---
title: "DefectDojo Software Pricing, Alternatives & More 2026 | Capterra"
description: "With the help of Capterra, learn about DefectDojo Software - reviews, pricing plans, popular comparisons to other Vulnerability Scanner products and more."
source_url: "https://www.capterra.com/p/178929/DefectDojo/"
page_type: "product"
language: "en"
---

# 

 DefectDojo Software Review 2026: Features, Reviews, Integrations, Pros & Cons

Last updated on September 23, 2026

Provider data verified by our Software Research team, and reviews moderated by our Reviews Verification team.

[Description](#description)[Use cases](#use-cases)[Alternatives](#alternatives)[FAQs](#faqs)[Features](#features)[Pricing](#pricing)[Support](#support)[Reviews](#reviews)

DefectDojo

## What is DefectDojo?

DefectDojo is an open-source application vulnerability management tool designed for both DevSecOps and traditional application security. DefectDojo integrates with 150 security tools, has bi-directional integration with JIRA, and algorithms that learn overtime to automatically reduce noise and distill results. The tool provides reporting at every level including tests, engagements, and products, and offers a variety of metrics to gain visibility into vulnerability trends and insights.

## What is DefectDojo used for?

[Vulnerability Scanner](https://www.capterra.com/vulnerability-scanner-software/)[Vulnerability Management](https://www.capterra.com/vulnerability-management-software/)

Top alternative

Featured

Overall rating

Based on 2 user reviews

Reviews sentiment

Positive

\-

Neutral

\-

Negative

\-

Contact vendor  
for pricing

Free trial  
available

Includes Free Version

Capterra Shortlist charts the highest-rated and most popular products...

Our "Best of" badge program showcases products with the highest ratings...

Our "Best of" badge program showcases products with the highest ratings...

Do you work for DefectDojo?[Manage this product listing](https://www.g2.com/products/defectdojo/claim_requests/new?auto=true)

## DefectDojo Overview

Updated September 2026

AI summary

DefectDojo is a vulnerability management platform designed for small to midsize businesses and technical teams focused on application and infrastructure security. Delivered via cloud or web, it centralizes tracking, organization, and management of security findings, supporting workflows such as vulnerability import, deduplication, remediation, and reporting to help maintain oversight of security risks and testing outcomes.

## Compare with a popular alternative

Capterra selects software alternatives based on relevant features, verified user reviews and user interactions. Placement may be influenced by client status.

### DefectDojo

4.0 (2)

VS.

[4.9 (239)](https://www.capterra.com/p/180609/Action1-RMM/reviews/)

Starting Price

Contact vendor

Starting Price

Contact vendor

Free Trial

Free Version

Pricing Options

Free Trial

Free Version

Ease Of Use

5.0 (2)

Ease Of Use

4.8 (239)

Value For Money

5.0 (2)

Value For Money

4.9 (226)

Customer Service

4.0 (2)

Customer Service

4.8 (212)

## DefectDojo alternatives

[4.7 (153)](https://www.capterra.com/p/148872/Automox/reviews/)

Starting price

$1.00

Per User, Per Month

Pricing Options

Free Trial

Free Version

User Rating

98%

of reviewers

rated it above 4 stars

[4.7 (66)](https://www.capterra.com/p/231180/Heimdal-Patch--Asset-Management/reviews/)

Starting price

$16.00

Per User, Per Month

Pricing Options

Free Trial

Free Version

User Rating

100%

of reviewers

rated it above 4 stars

Highest Rated

[4.9 (493)](https://www.capterra.com/p/181954/Iru/reviews/)

Starting price

Contact vendor for pricing

Pricing Options

Free Trial

Free Version

User Rating

99%

of reviewers

rated it above 4 stars

[ManageEngine Vulnerability Manager Plus](https://www.capterra.com/p/185510/ManageEngine-Vulnerability-Manager-Plus/)

[4.7 (43)](https://www.capterra.com/p/185510/ManageEngine-Vulnerability-Manager-Plus/reviews/)

Starting price

$695.00

Per User, Per Month

Pricing Options

Free Trial

Free Version

User Rating

95%

of reviewers

rated it above 4 stars

[Learn More](https://www.capterra.com/p/185510/ManageEngine-Vulnerability-Manager-Plus/)

[View all alternatives](https://www.capterra.com/p/178929/DefectDojo/alternatives/)

## FAQs about DefectDojo

Overview

### What company size and specific industries is DefectDojo built for?

DefectDojo is designed for small to midsize businesses and for teams working in DevOps, application security, infrastructure security, and CI/CD environments, as well as open source users. It fits organizations that need a security testing and tracking tool for technical teams handling application and infrastructure risk.

