes to speed, integration and detection capabilities as compared to Insight Appsec. What I loved the most is the broad coverage of vulnerabilities it identified as against Insight Appsec. Apart from detection capabilities the time taken is also less compared to Insight Appsec. Given the performance of Micro Focus Fortify WebInspect I would strongly recommend to everyone looking for DevSecOps and application security solutions

Do you think Fortify by OpenText delivers good value for the price?

Yes

Are you happy with Fortify by OpenText's feature set?

Yes

Did Fortify by OpenText live up to sales and marketing promises?

Yes

Did implementation of Fortify by OpenText go as expected?

Yes

Would you buy Fortify by OpenText again?

Yes

It is best suited for runtime application security scanning and very useful for automation. You can seemlessly integrate with pipeline for dynamic scans. Cloud based apps can also be scanned for vulnerabilities, cross site scripting attacks. Basically all OWASP TOP 10. It is less appropriate to use if you have serverless architecture