# StackHawk vs ZAP by Checkmarx Comparison

| | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Star Rating** | 4.6 out of 5 | 4.7 out of 5 | 
| **Total Reviews** | 68 | 14 | 
| **Largest Market Segment** | Small-Business (45.5% of reviews) | Small-Business (76.9% of reviews) | 
| **Entry Level Price** | $39.00 1 Code Contributor Per Month | Free | 

---
## Top Pros & Cons

### StackHawk

Pros:
- Easy Integrations (4 reviews)
- Customer Support (3 reviews)

Cons:
- Complex Setup (3 reviews)
- High Learning Curve (3 reviews)

### ZAP by Checkmarx

Pros:
- Ease of Use (6 reviews)
- Automation (5 reviews)

Cons:
- False Positives (3 reviews)
- Poor Documentation (2 reviews)

---
## Ratings Comparison
| Rating | StackHawk | ZAP by Checkmarx | 
|---|---|---|
  | **Meets Requirements** | 8.8 (53 reviews) | 9.6 (12 reviews) | 
  | **Ease of Use** | 9.0 (53 reviews) | 9.0 (12 reviews) | 
  | **Ease of Setup** | 8.4 (33 reviews) | Not enough data | 
  | **Ease of Admin** | 8.8 (28 reviews) | Not enough data | 
  | **Quality of Support** | 9.3 (49 reviews) | 8.1 (12 reviews) | 
  | **Has the product been a good partner in doing business?** | 9.1 (25 reviews) | Not enough data | 
  | **Product Direction (% positive)** | 9.4 (42 reviews) | 10.0 (11 reviews) | 

---
## Pricing

### StackHawk

#### Entry-Level Pricing

Plan: Secure

Price: $39.00 1 Code Contributor Per Month

Description: Shift-Left DAST &amp; API Security Testing that runs directly in CI/CD to enable developers to fix critical application and API security vulnerabilities.

Key Features:
- Unlimited scans and environments
- Unlimited applications
- Docker based application security scanner

[Browse all 3 editions](https://www.g2.com/products/stackhawk/pricing)

#### Free Trial

Yes

### ZAP by Checkmarx

#### Entry-Level Pricing

Plan: Open source

Price: Free

Key Features:
- Everything

[Learn more about ZAP by Checkmarx](https://www.g2.com/products/zap-by-checkmarx/reviews)

#### Free Trial

Yes

---
## Features Comparison By Category

### Penetration Testing

| Product | Score | Reviews |
|---|---|---|
| **StackHawk** | 9.2/10 | 12 |
| **ZAP by Checkmarx** | 8.4/10 | 13 |

#### Administration

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **API / Integrations** | 9.2 (12 reviews) | 8.3 (12 reviews) | 
| **Extensibility** | 9.2 (10 reviews) | 8.8 (12 reviews) | 
| **Reporting and Analytics** | 9.3 (12 reviews) | 8.8 (12 reviews) | 

#### Analysis

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Issue Tracking** | 9.2 (11 reviews) | 8.1 (12 reviews) | 
| **Reconnaissance** | 9.0 (10 reviews) | 8.2 (12 reviews) | 
| **Vulnerability Scan** | 9.3 (10 reviews) | 9.4 (12 reviews) | 

#### Testing

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Command-Line Tools** | 9.2 (11 reviews) | 7.6 (12 reviews) | 
| **Manual Testing** | 9.2 (12 reviews) | 7.5 (12 reviews) | 
| **Test Automation** | 9.4 (11 reviews) | 8.6 (12 reviews) | 
| **Performance and Reliability** | 9.2 (11 reviews) | 8.9 (12 reviews) | 

### Dynamic Application Security Testing (DAST)

| Product | Score | Reviews |
|---|---|---|
| **StackHawk** | 8.2/10 | 32 |
| **ZAP by Checkmarx** | N/A | N/A |

#### Administration

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **API / Integrations** | 8.8 (29 reviews) | Not enough data | 
| **Extensibility** | 8.5 (28 reviews) | Not enough data | 