Features and Usability

### What are the key features of DefectDojo?

DefectDojo offers vulnerability management features for tracking, organizing, and managing security findings across applications and infrastructure. It supports vulnerability import, deduplication, engagement management, remediation workflows, and reporting, giving teams a central place to record and monitor issues.

Getting Started and Support

### What training and onboarding options does DefectDojo offer?

DefectDojo provides in person training, live online sessions, webinars, and documentation to help teams get started. In person and live online formats support guided instruction, webinars offer scheduled training presentations, and documentation gives written reference material for setup and feature review.

Getting Started and Support

### What customer support options does DefectDojo offer?

DefectDojo provides chat support for users who need help with the product. No reviewer feedback about support quality is available, so there is no evidence to describe response times, helpfulness, or common frustrations with the support experience.

## Features

AI summary

Based on 624 Vulnerability Scanner reviews

Capterra reviewers highlight the following as the features buyers value most when evaluating vulnerability management software:

-   **Vulnerability/Threat Prioritization** (**64%** of reviewers rated this feature as critical)
-   **Patch Management** (**64%**)
-   **Vulnerability Scanning** (**66%**)

DefectDojo is built around vulnerability management workflows, giving teams a central place to track findings, review security issues, and manage remediation activity across testing inputs. Its feature set supports ongoing visibility into identified vulnerabilities and related processes, helping businesses maintain organized security records, coordinate follow-up work, and improve oversight of risk management efforts.

Access Controls/Permissions

Define levels of authorization for access to specific files or systems

Activity Dashboard

Dashboard to view the status of ongoing processes, identify current incidents and track past activities

AI Copilot

A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users

Alerts/Escalation

System alerts about the need to escalate an issue or request

Alerts/Notifications

Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges

Anomaly/Malware Detection

Automatically identify and flag unusual behaviors and malicious software

DefectDojo 54 features

### All Features
- Access Controls/Permissions: Define levels of authorization for access to specific files or systems
- Activity Dashboard: Dashboard to view the status of ongoing processes, identify current incidents and track past activities
- AI Copilot: A virtual assistant that uses AI to pursue goals and complete tasks on behalf of users
- Alerts/Escalation: System alerts about the need to escalate an issue or request
- Alerts/Notifications: Alerts or notifications of various types such as pop-up messages, sounds, banners, or badges
- Anomaly/Malware Detection: Automatically identify and flag unusual behaviors and malicious software
- Anti Spam: Techniques to prevent and filter unwanted or unsolicited email spam from reaching a user's inbox
- Anti Virus: Prevents, detects and removes malware
- API: Application programming interface that allows for integration with other systems/databases
- Application Security: Identify and respond to security threats to developed applications
- Audit Trail: A record of all activities within the system, including user access, changes made, etc.
- Authentication: Verify the identity of users/devices to enable secure access
- Automated Scans: Runs pre-scripted vulnerability scans without requiring manual work.
- Autonomous Task Execution: Completes tasks independently without constant human intervention
- Black Box Testing: Scans functional applications externally for vulnerabilities like SQL injection or XSS.
- Compliance Testing: Allows users to scan applications and networks for specific compliance requirements.
- Configuration Monitoring: Monitors configuration rule sets and policy enforcement measures and document changes to maintain compliance.
- Data Security: Protect sensitive data for digital privacy
- Data Visualization: Graphical representation of data
- Detection Rate: The rate at which scans accurately detect all vulnerabilities associated with the target.
- Encryption: Convert data into a code for security
- Endpoint Protection: Protect users working remotely and provide secure environments for personal devices to access company programs
- False Positives: The rate at which scans falsely indicate detection of a vulnerability when no vulnerabilitiy legitimately exists.
- Generative AI: Use AI to generate content in the form of text, images, videos, etc.
- HIPAA Compliant: Compliant with HIPAA, which sets standards for sensitive patient data protection
- Issue Tracking: Record and follow the progress of every issue
- Maintenance Scheduling: Schedule predetermined or ad hoc maintenance services and labor requests
- Manual Application Testing: Allows users to perfrom hands-on live simulations and penetration tests.
- Network Scanning: Scanning networks to identify security threats
- Network Security: Prevent and monitor unauthorized access, misuse, modification, or denial of a computer network and network-accessible resources
- Password Protection: Protect passwords from security threats
- Proactive Assistance: Uses webpage, tab, browsing session, or selected text context to generate responses and suggestions
- Real-Time Analytics: Analyze and gain insights into data in real-time
- Real-Time Reporting: Active reporting of data and metrics
- Reporting/Analytics: View and track pertinent metrics to find patterns and gain insights from data
- Risk Analysis: Analyze potential risks across the organization
- Runtime Container Security: Continuously vetting activities within the container application environment including hosts, open ports, protocols and payloads.
- Secure Data Storage: Securely stores data to prevent data loss or breaches
- Security Auditing: Systematic evaluation of the security of a company's overall security system and situation
- Source-Code Scanning: Scan the initial code written for application development
- SQL Injections: Protect against code driven website security attack techniques
- SSL Security: Security protocol that ensures secure, encrypted communication over the internet, safeguarding sensitive data from unauthorized access
- Static Code Analysis: Examines application source code for security flaws without executing it.
- Third-Party Integrations: Set up connections to third-party platforms to improve business processes
- Threat Intelligence: Information to prevent, understand and identify cyber threats
- Threat Protection: Protect incoming and outgoing communications against malware, spam, display spoofing, and other threats
- Threat Response: Identifying, analyzing, and mitigating security issues and taking appropriate action to protect systems and data from potential harm
- VPN: Extend virtual private network over public networks to enable protected information exchange
- Vulnerability Assessment: The process of identifying, quantifying, and prioritizing the vulnerabilities in a system.
- Vulnerability Protection: Safeguards to protect network vulnerabilities
- Vulnerability Scanning: Discover patch statuses and vulnerabilities
- Vulnerability/Threat Prioritization: Classify levels of threat and organize actions based on priorities
- Web-Application Security: Identify and respond to security threats to web applications
- Website Crawling: Crawling and indexing web pages

