# Burp Suite, Checkmarx vs GitHub Comparison

| | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Star Rating** | 4.8 out of 5 | 4.2 out of 5 | 4.7 out of 5 | 
| **Total Reviews** | 129 | 36 | 2,347 | 
| **Largest Market Segment** | Mid-Market (40.0% of reviews) | Enterprise (53.1% of reviews) | Small-Business (45.3% of reviews) | 
| **Entry Level Price** | $475.00 1 User Per Year | No pricing available | $0.00 1 users | 

---
## Top Pros & Cons

### Burp Suite

Pros:
- Ease of Use (12 reviews)
- User Interface (8 reviews)

Cons:
- Expensive (5 reviews)
- Slow Performance (5 reviews)

### Checkmarx

Pros:
- Implementation Ease (2 reviews)
- User Interface (2 reviews)

Cons:
- False Positives (1 reviews)
- Lacking Features (1 reviews)

### GitHub

Pros:
- Features (124 reviews)
- Ease of Use (111 reviews)

Cons:
- Complexity (47 reviews)
- Learning Curve (45 reviews)

---
## Ratings Comparison
| Rating | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
  | **Meets Requirements** | 9.4 (105 reviews) | 8.6 (27 reviews) | 9.3 (2028 reviews) | 
  | **Ease of Use** | 8.8 (108 reviews) | 8.2 (27 reviews) | 8.7 (2047 reviews) | 
  | **Ease of Setup** | 9.3 (43 reviews) | 7.7 (13 reviews) | 9.0 (658 reviews) | 
  | **Ease of Admin** | 9.2 (28 reviews) | 7.9 (13 reviews) | 8.7 (454 reviews) | 
  | **Quality of Support** | 8.7 (94 reviews) | 8.3 (22 reviews) | 8.7 (1620 reviews) | 
  | **Has the product been a good partner in doing business?** | 9.7 (26 reviews) | 8.3 (12 reviews) | 8.9 (390 reviews) | 
  | **Product Direction (% positive)** | 9.3 (104 reviews) | 7.5 (23 reviews) | 8.9 (1972 reviews) | 

---
## Pricing

### Burp Suite

#### Entry-Level Pricing

Plan: Burp Suite Professional 

Price: $475.00 1 User Per Year

Description: Test, find and exploit vulnerabilities faster with the complete manual testing toolkit. Best for pentesters and hands-on security professionals.

Key Features:
- Map your entire attack surface, including hidden and dynamic content.
- Intercept, inspect, and modify HTTP/S traffic in real time with Proxy.
- Test protected areas and APIs including OpenAPI, GraphQL, and SOAP.

[Browse all 2 editions](https://www.g2.com/products/burp-suite/pricing)

#### Free Trial

No

### Checkmarx

#### Entry-Level Pricing

No pricing available

#### Free Trial

Yes

### GitHub

#### Entry-Level Pricing

Plan: Free for Individuals and Organizations

Price: $0.00 1 users

Description: Basics for teams and developers

Key Features:
- Unlimited public/private repositories
- Unlimited collaborators
- 2,000 Actions minutes/month  (Free for public repositories)

[Browse all 3 editions](https://www.g2.com/products/github/pricing)

#### Free Trial

Yes

---
## Features Comparison By Category

### Application Release Orchestration

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.7/10 | 176 |

#### Administration

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Configuration Management** | Not enough data | Not enough data | 8.9 (140 reviews) | 
| **Access Control** | Not enough data | Not enough data | 9.0 (149 reviews) | 
| **Dashboards** | Not enough data | Not enough data | 8.6 (140 reviews) | 

#### Functionality

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Deployment Automation** | Not enough data | Not enough data | 8.9 (144 reviews) | 
| **Process Analytics** | Not enough data | Not enough data | 8.5 (126 reviews) | 
| **Plugins** | Not enough data | Not enough data | 8.8 (131 reviews) | 
| **APIs / Integrations** | Not enough data | Not enough data | 9.0 (145 reviews) | 
| **Feature Flags** | Not enough data | Not enough data | 8.1 (127 reviews) | 

