
the IAST and the flow map part to trigger seurity bugs Review collected by and hosted on G2.com.
To add a taint analysis and solution for route coverage Review collected by and hosted on G2.com.

the IAST and the flow map part to trigger seurity bugs Review collected by and hosted on G2.com.
To add a taint analysis and solution for route coverage Review collected by and hosted on G2.com.
easy integration
the support is very responsive Review collected by and hosted on G2.com.
false positives
support in ruby/scala isnt the best
getting logs is a bit annoying Review collected by and hosted on G2.com.

All the security features which makes me more productive. Review collected by and hosted on G2.com.
It sometimes makes the system very slow but that is ok. Review collected by and hosted on G2.com.

It's free to some extent
Fast then most security scanners Review collected by and hosted on G2.com.
Nothing other than the learning and usage curve Review collected by and hosted on G2.com.

The tool is straightforward to use; alerts and errors do not overpower developers during the Coding phase. The experience of Security Analyst, Developer, and Management is very positive.
The reports against Standards (OWASP Top 10 and PCI) are very convenient for audits allowing for better efficiency. Review collected by and hosted on G2.com.
I have not been able to identify a feature that does not help the organization achieve the results aimed when implementing the solution. The features on the roadmap, along with the ones already in place, offer a complete suite that leaves no room for disliking. Review collected by and hosted on G2.com.
Simple UI with solid IAST & SCA scans built into Contrast Assess/OSS product. Review collected by and hosted on G2.com.
Less robust features for .NET-based workloads: Azure functions/serverless not available (only app services), Azure DevOps integrations work but are not intensive, Contrast support are generally less-knowledgeable on .NET environments (optimized for Java & AWS environments). Review collected by and hosted on G2.com.
The tool helps find high-quality security vulnerabilities at the speed of DevOps. "Fail fast, fail often" at the requirement of daily changes to the application landscape. Traditional SAST and DAST tools struggle to keep up with the rate of change and cause more noise than acceptable. Contrast Security helped us reach our goal of coverage without the hassle of the terrible signal-to-noise ratio common to other application security tools. Review collected by and hosted on G2.com.
The main struggle that is inherit with this style of tool is the agent. However, it's unclear how you could have the best of both worlds without it. Review collected by and hosted on G2.com.
I like the proprietary way in which it scans for vulnerabilities compared to some of the traditional application scanning tools we use/used. Noise is the number one issue we hear from our engineers, and Contrast is really good at reducing the noise and focusing on actual vulnerabilities. The team we have been working with at Contrast has also been very helpful and responsive. It comes with a really good reporting solution out of the box, even though we use our own vulnerability aggregation solution. Review collected by and hosted on G2.com.
The biggest thing we are dealing with on Contrast is code coverage. We currently his a much smaller code coverage than what you would see with a traditional SAST or SA scanning solution. We need to figure out a better way to increase that coverage to reduce the amount of risk that we are trying to employ with these new security test methods. Review collected by and hosted on G2.com.
-Technology used to detect the vulnerabilities, the way it's presented along with complete tracing, guidance for teams to learn about the vulnerability and associated risk are plus.
-Another great advantage is giving visibility into route coverage which helps to identify the route's that not exercised or having high number of vulnerabilities, but please note that it's not supported for all Java frameworks.
-Ease of implementation, works great for both SDLC/DevOps model. Review collected by and hosted on G2.com.
- Log collection could be improved, for any troubleshooting/debugging require coordination with application teams to set required configuration to collected required logs. Heard that they are changing this approach, looking forward to same.
- Integration with systems like JIRA and other ticketing systems have issues. Again in roadmap to fix.
- Some of the updates require configuration change at the app end, which is hard to implement as it requires coordination with app teams - very hard to adopt to new enhancements.
- Technical support could be improved, slowly seeing the quality of support going down.
- For certain frameworks and app servers, vulnerabilities within commercial app server/framework is getting reported - kind of mess if it's one of the unsupported framework. Review collected by and hosted on G2.com.
As an administrator, the tool being saas, I do not have to worry about the server and I just need to take care of the agents. Installation is easy and the configuration is not much harder. The documentation is well written and you will usually find what you need. For the maintenance, on some machines, I periodically update the agent, which is as simple as executing the installer. In the CI build, with docker image, I always fetch the latest version.
For the developer, they get a warning in our security slack channel when something in their code needs to be "improved".
Support has always been stellar when I needed them for clarification. Review collected by and hosted on G2.com.
There is nothing I dislike about that tool. It does the job we bought it for, in the background, with minimal maintenance. Review collected by and hosted on G2.com.