---
title: StackHawk Reviews
meta_title: 'StackHawk Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 68 reviews by the users' company size, role or industry to
  find out how StackHawk works for a business like yours.
aggregate_rating:
  rating_value: 4.6
  review_count: 68
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---


# StackHawk Reviews
**Vendor:** StackHawk  
**Category:** [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast)  
**Average Rating:** 4.6/5.0  
**Total Reviews:** 68
## About StackHawk
StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.



## StackHawk Pros & Cons
**What users like:**

- Users value the **easy integrations** of StackHawk, enhancing CI/CD pipelines and streamlining the onboarding process. (4 reviews)
- Users commend StackHawk for its **exceptional customer support** , providing expert assistance and enhancing the overall user experience. (3 reviews)
- Users value the **customizability** of StackHawk, appreciating its flexibility and integration options for unique workflows. (3 reviews)
- Users find that StackHawk greatly enhances **efficiency** , enabling quicker identification and resolution of security vulnerabilities. (3 reviews)
- Users value the **scanning efficiency** of StackHawk, enabling faster and more effective security scanning processes. (3 reviews)
- User Interface (3 reviews)
- Affordable Pricing (2 reviews)
- Users commend StackHawk for its **automated scanning** , enabling quick and efficient identification of security vulnerabilities. (2 reviews)
- Automation Testing (2 reviews)
- CD Integration (2 reviews)

**What users dislike:**

- Users find the **complex setup** process frustrating due to the lack of simplified documentation and time-consuming configurations. (3 reviews)
- Users face a **high learning curve** with StackHawk due to its complex setup and scripting requirements. (3 reviews)
- Users find StackHawk **lacking features** , especially in API management and intuitive setup, hindering vulnerability management. (3 reviews)
- Users note the **limited scope** of StackHawk, particularly regarding on-prem usage and automation capabilities. (3 reviews)
- Users find **setup complexity** frustrating, as extensive YAML config trials are necessary for effective onboarding and scans. (3 reviews)
- Difficult Customization (2 reviews)
- False Positives (2 reviews)
- Inadequate Remediation (2 reviews)
- Users find **inadequate reporting** frustrating, wishing for better dashboards and automated sharing of vulnerability progress. (2 reviews)
- Lack of Detail (2 reviews)

## StackHawk Reviews
  ### 1. Stachawk efficiently processed the data, providing insightful analytics and reports.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Higher Education | Small-Business (50 or fewer emp.)

**Reviewed Date:** April 03, 2025

**What do you like best about StackHawk?**

Stachawk efficiently performed a comprehensive security assessment, identifying potential issues such as SQL injection, XSS, and security misconfigurations. The detailed reports provided clear insights into each vulnerability, along with recommendations for remediation.

Another key feature was its ability to adapt to different environments, making it a versatile solution for both black-box and white-box testing scenarios.

**What do you dislike about StackHawk?**

A learning path should be added to help users maximize the potential of Stachawk. While the tool is powerful and intuitive, a structured learning path would provide step-by-step guidance on configuring scans, interpreting results, and implementing security best practices.

**What problems is StackHawk solving and how is that benefiting you?**

Stachawk addresses the need for a DAST scanner that supports ethical hacking, enables early vulnerability detection, and enhances secure development practices. By automating security assessments, it allows cybersecurity professionals and development teams to identify weaknesses in web applications before they can be exploited. Its capabilities facilitate proactive security testing, helping organizations integrate security into their SDLC (Software Development Life Cycle) and adopt a shift-left approach. With Stachawk, teams can strengthen their security posture while ensuring compliance with industry standards and best practices.

  ### 2. DEV's Found It Easy To Integrate.   INFOSEC Gets The DevSecOps View/Reporting

**Rating:** 4.0/5.0 stars

**Reviewed by:** Michael O. | Director of Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** October 28, 2024

**What do you like best about StackHawk?**

The dev team found it fairl simple to get their codebase/apps (Python, BitBucket, Jenkins, Jira) integrated...  we had a volunteer who went through the process & provide steps so the rest could cookie-cutter it.