#### Processes

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Pipelines** | Not enough data | Not enough data | 9.0 (143 reviews) | 
| **Orchestration** | Not enough data | Not enough data | 8.7 (138 reviews) | 
| **Workflow Visualization** | Not enough data | Not enough data | 8.6 (138 reviews) | 

### Penetration Testing

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | 9.3/10 | 23 |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Administration

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **API / Integrations** | 8.7 (18 reviews) | Not enough data | Not enough data | 
| **Extensibility** | 8.9 (19 reviews) | Not enough data | Not enough data | 
| **Reporting and Analytics** | 9.0 (19 reviews) | Not enough data | Not enough data | 

#### Analysis

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Issue Tracking** | 8.3 (15 reviews) | Not enough data | Not enough data | 
| **Reconnaissance** | 9.3 (23 reviews) | Not enough data | Not enough data | 
| **Vulnerability Scan** | 8.9 (23 reviews) | Not enough data | Not enough data | 

#### Testing

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Command-Line Tools** | 7.1 (14 reviews) | Not enough data | Not enough data | 
| **Manual Testing** | 9.4 (22 reviews) | Not enough data | Not enough data | 
| **Test Automation** | 8.1 (20 reviews) | Not enough data | Not enough data | 
| **Performance and Reliability** | 8.8 (22 reviews) | Not enough data | Not enough data | 

### Static Application Security Testing (SAST)

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | 7.8/10 | 6 |
| **GitHub** | 8.6/10 | 64 |

#### Administration

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **API / Integrations** | Not enough data | 8.3 (5 reviews) | 9.0 (41 reviews) | 
| **Extensibility** | Not enough data | 8.3 (5 reviews) | 8.8 (38 reviews) | 

#### Analysis

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Reporting and Analytics** | Not enough data | 8.6 (6 reviews) | 8.3 (40 reviews) | 
| **Issue Tracking** | Not enough data | 8.1 (6 reviews) | 8.7 (43 reviews) | 
| **Static Code Analysis** | Not enough data | 8.3 (6 reviews) | 8.6 (40 reviews) | 
| **Code Analysis** | Not enough data | 8.7 (5 reviews) | 8.8 (46 reviews) | 

#### Testing

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Command-Line Tools** | Not enough data | 7.7 (5 reviews) | 9.1 (41 reviews) | 
| **Manual Testing** | Not enough data | 7.3 (5 reviews) | 8.3 (35 reviews) | 
| **Test Automation** | Not enough data | Not enough data | 8.4 (37 reviews) | 
| **Compliance Testing** | Not enough data | Not enough data | 8.5 (33 reviews) | 
| **Black-Box Scanning** | Not enough data | Not enough data | 8.3 (32 reviews) | 
| **Detection Rate** | Not enough data | Not enough data | 8.6 (34 reviews) | 
| **False Positives** | Not enough data | 5.3 (5 reviews) | 8.0 (32 reviews) | 

#### Agentic AI - Static Application Security Testing (SAST)

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | Not enough data | 

### Dynamic Application Security Testing (DAST)

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Administration

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **API / Integrations** | Not enough data | Not enough data | Not enough data | 
| **Extensibility** | Not enough data | Not enough data | Not enough data | 

#### Analysis

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Reporting and Analytics** | Not enough data | Not enough data | Not enough data | 
| **Issue Tracking** | Not enough data | Not enough data | Not enough data | 
| **Static Code Analysis** | Feature Not Available | Not enough data | Not enough data | 
| **Vulnerability Scan** | Not enough data | Not enough data | Not enough data | 
| **Code Analysis** | Feature Not Available | Not enough data | Not enough data | 

