---
title: StackHawk Reviews
meta_title: 'StackHawk Reviews 2026: Details, Pricing, & Features | G2'
meta_description: Filter 68 reviews by the users' company size, role or industry to
  find out how StackHawk works for a business like yours.
aggregate_rating:
  rating_value: 4.6
  review_count: 68
  scale: '5'
date_modified: '2026-08-07'
parent_category:
  name: "DevSecOps\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t"
  url: https://www.g2.com/categories/devsecops
---


# StackHawk Reviews
**Vendor:** StackHawk  
**Category:** [Dynamic Application Security Testing (DAST) Software](https://www.g2.com/categories/dynamic-application-security-testing-dast)  
**Average Rating:** 4.6/5.0  
**Total Reviews:** 68
## About StackHawk
StackHawk is reimagining AppSec for AI-driven development, where applications are built faster than traditional AppSec tools can keep up. Our AppSec Intelligence Platform combines scalable runtime testing with complete attack surface discovery from source code. We integrate directly into development workflows and provide context-aware remediations to developers, enabling teams to find and fix exploitable vulnerabilities before they reach production. With real-time visibility and centralized program intelligence, AppSec teams can prioritize testing and fixing what matters. Companies like British Airways, ITV, and Norstella trust StackHawk to evaluate application risk, prove program value, and scale testing coverage to match development velocity.



## StackHawk Pros & Cons
**What users like:**

- Users value the **easy integrations** of StackHawk, enhancing CI/CD pipelines and streamlining the onboarding process. (4 reviews)
- Users commend StackHawk for its **exceptional customer support** , providing expert assistance and enhancing the overall user experience. (3 reviews)
- Users value the **customizability** of StackHawk, appreciating its flexibility and integration options for unique workflows. (3 reviews)
- Users find that StackHawk greatly enhances **efficiency** , enabling quicker identification and resolution of security vulnerabilities. (3 reviews)
- Users value the **scanning efficiency** of StackHawk, enabling faster and more effective security scanning processes. (3 reviews)
- User Interface (3 reviews)
- Affordable Pricing (2 reviews)
- Users commend StackHawk for its **automated scanning** , enabling quick and efficient identification of security vulnerabilities. (2 reviews)
- Automation Testing (2 reviews)
- CD Integration (2 reviews)

**What users dislike:**

- Users find the **complex setup** process frustrating due to the lack of simplified documentation and time-consuming configurations. (3 reviews)
- Users face a **high learning curve** with StackHawk due to its complex setup and scripting requirements. (3 reviews)
- Users find StackHawk **lacking features** , especially in API management and intuitive setup, hindering vulnerability management. (3 reviews)
- Users note the **limited scope** of StackHawk, particularly regarding on-prem usage and automation capabilities. (3 reviews)
- Users find **setup complexity** frustrating, as extensive YAML config trials are necessary for effective onboarding and scans. (3 reviews)
- Difficult Customization (2 reviews)
- False Positives (2 reviews)
- Inadequate Remediation (2 reviews)
- Users find **inadequate reporting** frustrating, wishing for better dashboards and automated sharing of vulnerability progress. (2 reviews)
- Lack of Detail (2 reviews)

## StackHawk Reviews
  ### 1. A Game-Changer for DevSecOps

**Rating:** 5.0/5.0 stars

**Reviewed by:** Todd L. | Senior Site Reliability Engineer, Enterprise (> 1000 emp.)

**Reviewed Date:** November 09, 2023

**What do you like best about StackHawk?**

I appreciate StackHawk for its comprehensive documentation, which is incredibly helpful for passing on to developers, ensuring everyone shares responsibility in writing scans. The speed and configurability of StackHawk's scanning capabilities are impressive; I can fine-tune the balance between cost and effective scan speed to suit our needs. StackHawk embodies a shift-left mentality, allowing us to identify issues earlier in the development cycle, thereby reducing technical debt and enhancing application security. The product is rich in features, and the support from the StackHawk team ensures the success of using the product. The scanning speed, previously a challenge with Tenable Nessus, has drastically improved since switching to StackHawk, especially with its configuration-as-code approach as opposed to a traditional web interface. Additionally, the initial setup was very quick and simple, making it easy to get started and integrate seamlessly with our existing tools like GitHub CodeQL and Jira for handling findings.

