← All website monitoring tools
StackHawk
Developer-DAST built on top of ZAP — CI-native, free tier, paid from $49/app/mo.
Free tier: free Developer plan — 1 application, limited scans/mo
What it does well
- Integrates directly into CI/CD pipelines, providing feedback within pull requests.
- Offers a free developer plan for a single application with limited scans.
- Built on the widely-used and well-understood open-source ZAP scanning engine.
- Scans both traditional web applications and modern APIs (REST, GraphQL, SOAP).
Where it falls short
- Focuses exclusively on DAST, lacking integrated SAST or IAST capabilities.
- The free plan is limited to one application and a small number of scans per month.
- As a cloud-only solution, it may not suit organizations with strict on-premise requirements.
- Relatively new to the market, founded in 2019, with a smaller feature set than legacy vendors.
Alternatives to StackHawk
Beagle Security
freemiumAI-assisted DAST with free starter tier — paid plans from $99/mo, popular with SMB SaaS.
OWASP ZAP
freeMost popular free open-source DAST scanner — active/passive web scanning, intercepting proxy, CI/CD integration.
Burp Suite
freemiumIndustry-standard pentest proxy — free Community for manual work, Pro $449/yr per user, Enterprise from $6,995/yr.
Acunetix
paidMature commercial DAST scanner from Invicti — quote-based, generally $4,500+/yr per target tier.