#### Testing

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Manual Testing** | Feature Not Available | Not enough data | Not enough data | 
| **Test Automation** | Not enough data | Not enough data | Not enough data | 
| **Compliance Testing** | Not enough data | Not enough data | Not enough data | 
| **Black-Box Scanning** | Not enough data | Not enough data | Not enough data | 
| **Detection Rate** | Not enough data | Not enough data | Not enough data | 
| **False Positives** | Not enough data | Not enough data | Not enough data | 

### Cloud Infrastructure Automation

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.8/10 | 119 |

#### Administration 

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Administration Console** | Not enough data | Not enough data | 9.0 (91 reviews) | 
| **Task Management** | Not enough data | Not enough data | 8.9 (90 reviews) | 
| **Dashboards and Visualizations** | Not enough data | Not enough data | 8.6 (91 reviews) | 
| **Access Control** | Not enough data | Not enough data | 9.1 (95 reviews) | 

#### Automation

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Test Automation** | Not enough data | Not enough data | 8.8 (90 reviews) | 
| **Intelligent Automation** | Not enough data | Not enough data | 8.6 (83 reviews) | 
| **Release Automation** | Not enough data | Not enough data | 8.7 (91 reviews) | 
| **Automated Provisioning** | Not enough data | Not enough data | 8.8 (83 reviews) | 

#### IT Management

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Workflow Management** | Not enough data | Not enough data | 8.9 (94 reviews) | 
| **Infrastructure Management** | Not enough data | Not enough data | 8.8 (84 reviews) | 
| **IT Discovery** | Not enough data | Not enough data | 8.7 (79 reviews) | 

### Vulnerability Scanner

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | 8.1/10 | 78 |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Performance

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Issue Tracking** | 8.9 (65 reviews) ✓ Verified | Not enough data | Not enough data | 
| **Detection Rate** | 8.6 (69 reviews) ✓ Verified | Not enough data | Not enough data | 
| **False Positives** | 7.1 (69 reviews) ✓ Verified | Not enough data | Not enough data | 
| **Automated Scans** | 8.6 (69 reviews) | Not enough data | Not enough data | 

#### Network

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Compliance Testing** | 7.9 (57 reviews) ✓ Verified | Not enough data | Not enough data | 
| **Perimeter Scanning** | Feature Not Available | Not enough data | Not enough data | 
| **Configuration Monitoring** | Feature Not Available | Not enough data | Not enough data | 

#### Application

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Manual Application Testing** | 9.3 (73 reviews) ✓ Verified | Not enough data | Not enough data | 
| **Static Code Analysis** | 7.6 (60 reviews) | Not enough data | Not enough data | 
| **Black Box Testing** | 9.0 (68 reviews) ✓ Verified | Not enough data | Not enough data | 

#### Agentic AI - Vulnerability Scanner

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Autonomous Task Execution** | 6.3 (5 reviews) | Not enough data | Not enough data | 
| **Proactive Assistance** | Feature Not Available | Not enough data | Not enough data | 

### Continuous Delivery

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.8/10 | 302 |

#### Functionality

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Deployment-Ready Staging** | Not enough data | Not enough data | 9.1 (247 reviews) | 
| **Integration** | Not enough data | Not enough data | 9.2 (255 reviews) | 
| **Extensible** | Not enough data | Not enough data | 8.8 (232 reviews) | 

#### Management

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Processes and Workflow** | Not enough data | Not enough data | 9.1 (245 reviews) | 
| **Reporting** | Not enough data | Not enough data | 8.4 (229 reviews) | 
| **Automation** | Not enough data | Not enough data | 9.0 (251 reviews) | 

#### Agentic AI - Continuous Delivery

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | 9.1 (26 reviews) | 
| **Cross-system Integration** | Not enough data | Not enough data | 8.8 (24 reviews) | 
| **Adaptive Learning** | Not enough data | Not enough data | 8.5 (20 reviews) | 
| **Natural Language Interaction** | Not enough data | Not enough data | 8.6 (23 reviews) | 
| **Proactive Assistance** | Not enough data | Not enough data | 8.8 (23 reviews) | 

