Introducing G2.ai, the future of software buying.Try now
Share your insights with StackHawk

Thousands of people like you come to G2 to find out whether solutions like StackHawk are the right fit for them. Share your real experiences with StackHawk and the G2 community and help someone make the right decision about their software.

StackHawk Pros and Cons: Top Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users appreciate the easy integrations with CI/CD pipelines, making setup and configuration a breeze. (10 mentions)
Users commend the helpful customer support team at StackHawk for their responsiveness and attention to feedback. (9 mentions)
Users appreciate the ease of use of StackHawk, praising its nice UI and helpful customer support. (9 mentions)
Users praise the fast setup and diverse integration options of StackHawk, enhancing their development processes effectively. (7 mentions)
Users value the scanning efficiency of StackHawk, enabling quick identification and resolution of security vulnerabilities. (5 mentions)
Users commend StackHawk for its automated scanning, enabling quick and efficient identification of security vulnerabilities. (4 mentions)
Users face a complex setup process with StackHawk, requiring extensive learning and configuration efforts. (5 mentions)
Users find the complex setup of StackHawk challenging, requiring significant learning and configuration effort. (4 mentions)
Users find the high learning curve of StackHawk challenging due to limited training and complex setup processes. (3 mentions)
Users note a lack of features in StackHawk, particularly in vulnerability management and API endpoint collection. (3 mentions)
Users find StackHawk's limited scope frustrating due to manual policies, reporting gaps, and restricted accessibility options. (3 mentions)
Users find inadequate reporting frustrating, wishing for better dashboards and automated sharing of vulnerability progress. (2 mentions)

Top Pros or Advantages of StackHawk

1. Easy Integrations
Users appreciate the easy integrations with CI/CD pipelines, making setup and configuration a breeze.
See 10 mentions

See Related User Reviews

Verified User
U

Verified User

Mid-Market (51-1000 emp.)

4.0/5

"Review"

What do you like about StackHawk?

Its scanning capabilities and easy integration into our CI/CD pipelines

Michael O.
MO

Michael O.

Mid-Market (51-1000 emp.)

4.0/5

"DEV's Found It Easy To Integrate. INFOSEC Gets The DevSecOps View/Reporting"

What do you like about StackHawk?

The dev team found it fairl simple to get their codebase/apps (Python, BitBucket, Jenkins, Jira) integrated... we had a volunteer who went through th

2. Customer Support
Users commend the helpful customer support team at StackHawk for their responsiveness and attention to feedback.
See 9 mentions

See Related User Reviews

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you like about StackHawk?

Relatively easy to use once initial setup is done. Easy to add in automation. Decent interface. Customer support was very helpful.

SK

Shivani Santosh K.

Mid-Market (51-1000 emp.)

4.0/5

"StackHawk - An upcoming DAST solution"

What do you like about StackHawk?

Its configurable nature and diverse integration option. And the very supportive customer support team who value the feedback and make sure changes are

3. Ease of Use
Users appreciate the ease of use of StackHawk, praising its nice UI and helpful customer support.
See 9 mentions

See Related User Reviews

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you like about StackHawk?

Relatively easy to use once initial setup is done. Easy to add in automation. Decent interface. Customer support was very helpful.

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

3.5/5

"Good to have, in case it finds something in the future, but don't expect miracles"

What do you like about StackHawk?

Can find the most common vulnerabilities in common web applications. Easy to use and nice UI.

4. Integrations
Users praise the fast setup and diverse integration options of StackHawk, enhancing their development processes effectively.
See 7 mentions

See Related User Reviews

Michael O.
MO

Michael O.

Mid-Market (51-1000 emp.)

4.0/5

"DEV's Found It Easy To Integrate. INFOSEC Gets The DevSecOps View/Reporting"

What do you like about StackHawk?

The dev team found it fairl simple to get their codebase/apps (Python, BitBucket, Jenkins, Jira) integrated... we had a volunteer who went through th

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

5.0/5

"Positive product experience with helpful resources."

What do you like about StackHawk?

It's very fast to setup and get integrated. It has great configuration support and additional options.

5. Scanning Efficiency
Users value the scanning efficiency of StackHawk, enabling quick identification and resolution of security vulnerabilities.
See 5 mentions

See Related User Reviews

Verified User
U

Verified User

Mid-Market (51-1000 emp.)

