TrustRadius Insights for HCL AppScan are summaries of user sentiment data from TrustRadius reviews and, when necessary, third party data sources.
Business Problems Solved
HCL AppScan has been highly regarded by organizations seeking to secure their mobile and web applications. Users have found the tool invaluable for performing Dynamic Application Scans, enabling them to navigate through sites and identify potential vulnerabilities or fixes. The application offers a range of configurations, allowing users to customize their security measures based on their specific needs and capacity. This flexibility has made HCL AppScan a popular choice for conducting in-depth security assessments as part of vulnerability management programs. Users have compared HCL AppScan with other products and free alternatives, noting that the test patterns have become standardized across different solutions. The tool has not only helped teams reduce errors but also ensured adherence to security best practices throughout the software development cycle. Additionally, HCL AppScan provides holistic visibility into the security posture of applications, safeguarding them from threats, vulnerabilities, and compliance violations. Supporting a wide array of languages, this well-engineered source code analysis tool is highly regarded for its static application security testing capabilities. Users have found it easy to share reports generated by HCL AppScan with development members, facilitating collaboration and problem-solving. Furthermore, the tool has been used to pinpoint application vulnerabilities in web applications as well as ensure patching compliance and identify new vulnerabilities. Overall, HCL AppScan has emerged as a reliable solution for organizations looking to proactively address security concerns within their applications.
This application helps to perform Dynamic Application Scan, in which the HCL AppScan dynamically navigates through the site and finds any vulnerabilities or fixes that can be done to prevent any future attack. The best thing about this application is the variety of configurations we can do depending on the scenario and the ping capacity.
Pros
Test the application
Explore the application for vulnerabilities
Runs automatic scans
Cons
It can have a FAQ session in the Application itself.
It can recommend the fix for the error that occurred during the scan.
Like its storing multiple manuals explore, It should have the capability of storing multiple logins.
Likelihood to Recommend
I would say that HCL AppScan is very simple to understand and use since it uses a user-friendly interface and the terminologies that are used in the interface of the application is very clear. We can automate a scan with any third party like Jenkins. The fact, I don't like is the time takes to execute the application, it should be better.
VU
Verified User
Engineer in Engineering (Computer Software company, 10,001+ employees)
HCL AppScan provides mobile application scan with predefined templates integration with common code repositories supported Supports 13+ languages including C/C++, COBOL, ColdFusion, Java™ , Android, JSP, JavaScript, Perl, PHP, PL/SQL/T-SQL, C#, ASP.NET, and VB.NET on the other hand, it requires upfront planning for setup and configuration the recording of the application is crucial to have valuable test completion There is quite a complex list of supported browsers May be resource intensive which can cause long run-times for dynamic scans the application crashes sometimes
Pros
learns behavior of each application to test application-specific vulnerabilities
Provides mobile application scan with predefined templates
Cons
simplify the upfront planning for configuration
improves the resource management to prevent from crashes and timeout
Likelihood to Recommend
strengths : identifies Static and Dynamic Security vulnerabilities, has IDE plugins for ease of use like VS Plugin,
Eclipse Plugin, IntelliJ, etc Challenges : support build of code files prior to scan, offers limited static analysis features for data identification and
runtime data tracking