### Bug Tracking

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.8/10 | 231 |

#### Bug Reporting

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **User Reports &amp; Feedback** | Not enough data | Not enough data | 8.9 (189 reviews) | 
| **Tester Reports &amp; Feedback** | Not enough data | Not enough data | 8.8 (182 reviews) | 
| **Team Reports &amp; Comments** | Not enough data | Not enough data | 9.0 (188 reviews) | 

#### Bug Monitoring

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Analytics** | Not enough data | Not enough data | 8.4 (181 reviews) | 
| **Bug History** | Not enough data | Not enough data | 8.9 (198 reviews) | 
| **Data Retention** | Not enough data | Not enough data | 9.0 (178 reviews) | 

#### Agentic AI - Bug Tracking

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Adaptive Learning** | Not enough data | Not enough data | 9.0 (18 reviews) | 
| **Natural Language Interaction** | Not enough data | Not enough data | 8.9 (19 reviews) | 
| **Proactive Assistance** | Not enough data | Not enough data | 8.6 (18 reviews) | 

### Software Composition Analysis

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.8/10 | 91 |

#### Functionality - Software Composition Analysis 

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Language Support** | Not enough data | Not enough data | 8.8 (65 reviews) | 
| **Integration** | Not enough data | Not enough data | 9.0 (70 reviews) | 
| **Transparency** | Not enough data | Not enough data | 9.1 (70 reviews) | 

#### Effectiveness - Software Composition Analysis

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Remediation Suggestions** | Not enough data | Not enough data | 8.7 (67 reviews) | 
| **Continuous Monitoring** | Not enough data | Not enough data | 9.0 (70 reviews) | 
| **Thorough Detection** | Not enough data | Not enough data | 8.8 (69 reviews) | 

### DevOps Platforms

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.9/10 | 189 |

#### Management

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Configuration Management** | Not enough data | Not enough data | 8.9 (137 reviews) | 
| **Access Control** | Not enough data | Not enough data | 9.1 (145 reviews) | 
| **Orchestration** | Not enough data | Not enough data | 8.6 (131 reviews) | 

#### Functionality

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Automation** | Not enough data | Not enough data | 8.8 (144 reviews) | 
| **Integrations** | Not enough data | Not enough data | 8.9 (140 reviews) | 
| **Extensibility** | Not enough data | Not enough data | 8.6 (126 reviews) | 

#### Processes

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Pipeline Control** | Not enough data | Not enough data | 8.9 (137 reviews) | 
| **Workflow Visualization** | Not enough data | Not enough data | 8.8 (129 reviews) | 
| **Continuous Deployment** | Not enough data | Not enough data | 9.1 (147 reviews) | 

### Continuous Integration

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.5/10 | 263 |

#### Functionality

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Integrations** | Not enough data | Not enough data | 9.3 (226 reviews) | 
| **Extensibility** | Not enough data | Not enough data | 8.9 (210 reviews) | 
| **Test Customization** | Not enough data | Not enough data | 8.6 (199 reviews) | 

#### Management

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Automation** | Not enough data | Not enough data | 8.9 (219 reviews) | 
| **Processes and Workflow** | Not enough data | Not enough data | 8.9 (216 reviews) | 
| **Reporting** | Not enough data | Not enough data | 8.3 (205 reviews) | 

#### Agentic AI - Continuous Integration

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | 8.3 (25 reviews) | 
| **Cross-system Integration** | Not enough data | Not enough data | 8.7 (28 reviews) | 
| **Adaptive Learning** | Not enough data | Not enough data | 8.5 (24 reviews) | 
| **Natural Language Interaction** | Not enough data | Not enough data | 7.7 (27 reviews) | 
| **Proactive Assistance** | Not enough data | Not enough data | 8.3 (26 reviews) | 