---

Features

4.5 (2)

4.5

Based on 2 reviews

## Pricing

Value for money

5.0 (2)

Value for money

5.0 (2)

5.0

Based on 2 reviews

## Support, customer service and training options

Customer Service

4.0 (2)

Support

-   Email/Help Desk
-   FAQs/Forum
-   Knowledge Base
-   Phone Support
-   24/7 (Live rep)
-   Chat

Training

-   In Person
-   Live Online
-   Webinars
-   Documentation
-   Videos

Deployment

-   Web
-   Android
-   iPhone/iPad

Typical users

-   Freelancers
-   Small businesses
-   Mid size businesses
-   Enterprises

Customer Service

4.0 (2)

4.0

Based on 2 reviews

## User reviews

Overall rating

4.0

Based on 2 reviews

Filter by rating

5(0)

4(2)

3(0)

2(0)

1(0)

Mentioned topic

Sorted by most recent

DC

Damien C.

DevSecOps

Information Technology and Services

### "Open source gem"

4.0

Overall Rating

4.0

4.0

Ease of Use

5.0

5.0

Features

5.0

5.0

Customer Service

5.0

5.0

Likelihood to Recommend

9/10

February 13, 2021

Pros

DefectDojo is easy to setup/configure and accept a lot of different data. It's easy to integrate it to a big organization/ecosystem. The team behind it is very responsive regarding maintaining/fixing bug in the core features . Big plus issue management/support have a lot of media (Slack, ticketing system, HackerOne program...)

Cons

Even if the team behing it fix most of the bug fast, it's an open source project so sometimes some fixes takes 1 month to big fixed.

Alternatives considered

[Kiuwan](https://www.capterra.com/p/160729/Kiuwan-Code-Security/)

Reasons for choosing DefectDojo

Price and easy to use

Review source

Non-incentivized review: any software user can leave a review for any product listed on our site. All submitted reviews are subject to our verification process prior to publication.

Elyes C.

Application Security Engineer

Information Technology and Services

### "DefectDojo Review"

4.0

Overall Rating

4.0

4.0

Ease of Use

5.0

5.0

Features

4.0

4.0

Customer Service

3.0

3.0

Likelihood to Recommend

8/10

September 8, 2020

Pros

DefectDojo gives to professional people the ability to integrate different scan results in one place, also the dockerized solution is easy to use

Cons

As DefectDojo is an open source solution, in case of problem you need to raise an issue on github and there is no dedicated plateform for issues resolution

Review source

Non-incentivized review: any software user can leave a review for any product listed on our site. All submitted reviews are subject to our verification process prior to publication.

## Top-rated software of 2026

### Fill out the form and we'll send a list of the top-rated software based on real user reviews directly to your inbox.