Checkmarx One vs Parasoft SOAtest comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Number of Reviews
67
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (11th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Parasoft SOAtest
Ranking in Static Application Security Testing (SAST)
29th
Average Rating
8.2
Number of Reviews
30
Ranking in other categories
Functional Testing Tools (24th), API Testing Tools (9th), Test Automation Tools (21st)
 

Market share comparison

As of June 2024, in the Static Application Security Testing (SAST) category, the market share of Checkmarx One is 10.2% and it decreased by 20.5% compared to the previous year. The market share of Parasoft SOAtest is 0.4% and it increased by 12.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
Unique Categories:
Application Security Tools
13.2%
Vulnerability Management
1.3%
Functional Testing Tools
0.5%
API Testing Tools
2.4%
 

Featured Reviews

RB
Jul 11, 2022
Useful automation , detailed reports, but scalability could improve
We use Checkmarx as a code analysis tool We have always used some kind of code analysis tool and Checkmarx has been working for us at this time. We like the tool. The most valuable feature of Checkmarx are the automation and information that it provides in the reports. I am using Checkmarx for…
Milind Parab - PeerSpot reviewer
Jan 3, 2023
Useful for automated SQA, certifications, but the summary reports could improve
The summary reports could be improved because sometimes it is not very concise. The waiver process can also be improved because Parasoft SQAtest doesn't have a method to waive off one rule. Additionally, adding some guidance on providing standard templates could be helpful for new engineers or in complexity reduction. It could be sustained in a better way because it currently just gives the number that is a level of looping or callings. Hence, if something can be improved to refactor the code, then it should be code restructuring and all the information that can be provided to look at the complexity of the code.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes."
"The solution communicates where to fix the issue for the purpose of less iterations."
"It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
"The only thing I like is that Checkmarx does not need to compile."
"It shows in-depth code of where actual vulnerabilities are."
"Scan reviews can occur during the development lifecycle."
"We use the solution to validate the source code and do SAST and security analysis."
"The most valuable feature is that it actually identifies the different criteria you can set to meet whatever standards you're trying to get your system accredited for."
"Since the solution has both command line and automation options, it generates good reports."
"The solution is scalable."
"Every imaginable source in the entire world of information technology can be accessed and used."
"We have seen a return on investment."
"They have a feature where they can record traffic and create tests on the report traffic."
"Technical support is helpful."
"If you want something that’s not provided out of the box, then you can write it yourself and integrate it with SOAtest."
"The testing time is shortened because we generate test data automatically with SOAtest."
 

Cons

"Checkmarx needs to improve the false positives and provide more accuracy in identifying vulnerabilities. It misses important vulnerabilities."
"The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."
"If it is a very large code base then we have a problem where we cannot scan it."
"The pricing can get a bit expensive, depending on the company's size."
"Updating and debugging of queries is not very convenient."
"You can't use it in the continuous delivery pipeline because the scanning takes too much time."
"Checkmarx has a slightly difficult compilation with the CI/CD pipeline."
"I think the CxAudit tool has room for improvement. At the beginning you can choose a scan of a project, but in any event the project must be scanned again (wasting time)."
"UI testing should be more in-depth."
"Reporting facilities can be better."
"Parasoft SOAtest has an internal refresh function where you can refresh the software to show the changes you’ve made in your projects. Unfortunately this function does not work properly, because it often does not show the changes after you’ve hit te refresh button a few times."
"Reports could be customized and more descriptive according to the user's or company's requirements."
"The feedback that we received from the DevOps of our organization was that the tool was a little heavy from the transformation perspective."
"From an automation point of view, it should have better clarity and be more user friendly."
"The performance could be a bit better."
"Enabling/disabling an optional element of an XML request is only possible if a data source (e.g., Excel sheet) is connected to the test. Otherwise, the option is not available at all in the drop-down menu."
 

Pricing and Cost Advice

"It is a good product but a little overpriced."
"We have a subscription license that is on a yearly basis, and it's a pretty competitive solution."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"We got a special offer for a 30% reduction for three years, after our first year. I think for a real source-code scanning tool, you have to add a lot of money for Open Source Analysis, and AppSec Coach (160 Euro per user per year)."
"The solution's price is high and you pay based on the number of users."
"The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security."
"We have purchased an annual license to use this solution. The price is reasonable."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"We are completed satisfied with Parasoft SOAtest. The ROI is more than 95%."
"The license price is a little expensive, but it provides a better outcome in terms of the end-to-end automation process."
"The cost of Parasoft seems to have gotten higher with a projection that wasn't really stipulated for our company. They've done a tremendous job at negotiating those deals."
"It is an expensive product, so think carefully about whether it fits your purposes and is the right tool for you."
"They do have a confusing licensing structure."
"From what I understand, Parasoft SOAtest isn't the cheapest option. But it has a lot to offer."
"The price is around $5,000 USD."
"I think it would be a great step to decrease the price of the licenses."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
9%
Insurance Company
5%
Financial Services Firm
30%
Manufacturing Company
16%
Computer Software Company
13%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
What is your experience regarding pricing and costs for Checkmarx?
The solution's price is high and you pay based on the number of users.
What do you like most about Parasoft SOAtest?
Since the solution has both command line and automation options, it generates good reports.
What needs improvement with Parasoft SOAtest?
Tuning the tool takes time because it gives quite a long list of warnings. Going through that is a challenge. It only happens in the initial stage when we are setting up the tool, but it can be imp...
 

Comparisons

 

Also Known As

No data available
SOAtest
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Charter Communications, Sabre, Caesars Entertainment, Charles Schwab, ING, Intel, Northbridge Financial, Capital Services, WoodmenLife
Find out what your peers are saying about Checkmarx One vs. Parasoft SOAtest and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.