### Secure Code Review

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | 8.6/10 | 214 |

#### Documentation

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Feedback** | Not enough data | Not enough data | 8.7 (180 reviews) | 
| **Prioritization** | Not enough data | Not enough data | 8.7 (170 reviews) | 
| **Remediation Suggestions** | Not enough data | Not enough data | 8.5 (163 reviews) | 

#### Security

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **False Positives** | Not enough data | Not enough data | 8.2 (158 reviews) | 
| **Custom Compliance** | Not enough data | Not enough data | 8.5 (160 reviews) | 
| **Agility** | Not enough data | Not enough data | 9.0 (172 reviews) | 

### Static Code Analysis

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Agentic AI - Static Code Analysis

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Adaptive Learning** | Not enough data | Not enough data | Not enough data | 
| **Natural Language Interaction** | Not enough data | Not enough data | Not enough data | 
| **Proactive Assistance** | Not enough data | Not enough data | Not enough data | 

### AI AppSec Assistants

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Performance - AI AppSec Assistants

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Remediation** | Not enough data | Not enough data | Not enough data | 
| **Real-time Vulnerability Detection** | Not enough data | Not enough data | Not enough data | 
| **Accuracy** | Not enough data | Not enough data | Not enough data | 

#### Integration - AI AppSec Assistants

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Stack Integration** | Not enough data | Not enough data | Not enough data | 
| **Workflow Integration** | Not enough data | Not enough data | Not enough data | 
| **Codebase Contextual Awareness** | Not enough data | Not enough data | Not enough data | 

### Interactive Application Security Testing (IAST)

| Product | Score | Reviews |
|---|---|---|
| **Burp Suite** | N/A | N/A |
| **Checkmarx** | N/A | N/A |
| **GitHub** | N/A | N/A |

#### Agentic AI - Interactive Application Security Testing (IAST)

| Feature | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | Not enough data | 

---
## Categories

**Unique to Burp Suite (3):** [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner), [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast), [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools)

**Unique to Checkmarx (6):** [AI AppSec Assistants](https://www.g2.com/categories/ai-appsec-assistants), [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast), [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast), [Secure Code Review Software](https://www.g2.com/categories/secure-code-review), [Static Code Analysis Tools](https://www.g2.com/categories/static-code-analysis), [Interactive Application Security Testing (IAST) Software](https://www.g2.com/categories/interactive-application-security-testing-iast)

**Unique to GitHub (14):** [DevOps Platforms](https://www.g2.com/categories/devops-platforms), [Software Composition Analysis Tools](https://www.g2.com/categories/software-composition-analysis), [Cloud Infrastructure Automation Software](https://www.g2.com/categories/cloud-infrastructure-automation), [Static Application Security Testing (SAST) Software](https://www.g2.com/categories/static-application-security-testing-sast), [Application Release Orchestration (ARO) Tools](https://www.g2.com/categories/application-release-orchestration), [Version Control Hosting Software](https://www.g2.com/categories/version-control-hosting), [Peer Code Review Software](https://www.g2.com/categories/peer-code-review), [Continuous Delivery Tools](https://www.g2.com/categories/continuous-delivery-tools), [Gaming Tools ](https://www.g2.com/categories/gaming-tools), [Bug Tracking Software](https://www.g2.com/categories/bug-tracking), [Configuration Management Tools](https://www.g2.com/categories/configuration-management), [Continuous Integration Tools](https://www.g2.com/categories/continuous-integration), [Build Automation Software](https://www.g2.com/categories/build-automation), [Secure Code Review Software](https://www.g2.com/categories/secure-code-review)


---
## Reviewer Demographics

### By Company Size

| Segment | Burp Suite | Checkmarx | GitHub | 
|---|---|---|---|
| **Small-Business** | 31.2% | 18.8% | 45.3% | 
| **Mid-Market** | 40.0% | 28.1% | 30.8% | 
| **Enterprise** | 28.8% | 53.1% | 23.9% | 

