Qualys WAS is most appreciated for how it streamlines web application security testing. Its cloud‑based design makes deployment fast and simple, while the intuitive dashboards provide clear visibility into vulnerabilities and scan progress. The platform integrates smoothly with DevSecOps pipelines and other Qualys tools, allowing teams to automate scans and even apply virtual patches through the Web Application Firewall. Performance is another highlight, as it can crawl and scan thousands of applications and APIs at scale, detecting OWASP Top 10 issues and reducing false positives. Although pricing may feel premium, the ROI comes from faster detection, fewer manual checks, and reduced breach risk. Support and onboarding are backed by strong documentation and training resources, helping teams adopt best practices quickly. Finally, its intelligence features — such as fault‑injection testing and anomaly detection — add depth to vulnerability analysis, making Qualys WAS a trusted solution for organizations managing large and complex application portfolios. Review collected by and hosted on G2.com.
High Cost for Large Portfolios – Pricing can feel expensive when scanning hundreds or thousands of applications, making it less attractive for smaller organizations.
Complex Configuration – Advanced setup and fine‑tuning of scans may require significant expertise, and the interface can feel overwhelming at first.
Limited Customization in Reporting – While dashboards are helpful, some users find the reporting options rigid and wish for more flexibility in tailoring outputs to specific compliance needs. Review collected by and hosted on G2.com.