#### Analysis

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Reporting and Analytics** | 8.2 (32 reviews) | Not enough data | 
| **Issue Tracking** | 8.4 (28 reviews) | Not enough data | 
| **Static Code Analysis** | Feature Not Available | Not enough data | 
| **Vulnerability Scan** | 9.0 (31 reviews) | Not enough data | 
| **Code Analysis** | Feature Not Available | Not enough data | 

#### Testing

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Manual Testing** | 7.3 (29 reviews) | Not enough data | 
| **Test Automation** | 8.8 (31 reviews) | Not enough data | 
| **Compliance Testing** | 7.9 (29 reviews) | Not enough data | 
| **Black-Box Scanning** | 8.3 (28 reviews) | Not enough data | 
| **Detection Rate** | 8.1 (31 reviews) | Not enough data | 
| **False Positives** | 7.3 (31 reviews) | Not enough data | 

### Vulnerability Scanner

| Product | Score | Reviews |
|---|---|---|
| **StackHawk** | 8.3/10 | 26 |
| **ZAP by Checkmarx** | N/A | N/A |

#### Performance

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Issue Tracking** | 8.3 (22 reviews) | Not enough data | 
| **Detection Rate** | 8.7 (23 reviews) | Not enough data | 
| **False Positives** | 7.7 (23 reviews) | Not enough data | 
| **Automated Scans** | 8.7 (26 reviews) | Not enough data | 

#### Network

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Compliance Testing** | 8.3 (20 reviews) | Not enough data | 
| **Perimeter Scanning** | Feature Not Available | Not enough data | 
| **Configuration Monitoring** | Feature Not Available | Not enough data | 

#### Application

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Manual Application Testing** | 8.2 (22 reviews) | Not enough data | 
| **Static Code Analysis** | Feature Not Available | Not enough data | 
| **Black Box Testing** | 8.5 (19 reviews) | Not enough data | 

#### Agentic AI - Vulnerability Scanner

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Autonomous Task Execution** | Not enough data | Not enough data | 
| **Proactive Assistance** | Not enough data | Not enough data | 

### API Security

| Product | Score | Reviews |
|---|---|---|
| **StackHawk** | 8.4/10 | 13 |
| **ZAP by Checkmarx** | N/A | N/A |

#### API Management 

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **API Discovery** | 8.5 (11 reviews) | Not enough data | 
| **API Monitoring** | 9.1 (11 reviews) | Not enough data | 
| **Reporting** | 7.9 (12 reviews) | Not enough data | 
| **Change Management** | 8.2 (10 reviews) | Not enough data | 

#### Security Testing

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Compliance Monitoring** | 7.3 (10 reviews) | Not enough data | 
| **API Verification** | 9.2 (11 reviews) | Not enough data | 
| **API Testing** | 8.9 (12 reviews) | Not enough data | 

#### Security Management

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Security and Policy Enforcement** | 8.3 (11 reviews) | Not enough data | 
| **Anomoly Detection** | 7.7 (10 reviews) | Not enough data | 
| **Bot Detection** | 7.3 (10 reviews) | Not enough data | 

### Cloud Security

| Product | Score | Reviews |
|---|---|---|
| **StackHawk** | N/A | N/A |
| **ZAP by Checkmarx** | N/A | N/A |

#### Cloud Visibility

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Data Discovery** | Not enough data | Not enough data | 
| **Cloud Registry** | Not enough data | Not enough data | 
| **Cloud Gap Analytics** | Not enough data | Not enough data | 

#### Security

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Data Security** | Not enough data | Not enough data | 
| **Data loss Prevention** | Not enough data | Not enough data | 
| **Security Auditing** | Not enough data | Not enough data | 

#### Identity

| Feature | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **SSO** | Not enough data | Not enough data | 
| **Governance** | Not enough data | Not enough data | 
| **User Analytics** | Not enough data | Not enough data | 