### By Industry

#### Burp Suite

- **Information Technology and Services:** 28.8%
- **Computer &amp; Network Security:** 27.2%
- **Computer Software:** 15.2%
- **Financial Services:** 4.8%
- **Retail:** 3.2%
- **Electrical/Electronic Manufacturing:** 2.4%
- **Education Management:** 2.4%
- **Telecommunications:** 1.6%
- **Medical Practice:** 1.6%
- **Management Consulting:** 1.6%
- **Other:** 11.2%

#### Checkmarx

- **Computer Software:** 15.6%
- **Information Technology and Services:** 15.6%
- **Banking:** 9.4%
- **Computer &amp; Network Security:** 9.4%
- **Automotive:** 6.3%
- **Investment Banking:** 3.1%
- **Internet:** 3.1%
- **International Trade and Development:** 3.1%
- **Insurance:** 3.1%
- **Legal Services:** 3.1%
- **Other:** 28.1%

#### GitHub

- **Computer Software:** 32.0%
- **Information Technology and Services:** 22.6%
- **Internet:** 6.5%
- **Higher Education:** 3.3%
- **Financial Services:** 3.2%
- **Marketing and Advertising:** 2.5%
- **Education Management:** 2.2%
- **Program Development:** 1.7%
- **Computer &amp; Network Security:** 1.6%
- **Research:** 1.3%
- **Other:** 23.0%

---
## Alternatives

### Alternatives to Burp Suite

- [Intruder](https://www.g2.com/products/intruder/reviews) — 4.8/5 stars (206 reviews)
- [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews) — 4.1/5 stars (105 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews) — 3.8/5 stars (25 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (301 reviews)
- [Detectify](https://www.g2.com/products/detectify/reviews) — 4.5/5 stars (51 reviews)
- [Pentest-Tools.com](https://www.g2.com/products/pentest-tools-com/reviews) — 4.8/5 stars (100 reviews)
- [Tenable Vulnerability Management](https://www.g2.com/products/tenable-vulnerability-management/reviews) — 4.5/5 stars (122 reviews)
- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (890 reviews)
- [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews) — 4.1/5 stars (76 reviews)

### Alternatives to Checkmarx

- [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews) — 3.8/5 stars (25 reviews)
- [SonarQube](https://www.g2.com/products/sonarqube/reviews) — 4.4/5 stars (141 reviews)
- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (890 reviews)
- [HCL AppScan](https://www.g2.com/products/hcl-appscan/reviews) — 4.1/5 stars (76 reviews)
- [Coverity](https://www.g2.com/products/coverity/reviews) — 4.2/5 stars (55 reviews)
- [OpenText Core Application Security](https://www.g2.com/products/opentext-core-application-security/reviews) — 4.1/5 stars (34 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [Snyk](https://www.g2.com/products/snyk/reviews) — 4.5/5 stars (132 reviews)
- [Mend.io](https://www.g2.com/products/mend-io/reviews) — 4.3/5 stars (112 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (301 reviews)

### Alternatives to GitHub

- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (890 reviews)
- [Harness Platform](https://www.g2.com/products/harness-platform/reviews) — 4.6/5 stars (281 reviews)
- [Red Hat Ansible Automation Platform](https://www.g2.com/products/red-hat-ansible-automation-platform/reviews) — 4.6/5 stars (377 reviews)
- [Jenkins](https://www.g2.com/products/jenkins/reviews) — 4.4/5 stars (561 reviews)
- [CircleCI](https://www.g2.com/products/circleci/reviews) — 4.4/5 stars (509 reviews)
- [CloudBees](https://www.g2.com/products/cloudbees/reviews) — 4.4/5 stars (622 reviews)
- [Azure DevOps Server](https://www.g2.com/products/azure-devops-server/reviews) — 4.2/5 stars (198 reviews)
- [Bitbucket](https://www.g2.com/products/bitbucket/reviews) — 4.4/5 stars (1004 reviews)
- [Copado DevOps](https://www.g2.com/products/copado-devops/reviews) — 4.4/5 stars (329 reviews)
- [Gearset DevOps](https://www.g2.com/products/gearset-devops/reviews) — 4.7/5 stars (292 reviews)

