---
title: SQLmap Reviews
meta_title: 'SQLmap Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 38 reviews by the users' company size, role or industry to
  find out how SQLmap works for a business like yours.
aggregate_rating:
  rating_value: 4.3
  review_count: 38
  scale: '5'
date_modified: '2026-07-12'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---

# SQLmap Reviews
**Vendor:** SQLmap  
**Category:** [Penetration Testing Tools](https://www.g2.com/categories/penetration-testing-tools)  
**Average Rating:** 4.3/5.0  
**Total Reviews:** 38
## About SQLmap
Automatic SQL injection and database takeover tool




## SQLmap Reviews
  ### 1. Helps developers

**Rating:** 5.0/5.0 stars

**Reviewed by:** SHASHIDHAR KUDARI . | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 24, 2023

**What do you like best about SQLmap?**

Many of the developers don't do penetration testing while developing the API and this tool can help all of them including me

**What do you dislike about SQLmap?**

I think they are providing it only for SQL db, but it might be helpful if they do it for nosql dbs also

**What problems is SQLmap solving and how is that benefiting you?**

Can detect the security bugs earlier with this toool

  ### 2. A single masterpiece for hunting and automating sql injection

**Rating:** 5.0/5.0 stars

**Reviewed by:** Atul T. | security evangelist , Small-Business (50 or fewer emp.)

**Reviewed Date:** May 19, 2023

**What do you like best about SQLmap?**

Its automation in finding and dumping database.

**What do you dislike about SQLmap?**

Sometimes we need to give more details about db

**What problems is SQLmap solving and how is that benefiting you?**

I use it always in pentesting engagement to automate the hunting amd finding sql injection vulnerabilities.

  ### 3. Sqlmap is an open-source tool. It's a really good tool for SQLi, simple and useful.

**Rating:** 5.0/5.0 stars

**Reviewed by:** Udesh B. | Assistant Engineer - Information Security , Small-Business (50 or fewer emp.)

**Reviewed Date:** January 14, 2021

**What do you like best about SQLmap?**

It can automatically detect and use the SQL injection vulnerability database and the access server. It has a very powerful detection engine, has a penetration tester variety of characteristics, accesses to the underlying file system to extract the fingerprint database connection and execute commands that take away

**What do you dislike about SQLmap?**

Difficulty in Interfacing, Having a good user interface (GUI) will help relate better with users.

**What problems is SQLmap solving and how is that benefiting you?**

it helps to retrieve large amounts of records from a database quickly and efficiently. Once it detects one or more SQL injections on the target host, the user can choose to perform an extensive back-end database management system fingerprinting, retrieve DBMS session user and database, enumerate users, password hashes, privileges, databases, dump entire or user's specific DBMS tables/columns. Also, anyone can bypass WAF protection easily by using tamper scripts.

  ### 4. Useful tool if you are working in Cyber Security Industry

**Rating:** 5.0/5.0 stars

**Reviewed by:** Bawantha C. | Penetration Tester, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 28, 2021

**What do you like best about SQLmap?**

Easy to use and Very fast when considering other SQL injection tools , Has lot of new and valuable SQL injection methods that are not practical to test manually

**What do you dislike about SQLmap?**

Even though the application is pretty fast considering the other software's in the market sometimes it tend to miss out on some more complex attacks

**What problems is SQLmap solving and how is that benefiting you?**

Testing SQL injection points on Clients Web Applications

  ### 5. Amazing Database Vulnerability Scanning and a Take Over Tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Isuru S. | Security Consultant, Mid-Market (51-1000 emp.)

**Reviewed Date:** December 03, 2019

**What do you like best about SQLmap?**

Its automated process of database vulnerability detection and takeover. SQLmap is not only used for direct database scanning, but also used against web applications to identify potential SQL vulnerabilities in programming and etc. Its uses include vulnerability scanning and assessment of security, analysis of web applications and, mainly, penetration testing and database takeover.

**What do you dislike about SQLmap?**

It generates a good amount of false positives. We have to manually check whether a detected vulnerability exists and then verify it. Still considering its detailed output structure and ease of use this is not that much of a problem because if you are using it, then the chances are that you are already a security professional who is capable of manually verifying the detected vulnerability.

