+
+

Related Products

  • Aikido Security
    239 Ratings
    Visit Website
  • Reflectiz
    33 Ratings
    Visit Website
  • Astra Pentest
    295 Ratings
    Visit Website
  • NinjaOne
    6,035 Ratings
    Visit Website
  • ManageEngine Endpoint Central
    3,286 Ratings
    Visit Website
  • Kasm Workspaces
    127 Ratings
    Visit Website
  • Planview Software Product Delivery
    2 Ratings
    Visit Website
  • Cloudflare
    2,042 Ratings
    Visit Website
  • ESET PROTECT Advanced
    2,304 Ratings
    Visit Website
  • Jama Connect
    387 Ratings
    Visit Website

About

ActiveState provides software development teams with the world's most comprehensive library of secure and trusted open source, over 79 million vetted components across all major language ecosystems (e.g., Java, Javascript, Python, R, Go, etc.), including transitive dependencies and OS-level libraries. By building everything from source, we ensure that every component is what it says it is, contains the fewest amount of vulnerabilities, and is continuously remediated. Companies can consume this open source where and when they need it - through their existing artifact repositories, as container images or managed distributions, or via IDPs. When teams transfer their open source responsibility to ActiveState, developers and security teams break free from the endless cycle of vulnerability management. Developers gain confidence knowing their code will make it to production faster and with less friction. Security gains assurance that policy and compliance standards are met by default.

About

Nessus is trusted by more than 30,000 organizations worldwide as one of the most widely deployed security technologies on the planet - and the gold standard for vulnerability assessment. From the beginning, we've worked hand-in-hand with the security community. We continuously optimize Nessus based on community feedback to make it the most accurate and comprehensive vulnerability assessment solution in the market. 20 years later and we're still laser focused on community collaboration and product innovation to provide the most accurate and complete vulnerability data - so you don't miss critical issues which could put your organization at risk. Today, Nessus is trusted by more than 30,000 organizations worldwide as one of the most widely deployed security technologies on the planet - and the gold standard for vulnerability assessment.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Supported
On-Premises Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Not Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

For teams developing mission critical software, ActiveState is a one stop shop for secure and trusted open source with a 79M+ catalog of built-from-source and continually remediated open source components

Audience

IT professionals searching for a Vulnerability Assessment solution

Support

Phone Support Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Not Supported

Screenshots and Videos

Screenshots and Videos

Pricing

$25,000
SMB. Start with one or two languages. $25,000. < 100 employees Per Language / Year

Mid-Market. Already running multiple languages in production. $50,000. 100–999 employees Per Language / Year

Enterprise. Securing open source across multiple business units. $150,000. 1,000+ employees Per Language / Year

Enterprise+. For engineering orgs large enough that whole-catalog access is standard. Talk to our team. 1,000+ developers Per Language / Year
Free Version Not Supported
Free Trial Not Supported

Pricing

No information available.
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 4.8 / 5
ease 5.0 / 5
features 4.8 / 5
design 5.0 / 5
support 4.4 / 5

Pros & Cons from Real Users

Pros

  • Customizable Scans Wide Platform Support Pre-built policies and Templates like PCI DSS and HIPAA Frequent Plugin Updates Active and Passive Detection Comprehensive Vulnerability Coverage
  • Nessus supports a wide range of operating systems and devices, making it versatile for diverse IT environments. Nessus benefits from an active community of users and professional support, ensuring that users can find solutions and best practices when needed. Nessus provides the flexibility to perform both agent-based scans for systems that require persistent monitoring and agentless scans for systems where installing an agent is impractical.
  • Nessus excels at identifying vulnerabilities in systems across a wide range of platforms, including operating systems, databases, network devices, and web applications. It checks for known vulnerabilities using both signature-based and heuristic-based scanning techniques Nessus can perform configuration audits by comparing system settings against industry best practices (e.g., CIS Benchmarks, DISA STIGs). This allows organizations to enforce security policies and ensure that systems are configured securely By providing Nessus with valid credentials (such as admin-level access), it can perform more in-depth scans and accurately identify vulnerabilities that require elevated privileges. Nessus can integrate with other security solutions such as SIEMs (Security Information and Event Management systems), ticketing systems (e.g., ServiceNow, Jira), and other vulnerability management tools. This helps automate workflows and streamline vulnerability remediation. Nessus offers an intuitive user interface with a simple setup process, making it accessible even to organizations without a dedicated security team. The interface provides easy access to scan configurations, reports, and plugin management.
  • 1) Nessus provides in-depth vulnerability scanning across a wide range of systems, applications, and devices, helping identify potential security risks quickly and thoroughly. 2) The vulnerability database is constantly updated, ensuring that the scanner detects the latest threats and vulnerabilities, which is crucial for maintaining up-to-date security. 3) The interface is intuitive and easy to navigate, even for users who aren’t security experts. It’s simple to run scans, view results, and take action based on the findings. 4) Nessus offers flexibility with customizable scanning profiles, allowing users to tailor scans to specific needs, whether it’s targeting particular systems, vulnerabilities, or compliance requirements. 5) The reports generated by Nessus are detailed and clear, offering actionable insights and prioritizing vulnerabilities based on severity. This helps teams address the most critical issues first.
  • In depth vulnerability scanning with very usable results in easy to read formats and reports that you can drill down into. Very detailed information for how quick the scan is.