---
## Categories
**Shared Categories (2):** [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast), [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools)

**Unique to StackHawk (2):** [Vulnerability Scanner Software](https://www.g2.com/categories/vulnerability-scanner), [API Security Tools](https://www.g2.com/categories/api-security)



---
## Reviewer Demographics

### By Company Size

| Segment | StackHawk | ZAP by Checkmarx | 
|---|---|---|
| **Small-Business** | 45.5% | 76.9% | 
| **Mid-Market** | 36.4% | 7.7% | 
| **Enterprise** | 18.2% | 15.4% | 

### By Industry

#### StackHawk

- **Information Technology and Services:** 22.7%
- **Computer Software:** 18.2%
- **Computer &amp; Network Security:** 9.1%
- **Banking:** 4.5%
- **Financial Services:** 4.5%
- **Internet:** 3.0%
- **Education Management:** 3.0%
- **Higher Education:** 3.0%
- **Accounting:** 1.5%
- **Construction:** 1.5%
- **Other:** 28.8%

#### ZAP by Checkmarx

- **Computer &amp; Network Security:** 41.7%
- **Information Technology and Services:** 25.0%
- **Computer Software:** 16.7%
- **Internet:** 8.3%
- **Hospital &amp; Health Care:** 8.3%

---
## Alternatives

### Alternatives to StackHawk

- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (893 reviews)
- [Intruder](https://www.g2.com/products/intruder/reviews) — 4.8/5 stars (206 reviews)
- [Wiz](https://www.g2.com/products/wiz-wiz/reviews) — 4.7/5 stars (795 reviews)
- [Postman](https://www.g2.com/products/postman/reviews) — 4.6/5 stars (1784 reviews)
- [Cloudflare Application Security and Performance](https://www.g2.com/products/cloudflare-application-security-and-performance/reviews) — 4.5/5 stars (601 reviews)
- [Red Hat Ansible Automation Platform](https://www.g2.com/products/red-hat-ansible-automation-platform/reviews) — 4.6/5 stars (377 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (302 reviews)
- [Gearset DevOps](https://www.g2.com/products/gearset-devops/reviews) — 4.7/5 stars (292 reviews)
- [Beagle Security](https://www.g2.com/products/beagle-security/reviews) — 4.7/5 stars (88 reviews)
- [Harness Platform](https://www.g2.com/products/harness-platform/reviews) — 4.6/5 stars (281 reviews)

### Alternatives to ZAP by Checkmarx

- [GitLab](https://www.g2.com/products/gitlab/reviews) — 4.5/5 stars (893 reviews)
- [Tenable Nessus](https://www.g2.com/products/tenable-nessus/reviews) — 4.5/5 stars (302 reviews)
- [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews) — 4.1/5 stars (105 reviews)
- [Intruder](https://www.g2.com/products/intruder/reviews) — 4.8/5 stars (206 reviews)
- [Burp Suite](https://www.g2.com/products/burp-suite/reviews) — 4.8/5 stars (129 reviews)
- [Invicti (formerly Netsparker)](https://www.g2.com/products/invicti-formerly-netsparker/reviews) — 4.6/5 stars (69 reviews)
- [vPenTest](https://www.g2.com/products/vpentest/reviews) — 4.6/5 stars (235 reviews)
- [Astra Pentest](https://www.g2.com/products/astra-pentest/reviews) — 4.6/5 stars (186 reviews)
- [Metasploit](https://www.g2.com/products/metasploit/reviews) — 4.6/5 stars (55 reviews)
- [Cobalt](https://www.g2.com/products/cobalt-io-cobalt/reviews) — 4.5/5 stars (177 reviews)

---
## Top Discussions

### StackHawk

No discussions available for this product.

### ZAP by Checkmarx

No discussions available for this product.

---
**Source:** [G2.com](https://www.g2.com) | [Comparison Page](https://www.g2.com/compare/stackhawk-vs-zap-by-checkmarx)