4.0/5

"Review"

What do you like about StackHawk?

Its scanning capabilities and easy integration into our CI/CD pipelines

BB

Bonam B.

Enterprise (> 1000 emp.)

5.0/5

"A Fast, Developer-Friendly Security Solution with Clear Remediation Guidance"

What do you like about StackHawk?

StackHawk is an efficient and developer-friendly tool for application security testing. One of its standout features is the easy integration with CI/C

6. Automated Scanning
Users commend StackHawk for its automated scanning, enabling quick and efficient identification of security vulnerabilities.
See 4 mentions

See Related User Reviews

BB

Bonam B.

Enterprise (> 1000 emp.)

5.0/5

"A Fast, Developer-Friendly Security Solution with Clear Remediation Guidance"

What do you like about StackHawk?

StackHawk is an efficient and developer-friendly tool for application security testing. One of its standout features is the easy integration with CI/C

TL

Todd L.

Enterprise (> 1000 emp.)

5.0/5

"A Game-Changer for DevSecOps"

What do you like about StackHawk?

I appreciate StackHawk for its comprehensive documentation, which is incredibly helpful for passing on to developers, ensuring everyone shares respons

Top Cons or Disadvantages of StackHawk

1. Setup Complexity
Users face a complex setup process with StackHawk, requiring extensive learning and configuration efforts.
See 5 mentions

See Related User Reviews

Verified User
U

Verified User

Mid-Market (51-1000 emp.)

4.0/5

"Review"

What do you dislike about StackHawk?

Simplified documentation for the yml specs. I have to search all over and go through a ton of trial and error when it comes time to setup configuratio

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you dislike about StackHawk?

Not quite intuitive setup, so a bit of a learning curve. Hard to manage vulnerabilities from a perspective of seeing how to manually reproduce and als

2. Complex Setup
Users find the complex setup of StackHawk challenging, requiring significant learning and configuration effort.
See 4 mentions

See Related User Reviews

Verified User
U

Verified User

Mid-Market (51-1000 emp.)

4.0/5

"Review"

What do you dislike about StackHawk?

Simplified documentation for the yml specs. I have to search all over and go through a ton of trial and error when it comes time to setup configuratio

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you dislike about StackHawk?

Not quite intuitive setup, so a bit of a learning curve. Hard to manage vulnerabilities from a perspective of seeing how to manually reproduce and als

3. High Learning Curve
Users find the high learning curve of StackHawk challenging due to limited training and complex setup processes.
See 3 mentions

See Related User Reviews

LS

Lake S.

Mid-Market (51-1000 emp.)

4.0/5

"Stackhawk has been a great tool to implement inside of our CI/CD pipeline for DAST scanning."

What do you dislike about StackHawk?

There is not much training offered to get started with the tool.

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you dislike about StackHawk?

Not quite intuitive setup, so a bit of a learning curve. Hard to manage vulnerabilities from a perspective of seeing how to manually reproduce and als

4. Lacking Features
Users note a lack of features in StackHawk, particularly in vulnerability management and API endpoint collection.
See 3 mentions

See Related User Reviews

Verified User
A

Verified User

Mid-Market (51-1000 emp.)

3.5/5

"Good to have, in case it finds something in the future, but don't expect miracles"

What do you dislike about StackHawk?

It comes nowhere near close to a real pen-testing, and it doesn't find many vulnerabilities in GraphQL.

Verified User
A

Verified User

Enterprise (> 1000 emp.)

3.5/5

"Overall a decent front end to ZAP scanning"

What do you dislike about StackHawk?

Not quite intuitive setup, so a bit of a learning curve. Hard to manage vulnerabilities from a perspective of seeing how to manually reproduce and als

5. Limited Scope
Users find StackHawk's limited scope frustrating due to manual policies, reporting gaps, and restricted accessibility options.
See 3 mentions

See Related User Reviews

AF

Alejandro F.

Enterprise (> 1000 emp.)

5.0/5

"Amazing automatable DAST tool"

What do you dislike about StackHawk?

They need more reporting capabilities, more dashboard views to showcase the progress of vulnerabilities remediation. Some customization of scan polic

SK

Shivani Santosh K.

Mid-Market (51-1000 emp.)

