Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Paid
Claimed

StackHawk Reviews & Product Details - Page 6

StackHawk Overview

What is StackHawk?

StackHawk makes it simple for developers to find and fix application security bugs. Scan your application for AppSec bugs in the code your team wrote, triage and fix with provided documentation, and automate in your pipeline to prevent future bugs from hitting prod.

StackHawk Details
Product Website
Languages Supported
English
Show LessShow More
Product Description

StackHawk makes it simple for developers to find, triage, and fix application security bugs. Scan your application for AppSec bugs in the code your team wrote, triage and fix with provided documentation, and automate in your pipeline to prevent future bugs from hitting prod.


Seller Details
Seller
StackHawk
Company Website
Year Founded
2019
HQ Location
Denver, CO
Twitter
@StackHawk
1,153 Twitter followers
LinkedIn® Page
www.linkedin.com
46 employees on LinkedIn®
Description

StackHawk is a leading application security company that specializes in automated security testing for developers. Their platform helps organizations identify and remediate vulnerabilities in web applications through dynamic application security testing (DAST) integrated into the development workflow. StackHawk's tools enable DevOps teams to improve security without sacrificing speed, allowing for continuous testing and deployment of secure code. For more information, visit their website at https://stackhawk.com.


Alexa S.
AS
Overview Provided by:

Recent StackHawk Reviews

Verified User
U
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"Review"
Its scanning capabilities and easy integration into our CI/CD pipelines
David M.
DM
David M.Mid-Market (51-1000 emp.)
5.0 out of 5
"StackHawk is a great DAST security tool"
We have recently partnered with StackHawk for dynamic security code scanning and the product has been fantastic. StackHawk has many methods for per...
Verified User
A
Verified UserMid-Market (51-1000 emp.)
4.5 out of 5
"StackHawk Review"
I like the ability to configure the YAML file centrally. I like the integrations that are available as well.
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
0 people requested security information

StackHawk Media

StackHawk Demo - Finding Details
Security bug finding details from a scan of your application. Bug details, fix documentation, request/response payloads, and paths where the bug was found.
StackHawk Demo - HawkAI - All Repos
API Discovery & Observability powered by HawkAI
StackHawk is the only modern API security testing tool that runs in CI/CD, enabling developers to quickly find and fix security issues before they hit production.
Play StackHawk Video
StackHawk is the only modern API security testing tool that runs in CI/CD, enabling developers to quickly find and fix security issues before they hit production.

Official Downloads

Answer a few questions to help the StackHawk community
Have you used StackHawk before?
Yes

67 StackHawk Reviews

4.6 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
67 StackHawk Reviews
4.6 out of 5
67 StackHawk Reviews
4.6 out of 5

StackHawk Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for StackHawkQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Bart V.
BV
CTO & Co-founder
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

The setup and scanning process is very straightforward and provides ongoing value to stay compliant with OWASP and the many other CVE's out there. It has already helped us improve security and we're able to learn while using it because of its documentation included in the reporting. On top of all this, it has also helped us with sales and procurement. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

False positives do occur when using Stackhawk but they're very limited. Review collected by and hosted on G2.com.

Recommendations to others considering StackHawk:

If you are using GraphQL in your tech stack then StackHawk should be a no-brainer. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

- Building secure applications and keeping them secure

- Enterprise sales are easier when you are a customer of Stackhawk Review collected by and hosted on G2.com.

Chance H.
CH
COO
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

After evaluating several vendors, We chose to use Stackhawk because of how well it integrated with our CI/CD process and that it works really well in containers, whereas most competitors are harder (or impossible) to implement with our configuration. Their team is engaged and responsive. Their solution is modern and easy to use. I'm happy we selected this solution. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I don't have any complaints about using Stackhawk. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

The key benefit for us of using Stackhawk is having a Dynamic Application Security Testing (DAST) tool that runs in our containers effectively. This has been a key differentiator for us. Review collected by and hosted on G2.com.

Verified User in Public Policy
UP
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

The detailed descriptions of vulnerabilities and linked cheatsheets are incredibly helpful, especially for busy developers that may not have done any work on fixing security bugs. The UI is extremely easy on the eyes and one of the most well designed I've ever seen, the same goes for the UX. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Besides the CI setup issue we had which I believe was more of a codebase issue than a StackHawk issue (I wasn't involved), there really isn't anything currently in StackHawk that I have an issue with. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

We haven't had a lot of time to focus on security just yet, but we (I) am definitely looking forward to getting to the point where we are less pressured by a deadline and can focus on using StackHawk to start resolving the major issues with our codebase. Review collected by and hosted on G2.com.

Spencer K.
SK
Cyber Security Analyst
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Organic
What do you like best about StackHawk?