**Recommendations to others considering SQLmap:**

If you are security professional conducting VAPT for either your own company products or for clients or else even if you just an IT guy needing to check the base security levels of the application, I recommend you use this tool. Its free to use with no additional effort and can be learnt easily through countless tutorial and comprehensive documentation available as both article/documentation and video based deliverables.

**What problems is SQLmap solving and how is that benefiting you?**

We conduct VAPT as a service to clients. In this business it is good to have automated tools for testing rather than having to manually try countless methods and vulnerabilities. For SQL injection and database takeover via detecting SQL vulnerabilities (parameter or configuration), SQLmap proved to be one of the best tools in existence.

  ### 6. Best Automated SQL Injection Vulnerability Scanner

**Rating:** 5.0/5.0 stars

**Reviewed by:** Keshani B. | Intern, Enterprise (> 1000 emp.)

**Reviewed Date:** December 10, 2019

**What do you like best about SQLmap?**

Its ability to thoroughly scan a web application to find SQL injection vulnerabilities and automatically exploit a detected vulnerability to take over the database. SQLmap is provided preinstalled in Kali Linux and is an essential tool to any professional security tester. When given an URL, it automatically executes a thorough SQL injection scan and if possible extract the entirety of database details and DB user details. These enumerated DB information include databases, roles, privileges, users, tables and their columns and can even get hash values of passwords. It even has the ability to bypass firewalls (WAF) employing tamper scripts.

**What do you dislike about SQLmap?**

Nothing of significance. As with any other vulnerability scanner, SQLmap also gives false positives and the tester must manually check and confirm whether a detected vulnerability exists in the target.

**Recommendations to others considering SQLmap:**

If you are a security professional in the IT field looking for SQL vulnerabilities in systems or even just a developer with the need to secure an application, this is the best tool for that. It automates the scanning process and the exploitation process and it supports a wide variety of DBMSs so that you won't have to look for a another tool just scan a specific alienated DBMS. SQLmap supports a variety of injection procedures and even supports to deploy dictionary attacks against hashed passwords. It comes already installed in Kali Linux distribution and it does not hurt that SQLmap is free of any charge.

**What problems is SQLmap solving and how is that benefiting you?**

For sometime, we were in need of a tool which can automate the process of finding SQL vulnerabilities in web applications. It was our requirement that the tool should support at least the major Database Management Systems in existence while providing the minimum number of false positives possible. These requirements were fulfilled by SQLmap to the best extent possible. It supports DBMSs such as Microsoft SQL Server as well as Microsoft Access, MySQL, PostgreSQL, Oracle, SQLite, Sybase and many others.

  ### 7. Best Automated SQL Vulnerability Scanner

**Rating:** 5.0/5.0 stars

**Reviewed by:** Isuru S. | Intern, Enterprise (> 1000 emp.)

**Reviewed Date:** December 07, 2019

**What do you like best about SQLmap?**

Everything about it. It is an amazing and a powerful automated engine for detecting SQL Injection vulnerabilities and, if possible, for database takeover. We can customize its commands to target a specific outcome. Since it is open-source., it is free of cost and has a massive online community of user who can guide you on any sort of problem that arises along the way. Due to its thorough testing of all possible DB vulnerabilities, any penetration tester can easily can conduct DB testing without much to worry about.

**What do you dislike about SQLmap?**

One is that it does not have a graphical user interface. It may prove to be a little bit difficult, than it actually is, to some users because of this. Still, even with the command line interface, the learning curve is so small with all the help and tutorials available online. Another thing to dislike is its generation of false positive vulnerability findings. Even though this is true with any sort of vulnerability scanning software, still if the number of false positives can be limited to a minimum, SQLmap would be more impressive. In any case, the tester needs to double check the reported vulnerability by manually testing it.

**Recommendations to others considering SQLmap:**

If you are penetration tester and still is not using SQLmap, trust me, you are missing out on a lot. SQLmap is a must have tool in every penetration testers arsenal. It is open-source and freely available, hence no involvement of huge fees to buy tools that does not give expected outputs. It is easily understood and has a large user community, so you can get started right away without much hassle. And it comes already installed in Kali Linux distribution, which if you are a penetration tester may be already using. Give it a try and you will be amazed with what it can do.

