-Technology used to detect the vulnerabilities, the way it's presented along with complete tracing, guidance for teams to learn about the vulnerability and associated risk are plus.
-Another great advantage is giving visibility into route coverage which helps to identify the route's that not exercised or having high number of vulnerabilities, but please note that it's not supported for all Java frameworks.
-Ease of implementation, works great for both SDLC/DevOps model. Review collected by and hosted on G2.com.
- Log collection could be improved, for any troubleshooting/debugging require coordination with application teams to set required configuration to collected required logs. Heard that they are changing this approach, looking forward to same.
- Integration with systems like JIRA and other ticketing systems have issues. Again in roadmap to fix.
- Some of the updates require configuration change at the app end, which is hard to implement as it requires coordination with app teams - very hard to adopt to new enhancements.
- Technical support could be improved, slowly seeing the quality of support going down.
- For certain frameworks and app servers, vulnerabilities within commercial app server/framework is getting reported - kind of mess if it's one of the unsupported framework. Review collected by and hosted on G2.com.