**What do you dislike about StackHawk?**

The only improvement would be additional automation integration with results associating with a release.

**What problems is StackHawk solving and how is that benefiting you?**

I use StackHawk for DAST and API scans, providing early pen testing results. It helps our team become aware of issues earlier, leading to less tech debt and better security. The fast, tunable scans and effective documentation enhance developer collaboration.

  ### 2. StackHawk is a great DAST security tool

**Rating:** 5.0/5.0 stars

**Reviewed by:** David M. | Director of Security, Mid-Market (51-1000 emp.)

**Reviewed Date:** January 23, 2025

**What do you like best about StackHawk?**

We have recently partnered with StackHawk for dynamic security code scanning and the product has been fantastic. StackHawk has many methods for performing code scanning tests which have been helpful for our development team. But I want to mention that perhaps the greatest thing about StackHawk has been their employees and the support they provide. (Most big software manufacturers sort of drop you off the deep end of the pool and disappear.) I will say that the customer on-boarding we had from StackHawk and their professionals was one of the best I've seen in my long career. They have a bunch of experts who are friendly and will assist you in getting the tools set up, explaining all of the features and options, and there to assist when you need help. I'd like to extend my genuine thanks to all at StackHawk for making our security program better and being a great partner.

**What do you dislike about StackHawk?**

I do not have any dislikes regarding StackHawk.

**What problems is StackHawk solving and how is that benefiting you?**

We had been using tools from larger software vendors, but they were becoming less effective and their value was declining over time (compared to the ever increasing costs). We looked around this crowded vendor space and reviewed several solutions for code scanning, API scanning, etc. We found that StackHawk was quite easy to set up and integrate. We also found that their staff and support were top notch.

  ### 3. Working with Stack Hawk experience...

**Rating:** 4.5/5.0 stars

**Reviewed by:** Ramgopal K. | Sr Security Consultant, SME&amp; Tool Admin, Enterprise (> 1000 emp.)

**Reviewed Date:** December 16, 2024

**What do you like best about StackHawk?**

The onboarding of application.
Vendor customer support.
API files scanning.
Easy to use and implementation and DevSecOps CI/CD integration
The dashboard results...
Attack Surface utilization... etc.,

**What do you dislike about StackHawk?**

To onboard each application why should we have to involve each application POC to write their extra files to configure into the system. Here its lagging time to pass KT to each application POC to come up with their config Yaml file.

**What problems is StackHawk solving and how is that benefiting you?**

As of now we have onboarded few of our client applications to the Stack Hawk and seeing good results and using those results to implement more security with the help of Dev Teams to remediate the security vulnerabilities.


## StackHawk Discussions
  - [What is StackHawk used for?](https://www.g2.com/discussions/what-is-stackhawk-used-for)

- [View StackHawk pricing details and edition comparison](https://www.g2.com/products/stackhawk/reviews?filters%5Bsentiment_snippet%5D=1809770&qs=pros-and-cons&section=pricing&secure%5Bexpires_at%5D=2026-08-13+15%3A26%3A21+-0500&secure%5Bsession_id%5D=6a9b4686-e8b9-4a15-a782-190e480704ea&secure%5Btoken%5D=18c43a936d3ddbf7c6ebfe21e6a41943262288b7e701f656cbd77b05acd3485d&format=llm_user)
## StackHawk Integrations
  - [Bitbucket](https://www.g2.com/products/bitbucket/reviews)
  - [CircleCI](https://www.g2.com/products/circleci/reviews)
  - [Datadog](https://www.g2.com/products/datadog/reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews)
  - [Jenkins](https://www.g2.com/products/jenkins/reviews)
  - [Jira](https://www.g2.com/products/jira/reviews)
  - [Microsoft Azure DevOps](https://www.g2.com/products/microsoft-azure-devops/reviews)
  - [Slack](https://www.g2.com/products/slack/reviews)
  - [Snyk](https://www.g2.com/products/snyk/reviews)
  - [Vanta](https://www.g2.com/products/vanta/reviews)

