
What I like most about HCL AppScan is its deep scanning capabilities across both DAST and SAST, making it easy to spot critical vulnerabilities like SQL injection, XSS, and misconfigurations early in the development lifecycle. The actionable remediation guidance saves our team a ton of research time by pointing directly to the affected code lines and suggesting exact fixes. On top of that, its seamless integration into CI/CD pipelines allows us to automate security checks without slowing down deployment speeds. Review collected by and hosted on G2.com.
What I dislike most about HCL AppScan is that the user interface can feel dated and clunky, requiring a bit of a learning curve for team members who are new to the platform. Deep, comprehensive scans can also take a significant amount of time to complete and occasionally consume heavy system resources. Additionally, filtering out false positives still takes a noticeable amount of manual triage effort before passing actionable reports over to the engineering team. Review collected by and hosted on G2.com.