Cons

  • Limited Automation Custom Scripting Complexity No Built-In Patch Management Limited Cloud Integration False Positives
  • The basic version of Nessus is free for limited use, accessing advanced features like compliance checks and extended reporting in Nessus Professional requires a subscription, which may not suit smaller organizations with tight budgets. Nessus scans can consume significant network and system resources, potentially slowing down operations or affecting the performance of critical systems during scans.
  • Nessus can be resource-heavy, especially when performing in-depth scans or scanning large environments. High network bandwidth and processing power are required to perform large-scale scans without negatively impacting system performance. In environments with limited resources, this could slow down network operations or impact system stability While Nessus does offer some web application scanning capabilities (e.g., detecting SQL injection, XSS, etc.), it is not as specialized or comprehensive as dedicated web application security testing tools like Burp Suite or OWASP ZAP. Organizations with a heavy focus on web applications may find Nessus lacking in depth for these specific needs
  • 1) While Nessus does integrate with some third-party tools, its integration options are more limited compared to some other vulnerability management platforms, which might be a drawback for larger organizations with complex IT environments. 2) Nessus can struggle with scaling up for very large, complex environments or enterprise-level networks, where more robust vulnerability management platforms might be better suited.
  • The free trial sucked. Not only is it limited to 7 days, but you can't even try the full feature set for that 7 days. It's limited to reporting on the first 16 devices it detects. Unfortunately on my network, it didn't make it to any servers before hitting that limit, so I only got info on workstations, a printer and a credit card reader. At least give me 1 full scan of my network so I can compare workstations to servers, or give me the ability to go back and pick certain IP addresses to scan, maybe via csv file upload?

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Training

Documentation Not Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Company Information

ActiveState
Founded: 1997
Canada
www.activestate.com

Company Information

Tenable
Founded: 2002
United States
www.tenable.com/products/nessus

Alternatives

Alternatives

Astra Pentest

Astra Pentest

Astra Security
Tenable One

Tenable One

Tenable
Tenable One

Tenable One

Tenable
ESOF

ESOF

TAC Security

Categories

Categories

Application Security Features

Analytics / Reporting Supported
Open Source Component Monitoring Supported
Source Code Analysis Supported
Third-Party Tools Integration Supported
Training Resources Supported
Vulnerability Detection Supported
Vulnerability Remediation Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Not Supported
Network Scanning Supported
Patch Management Not Supported
Policy Management Supported
Prioritization Supported
Risk Management Not Supported
Vulnerability Assessment Supported
Web Scanning Supported

Integrations

Centraleyezer Not Supported
Clockspring Not Supported
Conviso Platform Not Supported
Core Impact Not Supported
GitHub Supported
Google Digital Risk Protection Not Supported
Hexway Pentest Suite Not Supported
JFrog Supported
Jira Supported
KernelCare Enterprise Not Supported
Kubernetes Supported
NorthStar Navigator Not Supported
Notus Not Supported
Nucleus Not Supported
OverSOC Not Supported
Ruby Supported
Rust Supported
Seeker Not Supported
Swimlane Not Supported
Visual Studio Supported

Integrations

Centraleyezer Supported
Clockspring Supported
Conviso Platform Supported
Core Impact Supported
GitHub Not Supported
Google Digital Risk Protection Supported
Hexway Pentest Suite Supported
JFrog Not Supported
Jira Not Supported
KernelCare Enterprise Supported
Kubernetes Not Supported
NorthStar Navigator Supported
Notus Supported
Nucleus Supported
OverSOC Supported
Ruby Not Supported
Rust Not Supported
Seeker Supported
Swimlane Supported
Visual Studio Not Supported
Claim ActiveState and update features and information
Claim ActiveState and update features and information
Claim Tenable Nessus and update features and information
Claim Tenable Nessus and update features and information