New Relic IAST probes running application code to identify vulnerabilities that could be exploited, helping DevOps and security teams address risk during software development. Dynamic assessment simulates attacks and can provide evidence of an exploit without code changes. New Relic APM agents deliver the feature, which can be enabled through a configuration setting. It supports Go, Java, Node.js, and Ruby, along with authenticated and API testing. Findings receive CVSS version 3 severity ratings from Low to Critical. Guided remediation can show the code location, stack and HTTP traces, URLs encountered, exploit mechanism, and parameters. Integration with New Relic Vulnerability Management supports ongoing discovery, fixing, and verification of high-risk issues; CI/CD pipelines and ticketing systems are also supported. The web-based service is designed to reduce false positives compared with traditional application security tools. A free plan is available. IAST analysis is billed through an optional Compute Add On according to Compute Capacity Units consumed, and other pricing is available on request.
Who it is for
New Relic IAST suits DevOps and security teams seeking continuous application security testing across the software development lifecycle. It supports teams working in Go, Java, Node.js, or Ruby.
What is good
- Attack simulation can provide exploit evidence without code changes.
- Guided remediation surfaces code locations, traces, URLs, and parameters.
- Integrated with New Relic Vulnerability Management.
- Supports CI/CD pipelines and ticketing systems.
What to know first
- Supported languages are Go, Java, Node.js, and Ruby.
- IAST analysis uses a billed optional Compute Add On.
- Pricing beyond the free plan is available on request.
Verdict
New Relic IAST combines runtime vulnerability detection with exploit evidence and guided remediation. Teams should account for the supported language list and usage-based Compute Add On billing.
New Relic IAST plans and pricing
All plansCompared on interactive application security testing software
- Free plan
- No
- Runtime targets
- web
- Deployment
- saas
- Authenticated testing
- Yes
- API testing
- Yes
- Instrumentation
- agent
- CI/CD integration
- Yes
- Language coverage
- Go, Java, Node.js, Ruby