**What do you dislike about StackHawk?**

I am not a coder - I'm on the InfoSec side of the house.    So my take about SH relates to the admin portal & reporting... both of which of very good.    It was easy to invite devs to the portal & the reports provide info that I use to relay for compliance/security work.

**What problems is StackHawk solving and how is that benefiting you?**

It does a few things for us:

1.  Adds a DAST function that automates discovery of vulns.  Previously done by humans - not ideal.
2. Help us to create a DevSecOps culture.   We are pairing this with Snyk to have a soup-to-nuts CI/CD analysis.
3. Both 1&2 help us meet GRC requirements.   Code-development has become a focus for more than a few compliance/privacy rules.

  ### 3. StackHawk - An upcoming DAST solution

**Rating:** 4.0/5.0 stars

**Reviewed by:** Shivani Santosh K. | Associate Security Specialist, Mid-Market (51-1000 emp.)

**Reviewed Date:** November 21, 2024

**What do you like best about StackHawk?**

Its configurable nature and diverse integration option. And the very supportive customer support team who value the feedback and make sure changes are reflected in upcoming releases.

**What do you dislike about StackHawk?**

The limitation of being able to use with only internet accessible surface and limitation on on-prem usage. Additionally, lack of granular roles to avoid accendential deletion of scan and scan result by a unaware user.

**What problems is StackHawk solving and how is that benefiting you?**

Helping us streamline our secure development initiative

  ### 4. Review

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Mid-Market (51-1000 emp.)

**Reviewed Date:** February 18, 2025

**What do you like best about StackHawk?**

Its scanning capabilities and easy integration into our CI/CD pipelines

**What do you dislike about StackHawk?**

Simplified documentation for the yml specs. I have to search all over and go through a ton of trial and error when it comes time to setup configurations for stackhawk.

**What problems is StackHawk solving and how is that benefiting you?**

We needed DAST and it provides that to us

  ### 5. Great SaaS-first DAST product

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Insurance | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 08, 2023

**What do you like best about StackHawk?**

StackHawk was built with a SaaS first mindset, unlike many of the competing products in the space, which made it a perfect fit for our needs. It has just the right number of features and does what it does very well.

We've been able to automate much of our interaction with the product through the robust APIs provided out of the box. Integrations are easy and straight forward. As a result, we're able to scan our products for vulnerabilities on every build as well as via continuous scanning from our CI/CD tooling.

I love the Slack-based customer support. As an early customer, we've been able to participate in beta and even pre-release design and have a great relationship with the StackHawk team.

**What do you dislike about StackHawk?**

We've struggled with some of our larger APIs not completing scans in a timely manner. The StackHawk support team has been great about helping us solve for it.

**What problems is StackHawk solving and how is that benefiting you?**

We've shifted our security to the left and StackHawk helped us do that in an easy, automated way. We're able to scan our internet-facing solutions early and often to ensure we're not introducing vulnerabilities in our products.

  ### 6. Overall a decent front end to ZAP scanning

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Financial Services | Enterprise (> 1000 emp.)

**Reviewed Date:** November 08, 2023

**What do you like best about StackHawk?**

Relatively easy to use once initial setup is done. Easy to add in automation. Decent interface. Customer support was very helpful.

**What do you dislike about StackHawk?**

Not quite intuitive setup, so a bit of a learning curve. Hard to manage vulnerabilities from a perspective of seeing how to manually reproduce and also to mark as false positive. No ability to mark application types and have custom severity on certain vulns based on that. eg XSS in website is more serious than in a json api.

**What problems is StackHawk solving and how is that benefiting you?**

We needed to scan our APIs daily to pick up any low hanging fruit and make sure it gets remediated immediately

  ### 7. Stackhawk has been a great tool to implement inside of our CI/CD pipeline for DAST scanning.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Lake S. | Mid-Market (51-1000 emp.)

**Reviewed Date:** November 08, 2023

**What do you like best about StackHawk?**

The flexability of delpoyment is great when deploying rapidly.

**What do you dislike about StackHawk?**

There is not much training offered to get started with the tool.

**What problems is StackHawk solving and how is that benefiting you?**

It is solving our need to actively scan our in house developed applications and microservices.