4.0/5

"StackHawk - An upcoming DAST solution"

What do you dislike about StackHawk?

The limitation of being able to use with only internet accessible surface and limitation on on-prem usage. Additionally, lack of granular roles to avo

6. Inadequate Reporting
Users find inadequate reporting frustrating, wishing for better dashboards and automated sharing of vulnerability progress.
See 2 mentions

See Related User Reviews

AF

Alejandro F.

Enterprise (> 1000 emp.)

5.0/5

"Amazing automatable DAST tool"

What do you dislike about StackHawk?

They need more reporting capabilities, more dashboard views to showcase the progress of vulnerabilities remediation. Some customization of scan polic

BB

Bonam B.

Enterprise (> 1000 emp.)

5.0/5

"A Fast, Developer-Friendly Security Solution with Clear Remediation Guidance"

What do you dislike about StackHawk?

if would be great if you guys provide score card & PDF report on email so that we can easily share with other prople higher managment

StackHawk Reviews (68)

Reviews

StackHawk Reviews (68)

4.6
68 reviews
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
TL
Senior Site Reliability Engineer
Enterprise (> 1000 emp.)
"A Game-Changer for DevSecOps"
What do you like best about StackHawk?

I appreciate StackHawk for its comprehensive documentation, which is incredibly helpful for passing on to developers, ensuring everyone shares responsibility in writing scans. The speed and configurability of StackHawk's scanning capabilities are impressive; I can fine-tune the balance between cost and effective scan speed to suit our needs. StackHawk embodies a shift-left mentality, allowing us to identify issues earlier in the development cycle, thereby reducing technical debt and enhancing application security. The product is rich in features, and the support from the StackHawk team ensures the success of using the product. The scanning speed, previously a challenge with Tenable Nessus, has drastically improved since switching to StackHawk, especially with its configuration-as-code approach as opposed to a traditional web interface. Additionally, the initial setup was very quick and simple, making it easy to get started and integrate seamlessly with our existing tools like GitHub CodeQL and Jira for handling findings. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

The only improvement would be additional automation integration with results associating with a release. Review collected by and hosted on G2.com.

David M.
DM
Director of Security
Mid-Market (51-1000 emp.)
"StackHawk is a great DAST security tool"
What do you like best about StackHawk?

We have recently partnered with StackHawk for dynamic security code scanning and the product has been fantastic. StackHawk has many methods for performing code scanning tests which have been helpful for our development team. But I want to mention that perhaps the greatest thing about StackHawk has been their employees and the support they provide. (Most big software manufacturers sort of drop you off the deep end of the pool and disappear.) I will say that the customer on-boarding we had from StackHawk and their professionals was one of the best I've seen in my long career. They have a bunch of experts who are friendly and will assist you in getting the tools set up, explaining all of the features and options, and there to assist when you need help. I'd like to extend my genuine thanks to all at StackHawk for making our security program better and being a great partner. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I do not have any dislikes regarding StackHawk. Review collected by and hosted on G2.com.

Verified User in Higher Education
UH
Small-Business (50 or fewer emp.)
"Stachawk efficiently processed the data, providing insightful analytics and reports."
What do you like best about StackHawk?

Stachawk efficiently performed a comprehensive security assessment, identifying potential issues such as SQL injection, XSS, and security misconfigurations. The detailed reports provided clear insights into each vulnerability, along with recommendations for remediation.

Another key feature was its ability to adapt to different environments, making it a versatile solution for both black-box and white-box testing scenarios. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

A learning path should be added to help users maximize the potential of Stachawk. While the tool is powerful and intuitive, a structured learning path would provide step-by-step guidance on configuring scans, interpreting results, and implementing security best practices. Review collected by and hosted on G2.com.

Michael O.
MO
Director of Security
Mid-Market (51-1000 emp.)
"DEV's Found It Easy To Integrate. INFOSEC Gets The DevSecOps View/Reporting"
What do you like best about StackHawk?

The dev team found it fairl simple to get their codebase/apps (Python, BitBucket, Jenkins, Jira) integrated... we had a volunteer who went through the process & provide steps so the rest could cookie-cutter it. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I am not a coder - I'm on the InfoSec side of the house. So my take about SH relates to the admin portal & reporting... both of which of very good. It was easy to invite devs to the portal & the reports provide info that I use to relay for compliance/security work. Review collected by and hosted on G2.com.

