We performed a comparison between Checkmarx One and Coverity based on real PeerSpot user reviews.
Find out in this report how the two Application Security Testing (AST) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."It is a stable product."
"The most valuable features are the easy to understand interface, and it 's very user-friendly."
"The most valuable feature is the application tracking reporting."
"The UI is user-friendly."
"The UI is very intuitive and simple to use."
"The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
"Most valuable features include: ease of use, dashboard. interface and the ability to report."
"The solution allows us to create custom rules for code checks."
"It's very stable."
"This solution is easy to use."
"The product is easy to use."
"Coverity is scalable."
"It has the lowest false positives."
"The solution effectively identifies bugs in code."
"Coverity gives advisory and deviation features, which are some of the parts I liked."
"The product has deeper scanning capabilities."
"Meta data is always needed."
"Checkmarx reports many false positives that we need to manually segregate and mark “Not exploitable”."
"Checkmarx could improve the REST APIs by including automation."
"One area for improvement in Checkmarx is pricing, as it's more expensive than other products."
"It provides us with quite a handful of false positive issues. If Checkmarx could reduce this number, it would be a great tool to use."
"Checkmarx could improve the solution reports and false positives. The false positives could be reduced. For example, we have alerts that are tagged as vulnerabilities but when you drill down they are not."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"I would like to see the tool’s pricing improved."
"SCM integration is very poor in Coverity."
"Sometimes, vulnerabilities remain unidentified even after setting up the rules."
"It should be easier to specify your own validation routines and sanitation routines."
"The tool needs to improve its reporting."
"The solution could use more rules."
"We use GitHub and Gitflow, and Coverity does not fit with Gitflow. I have to create a screen for our branches, and it's a pain for developers. It has been difficult to integrate Coverity with our system."
"We'd like it to be faster."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
Checkmarx One is ranked 3rd in Application Security Testing (AST) with 67 reviews while Coverity is ranked 4th in Application Security Testing (AST) with 33 reviews. Checkmarx One is rated 7.6, while Coverity is rated 7.8. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of Coverity writes "Best SAST tool to check software quality issues". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand, Snyk and Mend.io, whereas Coverity is most compared with SonarQube, Klocwork, Fortify on Demand, Veracode and Polyspace Code Prover. See our Checkmarx One vs. Coverity report.
See our list of best Application Security Testing (AST) vendors.
We monitor all Application Security Testing (AST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.