We performed a comparison between Checkmarx One and Fortify WebInspect based on real PeerSpot user reviews.
Find out in this report how the two DevSecOps solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The UI is user-friendly."
"One of the most valuable features is it is flexible."
"The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
"The report function is the solution's greatest asset."
"The most valuable features of Checkmarx are the automation and information that it provides in the reports."
"The solution has good performance, it is able to compute in 10 to 15 minutes."
"The solution improved the efficiency of our code security reviews. It helps tremendously because it finds hundreds of potential problems sometimes."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"The most valuable feature of this solution is the ability to make our customers more secure."
"When we are integrating it with SSC, we're able to scan and trace and see all of the vulnerabilities. Comparison is easy in SSC."
"It is scalable and very easy to use."
"It's a well-known platform for doing dynamic application scanning."
"There are lots of small settings and tools, like an HTTP editor, that are very useful."
"Technical support has been good."
"The solution is able to detect a wide range of vulnerabilities. It's better at it than other products."
"I've found the centralized dashboard the most valuable. For the management, it helps a lot to have abilities at the central level."
"Meta data is always needed."
"Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
"The integration could improve by including, for example, DevSecOps."
"Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
"Checkmarx is not good because it has too many false positive issues."
"The pricing can get a bit expensive, depending on the company's size."
"Micro-services need to be included in the next release."
"The cost per user is high and should be reduced."
"The installation could be a bit easier. Usually it's simple to use, but the installation is painful and a bit laborious and complex."
"The initial setup was complex."
"Our biggest complaint about this product is that it freezes up, and literally doesn't work for us."
"Fortify WebInspect could improve user-friendliness. Additionally, it is very bulky to use."
"Fortify WebInspect's shortcoming stems from the fact that it is a very expensive product in Korea, which makes it difficult for its potential customers to introduce the product in their IT environment."
"Creating reports is very slow and it is something that should be improved."
"It took us between eight and ten hours to scan an entire site, which is somewhat slow and something that I think can be improved."
"Not sufficiently compatible with some of our systems."
Checkmarx One is ranked 2nd in DevSecOps with 67 reviews while Fortify WebInspect is ranked 8th in DevSecOps with 17 reviews. Checkmarx One is rated 7.6, while Fortify WebInspect is rated 7.0. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of Fortify WebInspect writes "A powerful tool catering to multiple use cases that provides reasonably good technical support". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand and Snyk, whereas Fortify WebInspect is most compared with PortSwigger Burp Suite Professional, Fortify on Demand, Acunetix, OWASP Zap and Rapid7 InsightAppSec. See our Checkmarx One vs. Fortify WebInspect report.
See our list of best DevSecOps vendors.
We monitor all DevSecOps reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.