New Relic IAST probes running application code to identify vulnerabilities that could be exploited. Its dynamic assessment simulates attacks and can provide proof of exploit without code changes. New Relic APM agents deliver the capability, which teams can enable through a configuration change; supported languages are Go, Java, Node.js, and Ruby. Guided remediation can identify code locations, stack and HTTP traces, URLs, exploit mechanisms, and parameters. Findings receive CVSS version 3 severity ratings from Low to Critical. IAST is integrated with New Relic Vulnerability Management to find, fix, and verify high-risk vulnerabilities across the software development lifecycle. It supports authenticated and API testing, along with CI/CD and ticketing integrations. The tool is intended for DevOps and security teams seeking continuous application security testing. A free New Relic plan is listed, while IAST analysis is billed through an optional Compute Add On based on Compute Capacity Units consumed. Other pricing is available on request.
Who it is for
New Relic IAST suits DevOps and security teams looking for continuous application security testing across the software development lifecycle. Supported languages are Go, Java, Node.js, and Ruby.
What is good
- Can show proof of exploit without code changes.
- Guided remediation identifies traces and exploit details.
- Supports authenticated and API testing.
- Integrates with CI/CD pipelines and ticketing systems.
What to know first
- IAST billing depends on Compute Capacity Units consumed.
- Pricing is available on request.
- Supported languages are Go, Java, Node.js, and Ruby.
Verdict
New Relic IAST combines attack simulation with remediation details and integration into vulnerability management workflows. Teams should account for its optional Compute Add On billing and check that their application uses a supported language.
New Relic IAST plans and pricing
All plansCompared on interactive application security testing software
- Free plan
- No
- Runtime targets
- web
- Deployment
- saas
- Authenticated testing
- Yes
- API testing
- Yes
- Instrumentation
- agent
- CI/CD integration
- Yes
- Language coverage
- Go, Java, Node.js, Ruby




