Checkmarx Software Composition Analysis vs Fortify Static Code Analyzer comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx Software Composit...
Average Rating
9.2
Number of Reviews
12
Ranking in other categories
Software Composition Analysis (SCA) (8th)
Fortify Static Code Analyzer
Average Rating
8.4
Number of Reviews
15
Ranking in other categories
Static Code Analysis (3rd)
 

Market share comparison

As of June 2024, in the Software Composition Analysis (SCA) category, the market share of Checkmarx Software Composition Analysis is 4.0% and it decreased by 16.8% compared to the previous year. The market share of Fortify Static Code Analyzer is 17.9% and it decreased by 10.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Software Composition Analysis (SCA)
Unique Categories:
No other categories found
Static Code Analysis
27.6%
 

Featured Reviews

DS
Sep 1, 2023
Identified and fixed security vulnerabilities in our code, such as a SQL injection vulnerability.
To make the list of the vulnerabilities more clear and exposed to the users in order to see. Sometimes, we see issues high-level issues vulnerabilities that are not really issues, the interpretation of scanning. Meaning, like, outside, it's not really the issue. But it surfaces as an issue, so we probably may have a database of the errors of the vulnerabilities to expose and maybe even provide some feedback on how valuable the vulnerability is. I'm doing that. So, basically, one area that could be improved is the way that false positives are handled. In future releases, if we could create a clear RESTful API to just extract the scanning data on user-added applications and presentations.
DJ
May 7, 2024
Helps us identify vulnerabilities, but the upgrading process needs improvement
Our primary use case for this solution is to analyze the security of our software applications during the development cycle. We use it to identify vulnerabilities and potential security issues before deploying the applications into production. Our environment comprises various software development…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of Checkmarx Software Composition Analysis is the comprehensive security scan."
"The customer service and support were good."
"What's most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in open-source components, especially if some critical issues exist."
"The product is stable and scalable."
"I appreciate the user-friendly interface. The GUI is excellent, providing detailed information on outdated versions, including version numbers and the flow of library calls. This allows me to plan and prioritize library changes based on potential vulnerabilities, even if the affected library is indirectly used in my project. The tool offers specific guidance on addressing these issues."
"One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good. It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely."
"The integration part is easy...It's a stable solution right now."
"It is a stable solution...It is a scalable solution."
"Its flexibility is most valuable. It is such a flexible tool. It can be implemented in a number of ways. It can do anything you want it to do. It can be fully automated within a DevOps pipeline. It can also be used in an ad hoc, special test case scenario and anywhere in between."
"We write software, and therefore, the most valuable aspect for us is basically the code analysis part."
"Automating the Jenkins plugins and the build title is a big plus."
"The reference provided for each issue is extremely helpful."
"Fortify integrates with various development environments and tools, such as IDEs (Integrated Development Environments) and CI/CD pipelines."
"It's helped us free up staff time."
"The Software Security Center, which is often overlooked, stands out as the most effective feature."
"I like the Fortify taxonomy as it provides us with a list of all of the vulnerabilities found. Fortify release updated rule packs quarterly, with accompanying documentation, that lets us know what new features are being released."
 

Cons

"The quality of technical support has decreased over time, and it is not as good as it used to be."
"Parts of the implementation process could improve by making it more user-friendly."
"In terms of areas for improvement, what could be improved in Checkmarx Software Composition Analysis is pricing because customers always compare the pricing among secure DevOps solutions in the market. Checkmarx Software Composition Analysis has a lot of competitors yet its features aren't much different. Pricing is the first thing customers consider, and from a partner perspective, if you can offer affordable pricing to your customers, it's more likely you'll have a winning deal. The performance of Checkmarx Software Composition Analysis also needs improvement because sometimes, it's slow, and in particular, scanning could take several hours."
"I have received complaints from my customers that the pricing could be improved."
"Some of the recommendations provided by the product are generic. Even if the recommendations provided by the product are of low level, the appropriate ones can help users deal with vulnerabilities."
"API security is an area with shortcomings that needs improvement."
"It can have better licensing models."
"Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved."
"Fortify Static Code Analyzer has a bit of a learning curve, and I don't find it particularly helpful in narrowing down the vulnerabilities we should prioritize."
"The generation of false positives should be reduced."
"Fortify Static Code Analyzer is a good solution, but sometimes we receive false positives. If they could reduce the number of false positives it would be good."
"It comes with a hefty licensing fee."
"The price can be improved."
"Streamlining the upgrade process and enhancing compatibility would make it easier for us to keep our security tools up-to-date."
"Fortify's software security center needs a design refresh."
"Their licensing is expensive."
 

Pricing and Cost Advice

"The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
"My customers need to pay for the licensing part, and they need to opt for an annual subscription."
"Pricing for Checkmarx Software Composition Analysis needs to be competitive."
"It is a little bit high priced. It would be better if it was a little less expensive."
"We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
"There is a licensing fee, and if you bring them to the company and you want them to do the installation and the implementation in the beginning, there is a separate cost. Similarly, if you want consultation or training, there is a separate cost. I see it as suitable only for enterprises. I do not see it suitable for a small business or individual use."
"The price of Fortify Static Code Analyzer could be reduced."
"Although I am not responsible for the budget, Fortify SAST is expensive."
"It has a couple of license models. The one that we use most frequently is called their flexible deployment. We use this one because it is flexible and based on the number of code-contributing developers in the organization. It includes almost everything in the Fortify suite for one developer price. It gives access to not just the secure code analyzer (SCA) but also to FSC, the secure code. It gives us accessibility to scan central, which is the decentralized scanning farm. It also gives us access to the software security center, which is the vulnerability management platform."
"The licensing is expensive and is in the 50K range."
"From our standpoint, we are significantly better off with Fortify due to the favorable pricing we secured five years ago."
"The setup costs and pricing for Fortify may vary depending on the organization's needs and requirements."
report
Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
787,383 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
38%
Manufacturing Company
13%
Computer Software Company
12%
Healthcare Company
4%
Financial Services Firm
28%
Computer Software Company
14%
Manufacturing Company
10%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Checkmarx Software Composition Analysis?
The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all...
What is your experience regarding pricing and costs for Checkmarx Software Composition Analysis?
We have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage.
What needs improvement with Checkmarx Software Composition Analysis?
Checkmarx Software Composition Analysis should improve dynamic analysis.
What do you like most about Fortify Static Code Analyzer?
Integrating the Fortify Static Code Analyzer into our software development lifecycle was straightforward. It highlights important information beyond just syntax errors. It identifies issues like pa...
What needs improvement with Fortify Static Code Analyzer?
The product shows false positives for Python applications.
 

Also Known As

CxSCA
Fortify Static Code Analysis SAST
 

Overview

 

Sample Customers

AXA, Liveperson, Aaron's, Playtech, Morningstar
Information Not Available
Find out what your peers are saying about Synopsys, Veracode, Snyk and others in Software Composition Analysis (SCA). Updated: May 2024.
787,383 professionals have used our research since 2012.