  ### 8. Quick Scan

**Rating:** 4.0/5.0 stars

**Reviewed by:** MRIDUL N. | Individual contributor, Higher Education, Small-Business (50 or fewer emp.)

**Reviewed Date:** June 23, 2023

**What do you like best about StackHawk?**

I like that it is fast and dynamic, and I can also automate things.

**What do you dislike about StackHawk?**

Troubleshooting network-related issues is a hectic process

**What problems is StackHawk solving and how is that benefiting you?**

I use it for my web application scanning. It helps me find bugs in code that improves my application security.

  ### 9. Good to have, in case it finds something in the future, but don't expect miracles

**Rating:** 3.5/5.0 stars

**Reviewed by:** Verified User in Retail | Mid-Market (51-1000 emp.)

**Reviewed Date:** July 20, 2023

**What do you like best about StackHawk?**

Can find the most common vulnerabilities in common web applications. Easy to use and nice UI.

**What do you dislike about StackHawk?**

It comes nowhere near close to a real pen-testing, and it doesn't find many vulnerabilities in GraphQL.

**What problems is StackHawk solving and how is that benefiting you?**

Having a DAST tool.

**Official Response from Nicole Jones:**

> Thanks for your review!

GraphQL scanning can be tricky. If you were not able to find many vulnerabilities in GraphQL, I recommend adding custom variables to your configuration. Using custom values allows you to scan operations that can potentially access real data and exercise more branches of your application’s code than default static values that may not exist in the context of your application.

An alternative solution is to generate smart values with the Java Faker library instead of providing your own. HawkScan will use the Faker library to generate smarter values when the proper information is supplied in the GraphQL schema.

  ### 10. StackHawk proves to be an interesting tool in secure development pipelines

**Rating:** 4.0/5.0 stars

**Reviewed by:** Jonatas W. | Cloud Security Analyst, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 12, 2022

**What do you like best about StackHawk?**

I like the ease of onboarding new applications. It is easy and practical, facilitating the user experience of security in the application development cycle. Additionally, the application utilizes native API development configurations through OpenAPI files.

**What do you dislike about StackHawk?**

It still seems too simplistic for the level expected in corporate environments. There is a lack of a way to manage multiple projects, but I believe it will be implemented in future releases.

**What problems is StackHawk solving and how is that benefiting you?**

I am implementing DAST analysis using the free tier, and this allows me to make my open-source environment more secure. The main feature is the automation of security tests directly in the CI/CD pipeline.

  ### 11. Attended a workshop at Devops.js

**Rating:** 4.0/5.0 stars

**Reviewed by:** Verified User in Computer Software | Small-Business (50 or fewer emp.)

**Reviewed Date:** March 30, 2022

**What do you like best about StackHawk?**

How easy it was to set up, and while I may not need something so complete at the moment it's definitely something I would use with bigger projects.

**What do you dislike about StackHawk?**

That I wasn't aware of this type of code check before and how much time it could save in the end.

**What problems is StackHawk solving and how is that benefiting you?**

At the moment I haven't really solved any issue with StackHawk due to my project being quite small, but in a more mature and bigger project, this would solve a lot of issues. I mean having a test that analyzes and tells you some potential to improve your code is amazing.

  ### 12. Solid CICD integration with a bright future

**Rating:** 4.0/5.0 stars

**Reviewed by:** Matt M. | Senior Product Security Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** February 07, 2022

**What do you like best about StackHawk?**

Slick CICD integration for a known scanning tool

**What do you dislike about StackHawk?**

The core scanner is zap, without additional checks or enhancements.

**What problems is StackHawk solving and how is that benefiting you?**

Automating our CICD pipeline for DAST with decent jira integration

  ### 13. Good Tool for Appsec

**Rating:** 3.5/5.0 stars

**Reviewed by:** Patrick R. | Security Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** February 07, 2022

**What do you like best about StackHawk?**

Good tool for Dynamic App Scanning. Can greatly help with the Vulnerablity identification and remediation process

**What do you dislike about StackHawk?**

Does not seem to be a way to scan multipage/multisite applications or Mobile.

**What problems is StackHawk solving and how is that benefiting you?**

We are not currently implementing the product fully, just demo and poc phase.