**What problems is SQLmap solving and how is that benefiting you?**

For some time we were struggling with manually testing each possible DB vulnerabilities in web applications when we get an assignment such as web application penetration testing. But soon found out about SQLmap which automates the whole process. Even though we still have to manually verify the vulnerabilities it finds, still SQLmap saved a lot of time by automating all possible vulnerability scenarios and injections.

  ### 8. Best tool for sql injection tests.

**Rating:** 4.5/5.0 stars

**Reviewed by:** Medhavi W. | Information Security Analyst, Enterprise (> 1000 emp.)

**Reviewed Date:** June 30, 2019

**What do you like best about SQLmap?**

SQL map support for different kind of sql injections such as os injections, command injections and many more. sql map based on the python and it comes free with the Kali or you can download the repository from the internet and able to use in a linux based environment. most of the vulnerable sql injection vulnerabilities can able to exploit using this tool and this is an essential tool for penetration testings.

**What do you dislike about SQLmap?**

SQL map is a command line tool and does not have any graphical user interface we need to memorize all the commands and it is a tool really hard to use and need and advanced knowledge about this tool for use it.

**What problems is SQLmap solving and how is that benefiting you?**

I use SQL map to perform web application security testings and find vulnerable products to sql injections.

  ### 9. Best tool for sql injection

**Rating:** 5.0/5.0 stars

**Reviewed by:** chalaka Z. | Assistant lecturer, Mid-Market (51-1000 emp.)

**Reviewed Date:** July 31, 2019

**What do you like best about SQLmap?**

SQLmap automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It has a powerful detection engine. numerous specialty highlights for an ultimate penetration tester and an expansive scope of changes enduring from database fingerprinting, over information bringing from the database to getting to the file system and executing commands on the OS by via out-of-band connections.

**What do you dislike about SQLmap?**

There is nothing dislike anything about this if there is GUI for SQLmap could be more useful.

**Recommendations to others considering SQLmap:**

recommend to everyone, easy use tool.

**What problems is SQLmap solving and how is that benefiting you?**

Used to detect SQL vulnerabilities
open-source and free tool

  ### 10. SQLmap is the best tool to test database security

**Rating:** 4.5/5.0 stars

**Reviewed by:** Sarah C. | Op-Ed Columnist, Newspapers, Mid-Market (51-1000 emp.)

**Reviewed Date:** August 17, 2019

**What do you like best about SQLmap?**

The best tool for testing databases to find SQL Injection vulnerabilities.

The best tool for detecting SQL vulnerabilities as a free and open source.

**What do you dislike about SQLmap?**

These are not even detailed about this SQL mapping... It works great

**Recommendations to others considering SQLmap:**

I wouldn't recommend this SQLMap tool to every pentester to easily automatically identify vulnerabilities in minutes.

**What problems is SQLmap solving and how is that benefiting you?**

The best tool to test database security.

It is best to test the SQL database using parametric tests.

This is an open source and free

  ### 11. SQL Injection and Penetration Testing SQLMap is your tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Media Production | Enterprise (> 1000 emp.)

**Reviewed Date:** February 24, 2019

**What do you like best about SQLmap?**

Ease of installation and usage. Examples and use cases. Test cases, high volume of forums and helps. Free of cost. The tutorials are easy to find and very extensive and cover all use case. So any developer or tester who does not know database can easily learn and start database testing.

**What do you dislike about SQLmap?**

Nothing so far, all features at this no price is very good. The learning curve for a new developer / tester is so smooth and easy that its the best tool in the market. And as you should know its an opensource tool hence free of cost.

**Recommendations to others considering SQLmap:**

Install it, try it think like a hacker test the use case and even the manual / automated testers can add this tool in their testing world and use it easily for a safe and secure application.

**What problems is SQLmap solving and how is that benefiting you?**

SQL injection is one of the basic yet most critical vulnerability in this data centric world. So to test each and every query and putting dedicated resource is not worth when automated tools are available. So, this led our business to opt for SQLMap as the automated penetration testing tool. The benefits were ease of installation and easy tutorial for anyone to learn. The cost was low and was compatible both on windows developer machine and unix based servers.

