Introducing G2.ai, the future of software buying.Try now
It's been two months since this profile received a new review
Leave a Review

StackHawk Reviews & Product Details

Pricing

Pricing provided by StackHawk.

Secure

$39.00
1 Code Contributor Per Month

StackHawk Integrations

(12)
Verified by StackHawk

StackHawk Media

StackHawk Demo - Finding Details
Security bug finding details from a scan of your application. Bug details, fix documentation, request/response payloads, and paths where the bug was found.
StackHawk Demo - Visibility
API discovery and application attack surface mapping from code
StackHawk is the only modern API security testing tool that runs in CI/CD, enabling developers to quickly find and fix security issues before they hit production.
Play StackHawk Video
StackHawk is the only modern API security testing tool that runs in CI/CD, enabling developers to quickly find and fix security issues before they hit production.
Product Avatar Image

Have you used StackHawk before?

Answer a few questions to help the StackHawk community

StackHawk Reviews (68)

Reviews

StackHawk Reviews (68)

4.6
68 reviews

Review Summary

Generated using AI from real user reviews
Users consistently praise StackHawk for its ease of use and fast integration into CI/CD pipelines, making it a valuable tool for identifying security vulnerabilities early in the development process. The intuitive interface and comprehensive documentation enhance the user experience, allowing teams to quickly address security issues. However, some users note that the setup can be complex, particularly for non-containerized applications.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
UI
Small-Business (50 or fewer emp.)
"Excellent vulnerability scanner tool for REST APIs"
What do you like best about StackHawk?

The tool is straightforward to use and scan the APIs for vulnerabilities very quickly. Provides a docker image which could be directly used Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Sometimes, all the endpoints from the swagger spec is not recognized Review collected by and hosted on G2.com.

Bart V.
BV
CTO & Co-founder
Small-Business (50 or fewer emp.)
"Scanning to stay compliant"
What do you like best about StackHawk?

The setup and scanning process is very straightforward and provides ongoing value to stay compliant with OWASP and the many other CVE's out there. It has already helped us improve security and we're able to learn while using it because of its documentation included in the reporting. On top of all this, it has also helped us with sales and procurement. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

False positives do occur when using Stackhawk but they're very limited. Review collected by and hosted on G2.com.

Chance H.
CH
COO
Small-Business (50 or fewer emp.)
"Stackhawk offers a cutting edge DAST tool that integrates the way we need it to"
What do you like best about StackHawk?

After evaluating several vendors, We chose to use Stackhawk because of how well it integrated with our CI/CD process and that it works really well in containers, whereas most competitors are harder (or impossible) to implement with our configuration. Their team is engaged and responsive. Their solution is modern and easy to use. I'm happy we selected this solution. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I don't have any complaints about using Stackhawk. Review collected by and hosted on G2.com.

Verified User in Public Policy
UP
Small-Business (50 or fewer emp.)
"In-depth and invaluable security insight packaged into the best UI you've ever seen"
What do you like best about StackHawk?

The detailed descriptions of vulnerabilities and linked cheatsheets are incredibly helpful, especially for busy developers that may not have done any work on fixing security bugs. The UI is extremely easy on the eyes and one of the most well designed I've ever seen, the same goes for the UX. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Besides the CI setup issue we had which I believe was more of a codebase issue than a StackHawk issue (I wasn't involved), there really isn't anything currently in StackHawk that I have an issue with. Review collected by and hosted on G2.com.

Spencer K.
SK
Cyber Security Analyst
Mid-Market (51-1000 emp.)
"StackHawk Eases My Mind"
What do you like best about StackHawk?

As a cybersecurity professional, I constantly worry about vulnerabilities in our applications. StackHawk outlines exactly what we need to do to make the application more secure, and I don't have to go about my day worrying about what might be out there without my knowledge. It does all of the scanning that would have previously taken hours, and it does it in a matter of minutes. This leaves more time in my day to focus on other aspects of security. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I have not found anything to dislike yet. Review collected by and hosted on G2.com.

Glen K.
GK
Senior Product Engineer
Small-Business (50 or fewer emp.)
"Great Product with even better support."
What do you like best about StackHawk?

StackHawk has a nice, clean, no-nonsense interface that gets to the point, and gets out of the way. It integrates nicely with our workflow and the customer support and success teams have been great to help us get our product to a better state. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

There is a bit of manual setup required that seems a little non-trivial, but given how modern applications are built I can't see a better way this could be done! Review collected by and hosted on G2.com.

Jason M.
JM
ISEC Advisory Board Member / Course Content Expert
Mid-Market (51-1000 emp.)
"DevSecOps tool for API and SPA’s dynamic scanning"
What do you like best about StackHawk?

Ease of deployment and speed to delivery. Tooling runs great for local dev as well in the CI. Uses GitOps approach for scanning definitions in CI. Ingesting Swagger/OpenAPI spec for surface scanning. Fast scanning and actionable results. ZAP on steroids with great tooling and developer experience. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Would like to see smoketesting for CD to make sure basic security controls are in place for prod deploys. Review collected by and hosted on G2.com.

Verified User in Hospitality
AH
Mid-Market (51-1000 emp.)
"Fast and effective DAST tool"
What do you like best about StackHawk?

StackHawk is an excellent tool built to find vulnerabilities developers typically miss and do not foresee when building applications. The support for both SOAP and REST APIs make it versatile to use for a variety of applications. The scan times are quick and resources are easily customizable in the Docker container. The ability to test against certain technologies using flags is a great plus to speed up scan times as well. The support team's quick turnaround times to resolve troubleshooting problems is a great asset to have when onboarding applications. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Only supports running in a Docker container, would love to see a .jar extension to attach to applications for faster onboarding when containers are not readily available for use Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Mid-Market (51-1000 emp.)
"Great DAST Scanner that empowers developers"
What do you like best about StackHawk?

Easy to configure applications, containerized scanning, high-quality API & GraphQL scanning, and unlimited application scanning Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

We are currently working with the StackHawk team to reduce the number of false positives. Since the scanner works off of ZAP, improvements can be made to reduce the number of false positives in the scans. Additionally, recommendations can be improved to include action items relevant to the developer. Review collected by and hosted on G2.com.

Luis R.
LR
Senior Application Security Engineer
Enterprise (> 1000 emp.)
"Great Dast for Modern Applications"
What do you like best about StackHawk?

The Stackhawk dashboard is intuitive and functional. I also really appreciate the low level of false positives as well. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

It would be helpful if there were a way to automatically scan APIs without swagger documentation. Review collected by and hosted on G2.com.

Pricing Options

Pricing provided by StackHawk.

Secure

$39.00
1 Code Contributor Per Month

Scale

$59.00
1 Code Contributor Per Month

Custom

$0.00
1 Code Contributor Per Month
StackHawk Comparisons
Product Avatar Image
Snyk
Compare Now
Product Avatar Image
GitLab
Compare Now
Product Avatar Image
Beagle Security
Compare Now
StackHawk Features
API / Integrations
Extensibility
Reporting and Analytics
Issue Tracking
Vulnerability Scan
Manual Testing
Test Automation
Compliance Testing
Detection Rate
False Positives
Automated Scans
Product Avatar Image
StackHawk