We compared SonarQube and Klocwork based on our user's reviews in several parameters.
SonarQube is lauded for its versatility, simplicity, and integration capabilities, offering comprehensive features and usability enhancements. Users praise its customer service and support, reasonable pricing, and positive ROI. Klocwork is valued for its code analysis, real-time notifications, integration options, and reporting functionality. Both tools have areas for improvement such as analysis speed and user interface refinement.
Features: SonarQube offers valuable features such as support for multiple languages, integration with DevOps pipelines, and comprehensive code quality parameters. On the other hand, Klocwork focuses on code analysis capabilities, real-time notifications, and comprehensive reporting functionality.
Pricing and ROI: SonarQube's setup cost is considered straightforward and easy, with users appreciating the simplicity of the process. In contrast, user thoughts on Klocwork's setup cost remain unspecified, leaving uncertainty about its ease and simplicity., SonarQube's ROI lies in its ability to improve code quality, efficiency, and project success, while Klocwork's ROI is indicated by positive user reviews.
Room for Improvement: Areas for improvement in SonarQube include enhancing analysis speed, refining user interface for better navigation, clearer instructions for setup and configuration, improving documentation for advanced functionalities, addressing occasional performance issues, and enhancing integration options. Users have provided suggestions for improvement and identified aspects that require attention in Klocwork.
Deployment and customer support: Based on user feedback, SonarQube takes an average of three months for deployment and one week for setup, while Klocwork varies with some users taking three months for deployment and one week for setup, and others taking one week for both deployment and setup., SonarQube's customer service stands out with exceptional support, prompt and knowledgeable assistance, responsiveness, and willingness to go above and beyond. Users have expressed confidence in its reliability and added value. On the other hand, Klocwork's customer service has been highly praised for excellent assistance, prompt and attentive response, knowledge and expertise, reliable support, effective solutions, and commitment to customer satisfaction.
The summary above is based on 40 interviews we conducted recently with SonarQube and Klocwork users. To access the review's full transcripts, download our report.
"We like using the static analysis and code refactoring, which are very valuable because of our requirements to meet safety critical levels and reliability."
"It's integrated into our CI, continuous integration."
"The tool helps the team to think beforehand about corner cases or potential bugs that might arise in real-time."
"The most valuable feature of Klocwork is finding defects while you're doing the coding. For example, if you have an IDE plug-in of Klocwork on Visual Studio or Eclipse, you can find the faults; similar to using spell check on Word, you can find out defects during the development phase, which means that you don't have to wait till the development is over to find the flaws and address the deficiencies. I also find language support in Klocwork good because it used to support only C, C++, C#, and Java, but now, it also supports Java scripts and Python."
"There is a central Klocwork server at our headquarter in France so we connect the client directly to the server on-premises remotely."
"Klocwork's most valuable feature is the static code analysis feature. It detects the potential problem earlier to allow the developer to receive feedback quickly and then address it before it becomes a problem."
"I like not having to dig through false positives. Chasing down a false positive can take anywhere from five minutes for a small easy one, then something that is complicated and goes through a whole bunch of different class cases, and it can take up to 45 minutes to an hour to find out if it is a false positive or not."
"On-the-fly analysis and incremental analysis are the best parts of Klocwork. Currently, we are using both of these features very effectively."
"There's plenty of documentation available to users."
"With SonarQube's web interface, it is easy to drill down to see the individual problems, but also to look at the project from above and get the big picture, with possible larger problem areas."
"It provides the security that is required from a solution for financial businesses."
"It is an easy tool that you can deploy and configure. After that you can measure the history of your obligation and integrate it with other tools like GitLab or GitHub or Azure DevOps to do quality code analysis."
"The most valuable features are the dashboard reports and the ease of integrating it with Jenkins."
"The most valuable features are the wide array of languages, multiple languages per project, the breakdown of bugs, and the description of vulnerabilities and code smells (best practices)."
"The most valuable feature is the security hotspot feature that identifies where your code is prone to have security issues."
"The most valuable feature of SonarQube I have found to be the configuration that has allowed us to can make adjusts to the demands of the code review. It gives a specified classification regarding the skill, prioritization, and it is easy for me to review and make my code."
"The way to define the rules is too complex. The definition/rules for static analysis could be automated according to various SILs, so as to avoid confusion."
"Now the only issue we have is that whenever we need to get the code we have to build it first. Then we can get the report."
"Klocwork has to improve its features to stay ahead of other free solutions."
"I would like to see better codes between projects and a more user-friendly desktop in the next release."
"We'd like to see integration with Agile DevOps and Agile methodologies."
"We bought Klocwork, but it was limited to one little program, but the program is now sort of failing. So, we have a license for usage on a program that is sort of failing, and we really can't use the license on anything else."
"I hope that in each new release they add new features relating to the addition of checkers, improving their analysis engines etc."
"Modern languages, such as Angular and .NET, should be included as a part of Klocwork. They have recently added Kotlin as a part of their project, but we would like to see more languages in Klocwork. That's the reason we are using Coverity as a backup for some of the other languages."
"The solution could improve the management reports by making them easier to understand for the technical team that needs to review them."
"It would be better if SonarQube provided a good UI for external configuration."
"We found a solution with dynamic testing, and are looking to find a solution that can be used for both types of testing."
"The solution could improve by providing more advanced technologies."
"SonarQube could improve its static application security testing as per the industry standard."
"The product needs to integrate other security tools for security scanning."
"The reporting can be improved."
"There could be better integration with other products."
Klocwork is ranked 18th in Application Security Tools with 20 reviews while SonarQube is ranked 1st in Application Security Tools with 108 reviews. Klocwork is rated 8.2, while SonarQube is rated 8.0. The top reviewer of Klocwork writes "Their technical team helps us get the most out of the solution, but we've faced some stability problems in our environment". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". Klocwork is most compared with Coverity, Polyspace Code Prover, CodeSonar, Checkmarx One and Veracode, whereas SonarQube is most compared with Checkmarx One, SonarCloud, Coverity, Veracode and CAST Highlight. See our Klocwork vs. SonarQube report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.