← All website monitoring tools
Rapid7 InsightAppSec
Enterprise cloud DAST — quote-based, often bundled with InsightVM and InsightIDR.
What it does well
- Attack Replay provides developers with exact HTTP requests to reproduce vulnerabilities.
- Integrates tightly with other Rapid7 Insight products for a unified security view.
- Scans can be triggered via API, enabling integration into CI/CD build pipelines.
Where it falls short
- No public pricing or free trial; requires engaging with a sales team for a quote.
- Primarily suited for enterprises; may be too complex and costly for small businesses.
- Fewer out-of-the-box integrations compared to some competitors focused solely on DAST.
Alternatives to Rapid7 InsightAppSec
Acunetix
paidMature commercial DAST scanner from Invicti — quote-based, generally $4,500+/yr per target tier.
Enterprise DAST + IAST with Proof-Based Scanning — annual contracts, quote-only.
Checkmarx One
paidUnified AppSec platform consolidating SAST/SCA/IAST/API/IaC. Quote-based, public minimums ~$30,000/yr.
Astra Pentest
paidContinuous DAST + manual pentest hybrid — published pricing $199-$5,999/yr, popular with SaaS startups.