We performed a comparison between Klocwork and Qualys Web Application Scanning based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."On-the-fly analysis and incremental analysis are the best parts of Klocwork. Currently, we are using both of these features very effectively."
"There's a feature in Klocwork called 'on-the-fly analysis', which helps developers to find and fix the defects at the time of development itself."
"Klocwork's most valuable feature is the static code analysis feature. It detects the potential problem earlier to allow the developer to receive feedback quickly and then address it before it becomes a problem."
"The most valuable feature is the Incremental analysis."
"I like not having to dig through false positives. Chasing down a false positive can take anywhere from five minutes for a small easy one, then something that is complicated and goes through a whole bunch of different class cases, and it can take up to 45 minutes to an hour to find out if it is a false positive or not."
"The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time."
"Technical support is quite good."
"It's integrated into our CI, continuous integration."
"With our vulnerabilities under control, it's putting our services in compliance and minimizing our risk for exposure."
"QualysGuard web-based scanner is very useful for performing external penetration and PCI scans from remote locations."
"It is a good product for website penetration testing to detect vulnerabilities."
"It is easy to use."
"Qualys' process of updating signatures is something we really appreciate, and it's way ahead of its industry peers."
"The feature that I have found most valuable is the progressive scan. It is good. It's done in 24 hours."
"We can do scanning and submit reports straight to the customers when there are new vulnerabilities, then tell them whether they are affected or not."
"The vulnerability management feature is a strong one. And also the patch management feature."
"We'd like to see integration with Agile DevOps and Agile methodologies."
"The main problem is that since it only parses the code, the warnings or the problems that are given as a result of the report can sometimes require a lot of effort to analyze."
"We bought Klocwork, but it was limited to one little program, but the program is now sort of failing. So, we have a license for usage on a program that is sort of failing, and we really can't use the license on anything else."
"I believe it should support more languages, such as Python and JavaScript."
"I hope that in each new release they add new features relating to the addition of checkers, improving their analysis engines etc."
"The way to define the rules is too complex. The definition/rules for static analysis could be automated according to various SILs, so as to avoid confusion."
"This solution could be improved if they offered support of more languages including Ada and Golang. They currently only support seven languages."
"What needs improvement in Klocwork, compared to other products in the market, is the dashboard or reporting mechanisms that need to be a bit more flexible. The Klocwork dashboard could be improved. Though it's good, it's not as good as some of the other products in the market, which is a problem. The reporting could be more detailed and easier to sort out because sorting in Klocwork could be a bit more time-consuming, mainly when sorting defects based on filters, compared to how it's done on other tools such as Coverity."
"Deployment can be complicated."
"There should be better visibility into the application."
"The product's pricing could be better."
"The scanner reports a lot of false positives, which is something that needs to be improved."
"The reporting contains too many false positives."
"There's a distinction between internal and external scanning processes that could be streamlined. Currently, for internal scanning, specific configurations and scanner appliances need to be deployed within the network, which differs from the simpler setup for external scans. This dual process complicates the setup for comprehensive scanning coverage."
"The GUI could be a little less complicated as it opens a lot of new windows for creating search lists, templates, reports, or for scanning purposes."
"There could be better management and faster scanning."
More Qualys Web Application Scanning Pricing and Cost Advice →
Klocwork is ranked 16th in Application Security Tools with 20 reviews while Qualys Web Application Scanning is ranked 19th in Application Security Tools with 31 reviews. Klocwork is rated 8.2, while Qualys Web Application Scanning is rated 7.8. The top reviewer of Klocwork writes "Their technical team helps us get the most out of the solution, but we've faced some stability problems in our environment". On the other hand, the top reviewer of Qualys Web Application Scanning writes "A stable solution that can be used for infrastructure vulnerability scanning and web application scanning". Klocwork is most compared with SonarQube, Coverity, Polyspace Code Prover, CodeSonar and Checkmarx One, whereas Qualys Web Application Scanning is most compared with OWASP Zap, Veracode, SonarQube, PortSwigger Burp Suite Professional and Fortify WebInspect. See our Klocwork vs. Qualys Web Application Scanning report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.