Burp Suite

Automated application security scanner for identifying vulnerabilities in APIs and web applications

Also known as
burp-suite

What is Burp Suite?

A dynamic analysis security testing tool that automatically scans APIs and applications to identify security vulnerabilities. It supports automated testing, API discovery through OpenAPI definitions, and integrates with CI/CD workflows for continuous security scanning.

Independently observed

Burp Suite pricing

We don't have Burp Suite's full plan breakdown yet (its pricing page resisted automated reading). Here's what we could confirm. Always check live pricing for exact numbers.

Pricing as of verify at live pricing ↗Independently observed
Quote-based

Free trial available on request

What Burp Suite does

The capabilities that matter for devsecops tools, normalised so it lines up with every alternative. “-” means we haven't confirmed it, not that it's missing.

Scan types
SAST (static analysis)
-
DAST (dynamic analysis)
SCA / dependency scanning
-
Secret scanning
-
Container / image scanning
-
IaC misconfiguration scanning
-
Governance
OSS licence compliance
-
SBOM generation (SPDX/CycloneDX)
-
Remediation
Automated fix / upgrade PRs
-
Prioritisation
Reachability / exploitability prioritisation
-
Deployment
Hosting
-
Integration
First-class CI / pipeline integration
In-editor / IDE scanning
-
Licensing
OSS engine available
-
Independently observed

Burp Suite FAQ

Common questions about Burp Suite, answered from independent, dated evidence.

What is Burp Suite?

A dynamic analysis security testing tool that automatically scans APIs and applications to identify security vulnerabilities. It supports automated testing, API discovery through OpenAPI definitions, and integrates with CI/CD workflows for continuous security scanning. It is indexed under DevSecOps Tools.

Source: https://portswigger.net/burp

How much does Burp Suite cost?

Burp Suite does not publish its prices. Pricing is quoted on request, so the figure depends on your seat count and requirements. We record this as a pricing-transparency signal rather than guessing a number. Pricing changes often, so verify at source before relying on it.

Source: https://portswigger.net/burp

What security certifications does Burp Suite have?

We have independently confirmed HIPAA and GDPR for Burp Suite. Certifications we do not list are ones we have not been able to verify from public sources, which is not the same as Burp Suite not holding them. Always confirm compliance directly before you rely on it.

Source: https://portswigger.net/compliance

Burp Suite alternatives

Other devsecops tools we track, ranked by the same independent score.

All Burp Suite alternatives, ranked →

Compare Burp Suite

Side by side against other devsecops tools, attribute by attribute, with a source on every value.

Independent · unbought · dated

The vioscaleAI score: one lens on the evidence

Not user reviews and not a paid placement: a confidence-weighted blend of the independent signals below (adoption, activity, security posture, and more), which you can sort and re-weight yourself. Vendors can correct their listing but can never move their rank, and stars are weighted low as a vanity metric. It is one way to read the evidence for Burp Suite, not the verdict.

Balanced composite 41 / 100
low · 43%
Signal contributions to the composite score
SignalScoreWeightContributionEvidence
Security posture300.216.3
Reliability500.094.7
Capabilities460.052.3
Price level00.040.0-
Integrations00.050.0-
Pricing transparency00.050.0-

Computed . Re-weight it by intent, or see the full method.

All data & sourcesshow ↓

Every value we hold, with its source, retrieval date, and confidence. This is the evidence behind the score: don't trust it, verify it.

Content

AttributeValueEvidence
Faq3 itemsmediumsource · 2026-09-10 · 63%

Features

AttributeValueEvidence
CapabilitiesDast, Ci nativemediumsource · 2026-09-04 · 60%

Pricing

AttributeValueEvidence
Modelquotemediumsource · 2026-09-04 · 60%
Price levelunknownmediumsource · 2026-09-04 · 60%

Reliability

AttributeValueEvidence
Status pageYesmediumsource · 2026-08-03 · 60%

Security

AttributeValueEvidence
GdprYeshighsource · 2026-08-03 · 75%
HipaaYeshighsource · 2026-08-03 · 75%
PciYeshighsource · 2026-08-03 · 75%
FedrampYesmediumsource · 2026-08-14 · 60%
Still deciding?

Is Burp Suite the right choice for you?

Tell us the job, the constraints and what you weigh most, and we will rank Burp Suite against the rest of the devsecops tools we index, using the same dated evidence weighted your way.

Free to run, no account needed to start. How the evaluation works

For the makers of Burp Suite

Is this your product?

This profile was built from public sources without asking you. You can take the badge below and use it anywhere, and you can claim the profile to correct anything we got wrong. Both are free, and neither moves Burp Suite up or down: nobody can buy rank here, including you.

Take the badge

Live, always current, and free to use on your own site. It shows Burp Suite's independent score and links back to this profile.

Burp Suite, verified on vioscaleAI
HTML
<a href="https://www.vioscale.ai/software/burp-suite" target="_blank" rel="noopener">
  <img src="https://www.vioscale.ai/badge/software/burp-suite.svg" alt="Burp Suite, verified on vioscaleAI" width="330" height="76" loading="lazy" />
</a>
Markdown, for a README →
Markdown
[![Burp Suite, verified on vioscaleAI](https://www.vioscale.ai/badge/software/burp-suite.svg)](https://www.vioscale.ai/software/burp-suite)

Claim the profile

Verify you control the domain and you can correct the facts, add the sources we should be reading, and see how AI assistants are describing Burp Suite. Free, and it does not change the score.

  • Correct anything wrong, with evidence
  • Point our crawler at the pages that matter
  • See which AI systems are reading this profile
Claim Burp Suite

Not the owner? How vendor profiles work