## StackHawk Features
**Administration**
- API
- Extensibility
- Reporting and Analytics

**Administration**
- API / Integrations
- Extensibility

**Performance**
- Issue Tracking
- Detection Rate
- False Positives
- Automated Scans
- Anomaly/Malware Detection

**API Management **
- API Discovery
- API Monitoring
- Reporting
- Change Management

**Cloud Visibility**
- Data Discovery
- Cloud Registry
- Cloud Gap Analytics

**Analysis**
- Issue Tracking
- Reconnaissance
- Vulnerability Scan
- Compliance Management
- Automatic Scans
- SPA Scans

**Analysis**
- Reporting and Analytics
- Issue Tracking
- Vulnerability Scan

**Network**
- Compliance Testing
- Vulnerability Scanning
- Source-Code Scanning
- Web Scanning

**Security Testing**
- Compliance Monitoring
- API Verification
- API Testing

**Security**
- Data Security
- Data loss Prevention
- Security Auditing
- Real-Time Data
- Cloud Application Security
- SSL Security

**Testing**
- Command-Line Tools
- Manual Testing
- Test Automation
- Performance and Reliability

**Testing**
- Manual Testing
- Test Automation
- Compliance Testing
- Black-Box Scanning
- Detection Rate
- False Positives

**Application**
- Manual Application Testing
- Black Box Testing
- Risk Analysis

**Security Management**
- Security and Policy Enforcement
- Anomoly Detection
- Bot Detection

**Identity**
- SSO
- Governance
- User Analytics
- Real-Time Analytics
- Visual Analytics
- Reporting/Analytics

**Agentic AI - Vulnerability Scanner**
- Autonomous Task Execution
- Proactive Assistance

**Additional Functionality**
- Alerts/Notifications
- AI Copilot
- Access Controls/Permissions
- Endpoint Management
- Intrusion Detection System
- Compliance Management
- HIPAA Compliant
- Search/Filter
- API
- Two-Factor Authentication
- Data Visualization
- Risk Assessment
- Real-Time Monitoring
- Event Logs
- Activity Dashboard
- Audit Management
- Cloud Security Policy Management
- Vulnerability Protection
- Anti Virus
- Incident Management
- Threat Intelligence
- Real-Time Reporting
- Reporting & Statistics
- User Management
- Encryption
- Vulnerability Scanning
- Generative AI
- Status Tracking
- Third-Party Integrations
- Real-Time Notifications
- Patch Management
- Monitoring
- Cloud Encryption

**Additional Functionality**
- SSL Security
- HIPAA Compliant
- API
- Threat Response
- Endpoint Protection
- Maintenance Scheduling
- Third-Party Integrations
- Security Auditing
- Application Security
- Encryption
- Network Security
- Real-Time Reporting
- AI Copilot
- Reporting/Analytics
- Authentication
- Financial Data Protection
- Anti Virus
- Secure Data Storage
- Virus Definition Update
- Activity Dashboard
- VPN
- Audit Trail
- Anti Spam
- Access Controls/Permissions
- Data Visualization
- Alerts/Escalation
- Data Security
- Runtime Container Security
- Asset Discovery
- Threat Intelligence
- Vulnerability Protection
- Alerts/Notifications
- Vulnerability/Threat Prioritization
- Generative AI
- SQL Injections
- Real-Time Analytics
- Threat Protection
- Web-Application Security
- Password Protection
- Website Crawling
- Vulnerability Assessment

**Additional Functionality**
- Network Mapping
- Activity Dashboard
- SQL Injections
- Audit Management
- Threat Intelligence
- Assignment Management
- Integration Management
- User Management
- Asset Discovery
- Remediation Management
- Vulnerability Scanning
- Generative AI
- Multi-User Collaboration
- AI Copilot
- Web-Application Security
- Vulnerability Assessment
- Security Auditing
- Runtime Container Security
- Network Scanning
- Password Cracking
- Simulated Threat Attacks
- Certificates
- Alerts/Notifications
- Real-Time Data
- Cross-Site Scripting
- Exploit Frameworks

## Top StackHawk Alternatives
  - [Intruder](https://www.g2.com/products/intruder/reviews) - 4.8/5.0 (209 reviews)
  - [GitLab](https://www.g2.com/products/gitlab/reviews) - 4.5/5.0 (885 reviews)
  - [Wiz](https://www.g2.com/products/wiz-wiz/reviews) - 4.7/5.0 (839 reviews)

