fitgap

OpenText Dynamic Application Security Testing

Features
Ease of use
Ease of management
Quality of support
Affordability
Market presence
Take the quiz to check if OpenText Dynamic Application Security Testing and its alternatives fit your requirements.
Pricing from
Contact the product provider
Free Trial unavailable
Free version unavailable
User corporate size
Small
Medium
Large
User industry
  1. Energy and utilities
  2. Banking and insurance
  3. Manufacturing

What is OpenText Dynamic Application Security Testing

OpenText Dynamic Application Security Testing is a dynamic web application security testing product used to identify runtime vulnerabilities by scanning running applications and APIs. It is typically used by application security teams and DevSecOps practitioners to validate security issues in staging or production-like environments and to support continuous testing in CI/CD pipelines. The product focuses on black-box testing techniques and reporting workflows that fit enterprise governance and compliance needs.

pros

Enterprise-grade governance and reporting

The product supports structured reporting and vulnerability management workflows that align with enterprise security programs. It is designed to help teams document findings, track remediation, and produce audit-friendly outputs. This is useful for organizations that need standardized processes across many applications and teams.

Runtime testing for web apps

As a DAST tool, it tests applications in a running state and can identify issues that static analysis may miss, such as certain authentication, session, and configuration weaknesses. This approach helps validate real-world exploitability in a deployed environment. It is well-suited for testing externally reachable web applications and services.

Fits DevSecOps scanning use cases

The product is commonly positioned for integration into security testing programs that include CI/CD and release gating. It can be used to run repeatable scans against environments as part of a broader secure SDLC. This supports teams that want automated security checks alongside functional testing.

cons

Limited coverage beyond DAST

DAST primarily evaluates behavior of running applications and does not replace code-level analysis, dependency analysis, or infrastructure misconfiguration checks. Teams often need additional tools to cover SAST, SCA, container, and IaC security. This can increase overall toolchain complexity for DevSecOps programs.

Scan tuning and false positives

Dynamic scanning often requires configuration to handle authentication flows, multi-step workflows, and modern single-page applications. Without careful tuning, scans can miss paths or generate findings that require manual validation. This can create operational overhead for security and engineering teams.

Potential performance and environment impact

Active scanning can place load on target applications and may trigger rate limits, WAF rules, or monitoring alerts. Many organizations need dedicated test environments or carefully scheduled scans to avoid disrupting services. This can slow adoption for teams that want frequent, always-on testing.

Plan & Pricing

Public pricing on vendor site: Unavailable — OpenText does not list public pricing for OpenText Dynamic Application Security Testing (Fortify); the product page prompts visitors to "Contact us" / "Request a demo".

Official materials located: Datasheet (PDF) describing features, deployment options, and capabilities; no pricing or licensing tiers are disclosed in the datasheet.

Trial information (related product): OpenText publishes a 15-day free trial for "OpenText Core Application Security (Fortify)" (cloud service), but the trial page explicitly states that dynamic scans are NOT available in that free trial (dynamic scanning is part of the full paid service).

Purchase path / notes: No public list prices or tiered plans found on OpenText’s official pages for this product. Prospective buyers are directed to contact OpenText sales or request a demo for pricing and licensing details.

Seller details

OpenText Corporation
Waterloo, Ontario, Canada
1991
Public
https://www.opentext.com/
https://x.com/OpenText
https://www.linkedin.com/company/opentext/

Tools by OpenText Corporation

OpenText Application Quality Management
Opentext functional Testing
OpenText Professional Performance Engineering
Opentext functional Testing for Developers
OpenText Functional Testing Lab for Mobile and Web
OpenText AppWorks Platform
OpenText LoadRunner Enterprise
OpenText Deployment Automation 25.2
OpenText AccuRev
OpenText Universal Discovery & Universal CMDB (UD/UCMDB)
OpenText ZENworks Configuration Management
OpenText Operations Bridge (OpsBridge)
OpenText Core Performance Engineering
OpenText Silk Performer
OpenText Service Virtualization
Ext JS
OpenText Project and Portfolio Management (PPM)
OpenText Vertica
OpenText PlateSpin Migrate
OpenText Migrate

Best OpenText Dynamic Application Security Testing alternatives

StackHawk
Contrast Security
Checkmarx
Pynt - API Security Testing
See all alternatives

Popular categories

All categories