shouldiuse.io

Categories

VERDICT

Should I use Rapid7?

Rapid7 Managed Cybersecurity: Outpace Attackers - rapid7.com

Depends. Buy if you're a mid-size or large org with dedicated security staff needing vulnerability management, SIEM, or MDR under one roof. Skip it if you're a small team or startup — pricing is quote-based and lighter tools will cover you.

Confidence

Medium. Based on 20+ public sources: G2/Gartner reviews, Reddit threads, security disclosures, pricing guides, and company data. Snippets were truncated, so some review detail is limited.

Ratings

  • Value for moneyNo published pricing in evidence
  • Ease of useNo direct usability evidence
  • Feature depth
  • Support qualityNo support evidence found
  • Security posture

Pricing

Not disclosed

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Mid-to-large security teams
  • Vulnerability management at scale
  • Orgs wanting MDR + SIEM combined
  • PCI/compliance-driven environments

Not for

  • Small teams needing a simple vulnerability scanner
  • Startups without dedicated security staff
  • Buyers wanting self-serve, transparent pricing
  • Solo devs who just need quick app scanning

Gotchas - check before you buy

medium

No public pricing; use third-party guides to budget before talking to sales.

medium

18% layoffs (2023) and takeover reports raise stability and roadmap questions.

low

Codecov supply-chain breach (2021) touched Rapid7 code; ask about current practices.

Pros and cons

Pros

  • Covers vulnerability management, SIEM, MDR, AppSec, and cloud security in one platform
  • Maintains a public vulnerability and exploit database used by the security community
  • Rated 4+ out of 5 across 264 G2 reviews
  • Established vendor: founded 2000, publicly traded, roughly $856M estimated revenue
  • Publishes fast analysis of actively exploited zero-days

Cons

  • No transparent pricing; third-party guides needed to estimate costs
  • Laid off 18% of staff amid takeover reports
  • Disclosed a 2021 supply-chain breach via Codecov
  • InsightAppSec faces developer-first alternatives like StackHawk

Sources & method

Analyzed 10/05/2026 - 12 sources - Established security vendor with an active research arm; one disclosed 2021 supply-chain (Codecov) breach, no newer incidents in sources reviewed.

official x1review x5security x2news x4
  • Supply-chain breach via Codecov (2021), Rapid7 disclosed attackers accessed its source code through the Codecov incident in May 2021.

Key stats

  • Feature depth: 5/5

    Rating

  • Not disclosed

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money. No published pricing in evidence
  • Ease of use. No direct usability evidence
  • Feature depth: 5/5. VM, SIEM, MDR, AppSec, cloud, GRC all covered
  • Support quality. No support evidence found
  • Security posture: 3/5. Strong research arm; 2021 Codecov supply-chain breach
  • 4+/5 G2 seller rating 264 reviews on G2
  • 2000 Founded Publicly traded (RPD)
  • $855.9M Est. annual revenue Growjo/Owler estimate
  • 14 markets Gartner review coverage Vulnerability assessment and more

Pricing

Not disclosed

Security

Established security vendor with an active research arm; one disclosed 2021 supply-chain (Codecov) breach, no newer incidents in sources reviewed.

  • Supply-chain breach via Codecov (2021)Rapid7 disclosed attackers accessed its source code through the Codecov incident in May 2021.⁵

What users say

G2 and Gartner reviewers rate Rapid7 around 4 out of 5, while Reddit security practitioners frequently weigh it against Tenable, Qualys, and eSentire.

Alternatives

Compare Rapid7 with each alternative.

  • eSentire MDR

    Managed detection alternative if you want outsourced response.

Companies that use it

  • Bob's Stores
  • Stein Mart
  • Acosta Sales & Marketing
  • Eyelock
Full analysis

Based on 20+ public sources: G2/Gartner reviews, Reddit threads, security disclosures, pricing guides, and company data. Snippets were truncated, so some review detail is limited.

Enterprise security platform (VM, SIEM, MDR, AppSec). Right for staffed SecOps; overkill for small teams.

Methodology

Based on 20+ public sources: G2/Gartner reviews, Reddit threads, security disclosures, pricing guides, and company data. Snippets were truncated, so some review detail is limited.

Sources

  1. review
  2. review
  3. review
  4. review
  5. security
  6. security
  7. official
  8. news
  9. news
  10. news
  11. news
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.