AppSecNews
DAST Commercial Established

Fortify WebInspect

by OpenText

Long established enterprise dynamic scanner with deep scan configuration, macro based authentication and an optional runtime agent for deeper visibility.

Visit opentext.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Fortify WebInspect in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Product and platform naming has changed through ownership transitions, confirm current branding and packaging
  • Integration list: partially confirmed, verify against vendor docs

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

WebInspect crawls a running application and audits what it discovers. The crawl handles JavaScript driven navigation, and the audit phase applies a large, policy organized check library against discovered parameters, headers, cookies and forms. What has always characterized it is configurability: scan policies can be composed check by check, crawl behavior is tunable in detail, and session exclusions, custom parameter handling and request throttling are all exposed rather than hidden behind presets.

Authentication is handled through recorded macros, scripted sequences that log in and detect when a session has been lost mid scan so the scanner can re authenticate rather than spending the rest of the run testing a logged out application. An optional runtime agent installed on the application server instruments the code during the scan and reports what happened inside the application when a request arrived, which converts some black box findings into stack traces and line references. Results can be pushed to the vendor's central server for cross application reporting alongside static analysis findings.

Where it fits

This is an enterprise security team tool. It runs on scheduled cycles against staging or pre production, with scan policies standardized centrally and results consolidated for governance and audit reporting. It can be triggered from a pipeline, but full scans are far too slow for per commit gating, so teams typically wire it to release branches or nightly jobs. Making it work requires a person who knows the product: macro maintenance, scope tuning and policy selection are ongoing tasks, not one time setup.

Strengths

  • Very deep scan configuration, which matters on awkward legacy applications that defeat simpler scanners.
  • Macro based authentication with session loss detection is more robust than naive login recording.
  • The runtime agent gives code level context for findings, something pure black box scanners cannot produce.
  • Central consolidation with static analysis results supports enterprise governance and audit reporting.

Limitations

  • Heavy to operate. It rewards a dedicated specialist and punishes casual use with poor coverage and noisy results.
  • Scan times are long, which limits how often you can realistically run it.
  • The interface and workflow show their age relative to newer developer facing tools, and developer experience is not its priority.
  • Branding and platform packaging have shifted through successive ownership changes, which makes documentation and support paths confusing.

Who it suits

A defensible choice for large regulated enterprises that need thorough, policy governed dynamic scanning across a wide portfolio, already own the surrounding Fortify tooling, and have staff to operate it. A poor fit for small engineering teams, for organizations wanting fast developer feedback, or for anyone who cannot dedicate someone to maintaining scan configurations.

Used Fortify WebInspect? Recommend it under your own name and title.

Recommend this tool