  ### 12. Project Accountant 

**Rating:** 5.0/5.0 stars

**Reviewed by:** Salani E. | Account Manager, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 31, 2019

**What do you like best about SQLmap?**

The best thing that I like about this software is that it will give the visual benefit of analyzing the results and the interrelation with the tables. This will allow me to understand the primary and foreign key an the interrelationship between two. I personally believe that all the 

**What do you dislike about SQLmap?**

The things that I don't dislike about this is sometimes the relationship between the tables confuse me. And I feel like we need more technical knowledge to understand that. 

**Recommendations to others considering SQLmap:**

As any other software learn all the features and things that you can do using SQL. and follow some you tube videos available for free to get a better understanding about this. Get a specialist service and this one time cost will be a good investment for sure. 

**What problems is SQLmap solving and how is that benefiting you?**

- Program mapping
-Contractors information mapping 
-Injecting information to for the company record. 

  ### 13. SQLmap the best tool to exploit SQLi

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Information Technology and Services | Small-Business (50 or fewer emp.)

**Reviewed Date:** June 15, 2019

**What do you like best about SQLmap?**

Advanced options to specify the type of SQLi and place for injection. There are multiple options to set risk/level, specify method (technique) and other things like encoding and so on.

**What do you dislike about SQLmap?**

GUI which is missing :/ Command line interface is pretty old. Actually, best thing to do, is integrate SQLmap with BurpSuite to help automate process of choosing requests.

**Recommendations to others considering SQLmap:**

sqlmap.py -h :)

**What problems is SQLmap solving and how is that benefiting you?**

SQLmap has helped me to exploit many BLIND SQLi.

  ### 14. SQLmap is the best  tool to test the security of the database

**Rating:** 5.0/5.0 stars

**Reviewed by:** Chaitanya T. | Chief Technology Officer, Small-Business (50 or fewer emp.)

**Reviewed Date:** January 28, 2019

**What do you like best about SQLmap?**

Best Tool for testing the database for finding the sql injection vulnerabilities.
Best tool available as Free and open source to detect SQL Vulnerabilities. 

**What do you dislike about SQLmap?**

These is not even a single con about this SQL Map... Its works great

**Recommendations to others considering SQLmap:**

I won't recommend this SQLMap tool to every pentester to automate and identify the vulnerabilities with ease within minutes.

**What problems is SQLmap solving and how is that benefiting you?**

Best tool to test the security of the Database. 
Best for testing the SQL Data base using Parameter Testing . 
It is a open source and free 

  ### 15. SQLmap is the best testing tool

**Rating:** 4.5/5.0 stars

**Reviewed by:** Santosh R. | DEVELOPER, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 20, 2019

**What do you like best about SQLmap?**

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of the database server. Full support for MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, and H2 database management systems. Automatic recognition of password hash formats .search for specific database names, specific tables across all databases or specific columns across all databases' tables

**What do you dislike about SQLmap?**

SQLmap is a full command line tool .graphical user interface not perfect .no exist sufficient documentation

**Recommendations to others considering SQLmap:**

SQLmap is a great free open source tool. The best tool for testing the security of the Database.

**What problems is SQLmap solving and how is that benefiting you?**

SQLmap is open source and free tool.there is no user-friendly interface

  ### 16. Bst Database Penetration Testing tool

**Rating:** 4.5/5.0 stars

**Reviewed by:** Verified User in Computer & Network Security | Mid-Market (51-1000 emp.)

**Reviewed Date:** January 23, 2019

**What do you like best about SQLmap?**

SQL map work with all SQL, MSSQL and Oracle databases, this tool is great tool for take database dumps and  access databases through privileged escalations using SQL injection commands using the SQLmap commands. it is very powerful tool for automate the sql injections for penetrate web servers and database servers using SQLmap. customized python scripts can be used for automate these tasks fast and easily and also SQLmap is a free and open source tool integrated with kali linux so any one can use it without additional cost and if anyone want more features there is a pro version as well for purchase depend on your requirements.

**What do you dislike about SQLmap?**

SQLmap is a full command line tool and doesn't have proper Graphical user interface tool if there graphical user interface tool it will be lot more easy for use than the command line interface.

