We performed a comparison between WhiteSource and SonarQube based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.
Comparison Results: SonarQube comes out on top in this comparison. It is high performing and user-friendly. In addition, it is less expensive than WhiteSource.
"I am the organizational deployment administrator for this tool, and I, along with other users in our company, especially the security team, appreciate the solution for several reasons. The UI is excellent, and scanning for security threats fits well into our workflow."
"We set the solution up and enabled it and we had everything running pretty quickly."
"Our dev team uses the fix suggestions feature to quickly find the best path for remediation."
"There are multiple different integrations there. We use Mend for CI/CD that goes through Azure as well. It works seamlessly. We never have any issues with it."
"The results and the dashboard they provide are good."
"It gives us full visibility into what we're using, what needs to be updated, and what's vulnerable, which helps us make better decisions."
"The dashboard view and the management view are most valuable."
"The overall support that we receive is pretty good. "
"The reporting and the results are quick. It gets integrated within the pipeline well."
"The customizable dashboard and ability to include results and coverage from unit test and other static analysis code tools."
"If code coverage is a low number then that's of great value to me."
"Using SonarQube benefits us because we are able to avoid the inclusion of malware in our applications."
"It has very good scalability and stability."
"SonarQube is good in terms of code review and to report on basic vulnerabilities in your applications."
"Before you even compile, it can catch known vulnerability issues or patterns."
"It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go."
"On the reporting side, they could make some improvements. They are making the reports better and better, but sometimes it takes a lot of time to generate a report for our entire organization."
"The only thing that I don't find support for on Mend Prioritize is C++."
"It would be nice to have a better way to realize its full potential and translate it within the UI or during onboarding."
"At times, the latency of getting items out of the findings after they're remediated is higher than it should be."
"Needs better ACL and more role definitions. This product could be used by large organisations and it definitely needs a better role/action model."
"It should support multiple SBOM formats to be able to integrate with old industry standards."
"Mend lets you create custom policies. They're not too complicated to set up, but it would be helpful if they had some preconfigured policies to match what we have in Azure DevOps. That would save us a lot of time. It's tedious to configure the policies manually, and I lack the capacity to do it right now. Other products have preconfigured packs and templates, and Mend doesn't."
"I rated the solution an eight out of ten because WhiteSource hasn't built in a couple of features that we would have loved to use and they say they're on their roadmap. I'm hoping that they'll be able to build and deliver in 2022."
"SonarQube could improve by adding automatic creation of tasks after scanning and more support for the Czech language."
"The solution could improve by providing more advanced technologies."
"I am not very pleased with the technical debt computation."
"The software testing tool capability could improve. It does not always integrate well. You have to use a specific plugin and the plugin does not always go in Apple's applications."
"SonarQube is not development-centric like Snyk."
"A robust credential scanner would be a huge bonus as it would remove the need for yet another niche product."
"This is a well-rounded solution, however, some features could be made available on the free version. The price of the solution could be reduced."
"We found a solution with dynamic testing, and are looking to find a solution that can be used for both types of testing."
Mend.io is ranked 13th in Application Security Tools with 29 reviews while SonarQube is ranked 1st in Application Security Tools with 112 reviews. Mend.io is rated 8.4, while SonarQube is rated 8.0. The top reviewer of Mend.io writes "Easy to use, great for finding vulnerabilities, and simple to set up". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". Mend.io is most compared with Black Duck, Veracode, Snyk, Checkmarx One and JFrog Xray, whereas SonarQube is most compared with Checkmarx One, SonarCloud, Coverity, Veracode and OWASP Zap. See our Mend.io vs. SonarQube report.
See our list of best Application Security Tools vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.