Product Avatar Image

PortSwigger

Show rating breakdown
129 reviews
  • 1 profiles
  • 3 categories
Average star rating
4.8
#1 in 1 categories
Grid® leader
Serving customers since
2008
Profile Filters

All Products & Services

Profile Name

Star Rating

119
10
0
0
0

PortSwigger Reviews

Review Filters
Profile Name
Star Rating
119
10
0
0
0
Aryan S.
AS
Aryan S.
Cyber Security Trainee @ HCLTech | CEHv12 | ISC2 CC | BU’26
05/15/2026
Validated Reviewer
Verified Current User
Review source: Organic

Burp Suite Pro: A Powerful, All-in-One Platform for Web App Pen Testing

Burp Suite is, in my experience, one of the most capable and well-rounded web application security testing platforms available, and that becomes obvious quickly when you use it hands-on across real penetration testing engagements. The UI/UX is clearly built for security professionals. The tab-based workflow across Proxy, Repeater, Intruder, and Scanner feels intuitive once you internalize how the toolchain fits together. A lot of the real testing value comes from being able to intercept, modify, and replay HTTP/S requests in Repeater with full control over every parameter, and the interface keeps that process fast and low-friction. Integrations are another major strength. Burp’s extension ecosystem through the BApp Store is extensive, spanning everything from extra scanner checks to custom payload generators. Extensions like ActiveScan++, JWT Editor, and Autorize add meaningful depth beyond what the platform can test natively. The Collaborator server integration for out-of-band vulnerability detection—especially for blind SSRF and blind XSS—is genuinely impressive, and it helps catch issues that purely in-band scanners can miss. The automated scanner in Burp Suite Professional performs consistently well. It handles crawling complex modern web applications, including those with heavy JavaScript rendering, and the scan configuration options are granular enough to balance thoroughness versus speed depending on the engagement scope. For pricing and ROI, Burp Suite Professional feels justified for any serious penetration tester or security team doing regular web application assessments. Having deep manual testing capability and automated scanning in a single tool reduces the need for multiple separate solutions, which makes the per-user licensing cost easier to defend. Support and onboarding are also areas where PortSwigger stands out. The Web Security Academy is one of the best free security training resources available, with hands-on labs covering major vulnerability classes and tying directly into Burp Suite workflows. The documentation is thorough, kept up to date, and written for practitioners rather than reading like generic marketing material. AI and intelligence have improved noticeably in recent versions. Burp Suite’s scanner uses intelligent crawling and analysis to reduce false positives and prioritize higher-confidence findings, and PortSwigger continues investing in better automated detection accuracy. It isn’t “AI-first” in the way some newer tools position themselves, but the detection intelligence behind the scanner reflects PortSwigger’s deep research into real-world vulnerability patterns.
Arish B.
AB
Arish B.
--
04/23/2026
Validated Reviewer
Verified Current User
Review source: Organic

Complete Control Over Web Requests with Burp Suite

To be honest, what I like most about Burp Suite is how it gives you complete control over the “conversation” between your browser and the server. It feels like being a digital middleman, where nothing slips through unless you allow it.I been using Burp for a bit now and honestly, the interceptor is a lifesaver. It’s so satisfying to catch a request and manually change the parameters to see if I can bypass some weak validation. I mostly use repeater to spam different payloads or just change headers on the fly to see how the app reacts. Sometimes the interface feels a bit cluttered with all the tabs, but once you get the hang of the workflow, its way better than any other tool. Only thing that sucks is the Pro version price tag, but for what it does, its kinda worth it if you're serious about bug bounties
KS
Karan S.
03/10/2026
Validated Reviewer
Verified Current User
Review source: Organic

Best-in-Class Tool for Manual Web, API, and Mobile Testing

Best tool in the market for web application manual testings, APIs and mobile dyanmic testing. The UI is simple with lots of features. Extensions are really useful especially considering that we can code our own and add it for almost all cases. The discord channel is great for support and they respond to email quite early as well. It is easy to connect with any browser, mobile device (considering you bypassed SSL pinning) or postman. I use it daily for my VAPT job and bug bounty.

About

Contact

HQ Location:
Knutsford, GB

Social

@Burp_Suite

What is PortSwigger?

PortSwigger is a global leader in the creation of software tools for security testing of web applications. For over a decade, we have worked at the cutting edge of the web security industry, and our software is well established as the de facto standard toolkit used by web security professionals.

Details

Year Founded
2008