**Recommendations to others considering SQLmap:**

SQLmap is great free open source tool that every one can use without additional cost, mostly SQLmap inbuilt with Kali Linux, and if you want to install SQLmap to other than Linux platform that would be possible in this product.

**What problems is SQLmap solving and how is that benefiting you?**

SQLmap is opensource tool and doesn't have much support from specific vendor
there is no user friendly interface and all depends on the command line interface. 

  ### 17. Free,  fast nad accurate

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 20, 2019

**What do you like best about SQLmap?**

Sqlmap is an open source tool which can be downloaded from any secure website. 
Its one of the best tool to exploit any sql injection in your code. It gives you a full control over a database by testing the security of it. It helps to keep multiple databases in sync.  You can access any database and its tables; can view, edit or delete the data in the tables. Its a 'must have' tool.  Many security professionals use this tool. 

**What do you dislike about SQLmap?**

This tool can be used for illegal purposes. Hackers can get into the database, if not secured, and can get all the confidential data. 

**What problems is SQLmap solving and how is that benefiting you?**

It helps me to test my web application code and for syncing my databases. 

  ### 18. Quite Interesting

**Rating:** 4.5/5.0 stars

**Reviewed by:** Nikki G. | Nikki, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 22, 2019

**What do you like best about SQLmap?**

It helped me for testing SQL injection on a dummy website

**What do you dislike about SQLmap?**

I don't dislike anything about the SQL MAP

**Recommendations to others considering SQLmap:**

Absolutely esp people who want to become security experts

**What problems is SQLmap solving and how is that benefiting you?**

It helps detecting the vulnerabilities in websites to make them more securer

  ### 19. SQLmap makes finding SQL injection points easy

**Rating:** 4.5/5.0 stars

**Reviewed by:** Matt B. | Security Engineer, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 07, 2019

**What do you like best about SQLmap?**

SQLmap is easy to get started in, and doesn't require an expert level user to test sites. The software has a built-in wizard option, which can walk novice users through the process without losing capability, and as familiarity with the product increases, allows further advancement without a terrible learning curve.

**What do you dislike about SQLmap?**

Some reports can become cumbersome and hard to parse in the command line interface.

**What problems is SQLmap solving and how is that benefiting you?**

SQLmap gives us the ability to easily and quickly spin through a broad spectrum of tests which would be difficult if not impossible to accomplish manually.

  ### 20. Best Penetration Tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** Verified User in Chemicals | Small-Business (50 or fewer emp.)

**Reviewed Date:** May 31, 2019

**What do you like best about SQLmap?**

User friendly tool and can become very advanced

**What do you dislike about SQLmap?**

It can be used by script kiddies. Anyone can become hacker

**Recommendations to others considering SQLmap:**

Read carefully the manual and become expert... Do tones of tests.

**What problems is SQLmap solving and how is that benefiting you?**

You can exploit vulnerabilities and get specific proof of concepts 


## SQLmap Discussions
  - [what are the similar tools which you use to get more results](https://www.g2.com/discussions/12220-what-are-the-similar-tools-which-you-use-to-get-more-results) - 1 comment, 1 upvote

- [View SQLmap pricing details and edition comparison](https://www.g2.com/products/sqlmap/reviews?filters%5Bnps_score%5D%5B%5D=5&section=pricing&secure%5Bexpires_at%5D=2026-08-02+19%3A35%3A50+-0500&secure%5Bsession_id%5D=fecda5be-bae0-4622-a804-954c2a57a111&secure%5Btoken%5D=962f31d81e5c4196f4bf21eda9a6c312a4e9920ebd3b6d425dd80266127687d7&format=llm_user)

## SQLmap Features
**Administration**
- API / Integrations
- Extensibility
- Reporting and Analytics

**Analysis**
- Issue Tracking
- Reconnaissance
- Vulnerability Scan

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Performance and Reliability

## Top SQLmap Alternatives
  - [Burp Suite](https://www.g2.com/products/burp-suite/reviews) - 4.8/5.0 (126 reviews)
  - [Metasploit](https://www.g2.com/products/metasploit/reviews) - 4.6/5.0 (53 reviews)
  - [Acunetix by Invicti](https://www.g2.com/products/acunetix-by-invicti/reviews) - 4.1/5.0 (100 reviews)