Ramgopal K.
RK
Sr Security Consultant, SME& Tool Admin
Enterprise (> 1000 emp.)
"Working with Stack Hawk experience..."
What do you like best about StackHawk?

The onboarding of application.

Vendor customer support.

API files scanning.

Easy to use and implementation and DevSecOps CI/CD integration

The dashboard results...

Attack Surface utilization... etc., Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

To onboard each application why should we have to involve each application POC to write their extra files to configure into the system. Here its lagging time to pass KT to each application POC to come up with their config Yaml file. Review collected by and hosted on G2.com.

AF
Sr Application Security Engineer
Enterprise (> 1000 emp.)
"Amazing automatable DAST tool"
What do you like best about StackHawk?

You can setup any type of authenticated scans due to its YAML configuration setup.

It is possible to run internal scans since it only needs the binary to run it.

Customer support has been great so far, they are always on and ready to answer any question, even their bot helps a lot.

The integration they have with Snyk makes it great when it comes to deeper analysis. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

They need more reporting capabilities, more dashboard views to showcase the progress of vulnerabilities remediation.

Some customization of scan policies would be neat, the current way to apply policies for scans is very manual. Review collected by and hosted on G2.com.

BB
Senior Software Engineer
Enterprise (> 1000 emp.)
"A Fast, Developer-Friendly Security Solution with Clear Remediation Guidance"
What do you like best about StackHawk?

StackHawk is an efficient and developer-friendly tool for application security testing. One of its standout features is the easy integration with CI/CD pipelines, making it straightforward to incorporate into existing development workflows. Additionally, the scan times are quick, allowing teams to identify and address security vulnerabilities without significant delays to deployment. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

if would be great if you guys provide score card & PDF report on email so that we can easily share with other prople higher managment Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
AI
Mid-Market (51-1000 emp.)
"Fantastic DAST product for the container world"
What do you like best about StackHawk?

Central management platform - StackHawk's SaaS management platform significantly simplifies the management of our applications. It provides an intuitive workflow for issue triage and remediation, making it easier for our team to identify, prioritize, and address security vulnerabilities efficiently.

Container-first orientation - the container-first approach of StackHawk's scanners provides unparalleled flexibility and ease of integration within our workflows. Given our unique requirements and constraints, this architecture enables us to build custom scanning workflows easily with our own scaffolding with more powerful configuration than any other DAST scanner we've tested. This flexibility not only meets our current needs but also positions us well for future integration with developer-centric processes.

Customer support - StackHawk's customer success team has been exceptional in guiding us towards effective use of their product. They keep us engaged with regular updates and news, and they are incredibly responsive to our questions, feature requests, and bug reports. Their proactive support has been instrumental in maximizing the value we derive from StackHawk.

Engaging brand identity - on a personal note, I greatly appreciate StackHawk's creative bird-themed branding. Their attention to detail in maintaining a cohesive and engaging brand identity, even in their internal libraries, adds a touch of personality and fun to our interactions with the tool. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

The most difficult part of working with StackHawk is the code-oriented nature of scripting, especially for application authentication. Many scanners use passive proxy mechanisms to capture authentication traffic, which makes it easy to get up and running rapidly with authenticated scanning. StackHawk does not offer this, opting instead for more powerful customization via their scripting engine. This may not be for everyone. Review collected by and hosted on G2.com.

SK
Associate Security Specialist
Mid-Market (51-1000 emp.)
"StackHawk - An upcoming DAST solution"
What do you like best about StackHawk?

Its configurable nature and diverse integration option. And the very supportive customer support team who value the feedback and make sure changes are reflected in upcoming releases. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

The limitation of being able to use with only internet accessible surface and limitation on on-prem usage. Additionally, lack of granular roles to avoid accendential deletion of scan and scan result by a unaware user. Review collected by and hosted on G2.com.

Verified User in Banking
UB
Mid-Market (51-1000 emp.)
"Excellent customer service"
What do you like best about StackHawk?

The StackHawk team achieves what seems impossible. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

The path was not very clear as we embarked on the beginning of our journey. Review collected by and hosted on G2.com.

Product Avatar Image
Product Avatar Image
StackHawk