  ### 14. Great Product with even better support.

**Rating:** 4.0/5.0 stars

**Reviewed by:** Glen K. | Senior Product Engineer, Small-Business (50 or fewer emp.)

**Reviewed Date:** May 14, 2021

**What do you like best about StackHawk?**

StackHawk has a nice, clean, no-nonsense interface that gets to the point, and gets out of the way. It integrates nicely with our workflow and the customer support and success teams have been great to help us get our product to a better state.

**What do you dislike about StackHawk?**

There is a bit of manual setup required that seems a little non-trivial, but given how modern applications are built I can't see a better way this could be done!

**What problems is StackHawk solving and how is that benefiting you?**

StackHawk helps us catch security vulnerabilities in an automated fashion as soon as they appear.


## StackHawk Discussions
  - [What is StackHawk used for?](https://www.g2.com/discussions/what-is-stackhawk-used-for)

- [View StackHawk pricing details and edition comparison](https://www.g2.com/products/stackhawk/reviews?filters%5Bnps_score%5D%5B%5D=4&section=pricing&secure%5Bexpires_at%5D=2026-08-07+11%3A57%3A03+-0500&secure%5Bsession_id%5D=b16eaaef-179c-43fe-86e8-50227224ea59&secure%5Btoken%5D=87f5911a4711181aafbc47af0783dad1503be29223c11b2cff949eeed0a4cf0f&format=llm_user)
## StackHawk Integrations
  - [Bitbucket](https://www.g2.com/products/bitbucket/reviews)
  - [CircleCI](https://www.g2.com/products/circleci/reviews)
  - [Datadog](https://www.g2.com/products/datadog/reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews)
  - [Jenkins](https://www.g2.com/products/jenkins/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [Microsoft Azure DevOps](https://www.g2.com/products/microsoft-azure-devops/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Snyk](https://www.g2.com/products/snyk/reviews)
  - [Vanta](https://www.g2.com/products/vanta/reviews)

## StackHawk Features
**Administration**
- API
- Extensibility
- Reporting and Analytics

**Administration**
- API / Integrations
- Extensibility

**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans
- Anomaly/Malware Detection

**API Management **
- API Discovery
- API Monitoring
- Reporting
- Change Management

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Analysis**
- Issue Tracking
- Reconnaissance
- Vulnerability Scan
- Compliance Management
- Automatic Scans
- SPA Scans

**Analysis**
- Reporting and Analytics
- Issue Tracking
- Vulnerability Scan

**Network**
- Compliance Testing
- Vulnerability Scanning
- Source-Code Scanning
- Web Scanning

**Security Testing**
- Compliance Monitoring
- API Verification
- API Testing

**Security**
- Data Security
- Data loss Prevention
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Performance and Reliability

**Testing**
- Manual Testing
- Test Automation
- Compliance Testing
- Black-Box Scanning
- Detection Rate
- False Positives

**Application**
- Manual Application Testing
- Black Box Testing
- Risk Analysis

**Security Management**
- Security and Policy Enforcement
- Anomoly Detection
- Bot Detection

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Runtime Container Security
- Asset Discovery
- Threat Intelligence
- Vulnerability Protection
- Alerts/Notifications
- Vulnerability/Threat Prioritization
- Generative AI
- SQL Injections
- Real-Time Analytics
- Threat Protection
- Web-Application Security
- Password Protection
- Website Crawling
- Vulnerability Assessment

**Additional Functionality**
- Network Mapping
- Activity Dashboard
- SQL Injections
- Audit Management
- Threat Intelligence
- Assignment Management
- Integration Management
- User Management
- Asset Discovery
- Remediation Management
- Vulnerability Scanning
- Generative AI
- Multi-User Collaboration
- AI Copilot
- Web-Application Security
- Vulnerability Assessment
- Security Auditing
- Runtime Container Security
- Network Scanning
- Password Cracking
- Simulated Threat Attacks
- Certificates
- Alerts/Notifications
- Real-Time Data
- Cross-Site Scripting
- Exploit Frameworks

## Top StackHawk Alternatives
  - [Intruder](https://www.g2.com/products/intruder/reviews) - 4.8/5.0 (209 reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews) - 4.5/5.0 (884 reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (837 reviews)

