Suggestions appear as you type. Use the up and down arrows to choose one and Enter to open it.

This page's audience real numbers from our own analytics — open to see them
–Visitors
–Page views
–Clicks to vendors
–Time on page
–Reading now
Clicks to vendors, by tool
  • –
Top countries
  • –
Devices
  • –

– · counted by iTechGuides's own first-party analytics, bots removed, every figure rounded down · how we count

Veracode DAST review

#17 of 26 in Dynamic Application Security Testing Software

A managed DAST option for authenticated web and API testing behind firewalls.

7.8/10Editor score
Veracode DAST7.8 Visit Veracode

Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026

Veracode DAST is a cloud-based dynamic application security testing product for security and development teams. It analyzes running web applications and REST APIs for runtime vulnerabilities, including single-page applications, multi-page applications, and API specifications. Teams can run authenticated or unauthenticated analyses, making it suitable for environments where testing both public and protected application paths matters. The product is delivered through the Veracode Platform and is designed for organizations that want managed DAST across web and API assets.

Its strongest differentiator is coverage for applications and APIs behind firewalls through Internal Scanning Management. That makes the product relevant to teams whose testing targets are not publicly reachable. Scan behavior is configurable, with quick or full scans and invasive or non-invasive options. Scheduled and automated analyses support recurring security checks, while real-time vulnerability findings and remediation guidance help connect discovery with follow-up work. Policy management and reporting add a governance layer for teams that need to organize findings and communicate results.

Veracode DAST also fits development workflows through CI/CD pipeline integration and REST API automation. The integration model centers on the Veracode Platform and REST API, rather than an open-source distribution. Pricing is handled through sales, so the product is better suited to teams evaluating a managed security platform than buyers looking for a self-service entry plan. Choose it when authenticated testing, API analysis, internal scanning, and workflow automation are priorities. Consider another option if you specifically need an open-source edition or a self-serve purchase path.

Veracode DAST pros and cons

  • Where it wins
    • Authenticated and unauthenticated scanning for web applications and APIs
    • Internal Scanning Management supports targets behind firewalls
    • Scheduled scans, CI/CD integration, and REST API automation
  • Where it doesn't
    • Pricing is handled through sales rather than a self-serve plan
    • Internal targets require Internal Scanning Management
    • No open-source edition is offered

Veracode DAST fact sheet, pricing and score →

Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.

Last updated · How we research and update