---
## Top Discussions

### Burp Suite

- Title: [Is BurpSuite free?](https://www.g2.com/discussions/is-burpsuite-free) — 2 comments
  > **Top comment:** "You can have Burpsuite for free as the community edition however there will be certain features which cannot be used in the community edition. To get full..."
- Title: [How do i intercept network that i am connected to?](https://www.g2.com/discussions/12021-how-do-i-intercept-network-that-i-am-connected-to) — 2 comments, 1 upvote
  > **Top comment:** "Check wether the network ip is accessable with the browser. If yes then you can use the same steps as you are using to intersept web applications."
- Title: [What is Burp Suite Professional?](https://www.g2.com/discussions/what-is-burp-suite-professional) — 1 comment
  > **Top comment:** "Burp Suite professional is a security testing tool.
Security testing professional or penetration testing professional use this tool for find security..."
- Title: [What is BurpSuite used for?](https://www.g2.com/discussions/what-is-burpsuite-used-for) — 1 comment
  > **Top comment:** "To identify vulnerability"
- Title: [You&#39;re go to extenion in Burp?](https://www.g2.com/discussions/you-re-go-to-extenion-in-burp) — 1 comment, 1 upvote
  > **Top comment:** "Intruder, XSSValidator, Sequencer, Encoder, Decoder"

### Checkmarx

- Title: [What is Checkmarx used for?](https://www.g2.com/discussions/what-is-checkmarx-used-for) — 2 comments
  > **Top comment:** "Checkmarx is a static code analysis tool used for SAST (Static application security testing)"
- Title: [What is Checkmarx used for?](https://www.g2.com/discussions/checkmarx-what-is-checkmarx-used-for) — 1 comment, 1 upvote
  > **Top comment:** "Checkmarx is an ultimate tool for Static code scan and analysis through code vulnerability testing, SCA and secret detections. They have a prebuilt engine to..."
- Title: [Which testing method does Checkmarx support?](https://www.g2.com/discussions/which-testing-method-does-checkmarx-support) — 1 comment
  > **Top comment:** "Checkmarx does support all these testing methodologies -Sast, Dast, IAST, SCA "
- Title: [Does Checkmarx support DAST?](https://www.g2.com/discussions/does-checkmarx-support-dast) — 1 comment
  > **Top comment:** "You cannot test DAST Testing using Checkmarx"

### GitHub

- Title: [What is GitHub used for?](https://www.g2.com/discussions/what-is-github-used-for) — 8 comments, 4 upvotes
  > **Top comment:** "- store software source code
- use actions to execute CI / CD and publish artefacts / create releases
- lightweight software project management"
- Title: [What can GitHub be used for?](https://www.g2.com/discussions/what-can-github-be-used-for) — 5 comments
  > **Top comment:** "To have a storage for my main projects."
- Title: [How is GitHub shaping the landscape of collaborative software development and version control?](https://www.g2.com/discussions/how-is-github-shaping-the-landscape-of-collaborative-software-development-and-version-control) — 4 comments
  > **Top comment:** "GitHub provides a platform for developers across the world to collaborate on projects, regardless of their location. It has become a vital tool for..."
- Title: [What does GitHub mean?](https://www.g2.com/discussions/what-does-github-mean) — 2 comments
  > **Top comment:** "pandora of Codes, 
All useful codes developed by coders around the globe are here."
- Title: [How can we make git merge easier to avoid conflicts](https://www.g2.com/discussions/how-can-we-make-git-merge-easier-to-avoid-conflicts) — 1 comment, 1 upvote
  > **Top comment:** "Rebase the brach you want to merge with the branch you are merging into berforehand "

---
**Source:** [G2.com](https://www.g2.com) | [Comparison Page](https://www.g2.com/compare/burp-suite-vs-checkmarx-vs-github)