As a cybersecurity professional, I constantly worry about vulnerabilities in our applications. StackHawk outlines exactly what we need to do to make the application more secure, and I don't have to go about my day worrying about what might be out there without my knowledge. It does all of the scanning that would have previously taken hours, and it does it in a matter of minutes. This leaves more time in my day to focus on other aspects of security. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

I have not found anything to dislike yet. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

Through the initial scan, we learned of numerous vulnerabilities in our application, and we were provided with the severity of each. These were not obvious to us before the scan, so we gained immense insight from this. Review collected by and hosted on G2.com.

Glen K.
GK
Senior Product Engineer
Small-Business(50 or fewer emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

StackHawk has a nice, clean, no-nonsense interface that gets to the point, and gets out of the way. It integrates nicely with our workflow and the customer support and success teams have been great to help us get our product to a better state. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

There is a bit of manual setup required that seems a little non-trivial, but given how modern applications are built I can't see a better way this could be done! Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

StackHawk helps us catch security vulnerabilities in an automated fashion as soon as they appear. Review collected by and hosted on G2.com.

Jason M.
JM
ISEC Advisory Board Member / Course Content Expert
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

Ease of deployment and speed to delivery. Tooling runs great for local dev as well in the CI. Uses GitOps approach for scanning definitions in CI. Ingesting Swagger/OpenAPI spec for surface scanning. Fast scanning and actionable results. ZAP on steroids with great tooling and developer experience. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Would like to see smoketesting for CD to make sure basic security controls are in place for prod deploys. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

Shifting dynamic security scanning left in the development lifecycle so we can catch flaws earlier. Fuzzing / scanning public RESTful API surface. Review collected by and hosted on G2.com.

Verified User in Hospitality
AH
Mid-Market(51-1000 emp.)
Validated Reviewer
Review source: Organic
What do you like best about StackHawk?

StackHawk is an excellent tool built to find vulnerabilities developers typically miss and do not foresee when building applications. The support for both SOAP and REST APIs make it versatile to use for a variety of applications. The scan times are quick and resources are easily customizable in the Docker container. The ability to test against certain technologies using flags is a great plus to speed up scan times as well. The support team's quick turnaround times to resolve troubleshooting problems is a great asset to have when onboarding applications. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

Only supports running in a Docker container, would love to see a .jar extension to attach to applications for faster onboarding when containers are not readily available for use Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

This is the first DAST tool we have adopted and have begun implementing this into our CI/CD workflows. Ultimately we aim to identify all vulnerabilities wherever possible to ensure our ecosystem is safe and secure, and StackHawk is providing great value to our goal. The quick scan times provide an easier integration with the remaining components of our pipelines, and the ability to scan SOAP apps is a must until we're able to retire our legacy apps or convert them to REST APIs. Developers are also able to scan applications from their local workstations to capture vulnerabilities early on and wherever else StackHawk is not yet integrated into our CI/CD pipeline for a particular application. Review collected by and hosted on G2.com.

Verified User in Hospital & Health Care
UH
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

Easy to configure applications, containerized scanning, high-quality API & GraphQL scanning, and unlimited application scanning Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

We are currently working with the StackHawk team to reduce the number of false positives. Since the scanner works off of ZAP, improvements can be made to reduce the number of false positives in the scans. Additionally, recommendations can be improved to include action items relevant to the developer. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

Traditional DAST scanners scan a few assets at a scheduled time and can only find vulnerabilities after they have hit production. StackHawk allows us to empower developers and scan an unlimited number of applications before issues hit production. Additionally, StackHawk offers GraphQL and API scanning capabilities not found with other vendors. Review collected by and hosted on G2.com.

Luis R.
LR
Senior Application Security Engineer
Enterprise(> 1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

The Stackhawk dashboard is intuitive and functional. I also really appreciate the low level of false positives as well. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

It would be helpful if there were a way to automatically scan APIs without swagger documentation. Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

Stackhawk is allowing us to shift left security vulnerability patching. We can scan at commit time and allow developers to fix bugs before they are checked into version control. Review collected by and hosted on G2.com.

David F.
DF
Manager of IT
Mid-Market(51-1000 emp.)
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about StackHawk?

Determining security holes and bugs within our chosen app stack is key to handling PII and PIFI data. The Stackhawk team is excellent; they follow up when our pipelines encounter issues via shared slack channel, usually before we even have a chance to follow up. Review collected by and hosted on G2.com.

What do you dislike about StackHawk?

We haven't found anything to dislike from StackHawk Review collected by and hosted on G2.com.

What problems is StackHawk solving and how is that benefiting you?

Security Best Practices, hardening our API and Application Code, testing against all known penetration points on each pull request. Review collected by and hosted on G2.com.