SonarQube vs Tenable.io Web Application Scanning comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

SonarQube
Ranking in Application Security Tools
1st
Average Rating
8.0
Number of Reviews
112
Ranking in other categories
Static Application Security Testing (SAST) (1st), Software Development Analytics (1st)
Tenable.io Web Application ...
Ranking in Application Security Tools
24th
Average Rating
7.6
Number of Reviews
14
Ranking in other categories
No ranking in other categories
 

Market share comparison

As of June 2024, in the Application Security Tools category, the market share of SonarQube is 27.7% and it decreased by 1.9% compared to the previous year. The market share of Tenable.io Web Application Scanning is 1.9% and it increased by 4.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Application Security Tools
Unique Categories:
Static Application Security Testing (SAST)
31.6%
Software Development Analytics
47.2%
No other categories found
 

Featured Reviews

BS
Dec 21, 2023
This solution is simple to use and can be quickly deployed
We use SonarQube to check for vulnerabilities and quality.  The solution has helped us to find flaws in the Syntax and comply with requirements.  I have found the most valuable features to be scanning for bugs or fixing the hotspot. These features have helped to improve the code quality.  I…
Jahanzeb Feroze Khan - PeerSpot reviewer
Nov 14, 2023
Highly Recommended Solution with Latest Scanning Methods
The fundamental objective of this product is to enhance the overall security, be it through verification within the organization or at the user's end All the features are valuable to us as they offer cutting-edge scanning methods and address the latest issues with a contemporary approach. We…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable function is its usability."
"This solution is simple to use and can be quickly deployed."
"Some of the most valuable features have been the latest up-to-date of the OWASP, the monitoring, the reporting, and the ease of use with the IDE plugins, in terms of integration."
"The most valuable features are the dashboard, the ability to drill down to the code, user-friendly, and the technical debt estimation."
"The most valuable features are the wide array of languages, multiple languages per project, the breakdown of bugs, and the description of vulnerabilities and code smells (best practices)."
"We use this solution for qualitative coding. We make use of the SonarLint plugin as well as the dashboard."
"The static code analysis of the solution is the most important aspect for us. When it comes to security breaches within the code, we can leverage some rules to allow us to identify the repetition in our code and the possible targets that we may have. It makes it very easy to review our code for security purposes."
"It is a very good tool for analysis despite its limitations."
"Tenable provides the end analysis results covering all the published vulnerabilities and information on the market."
"All the features are valuable to us as they offer cutting-edge scanning methods and address the latest issues with a contemporary approach. Tenable.io Web Application Scanning is highly stable. I rate it a nine out ten. Since the solution works on the Cloud, it's highly scalable. I rate the scalability a nine out of ten. The setup of the solution is straightforward. The Return on Investment is substantial. I recommend the solution to all."
"We use the tool for our websites. We have a vulnerable subdomain. The tool helps to scan it for vulnerabilities."
"It collects the vulnerabilities on the hostnames and sends them to the Tenable.io cloud. Tenable has its own cloud where Tenable.io is running, but there are many connectors to other cloud solutions. Tenable can do vulnerability scanning for other cloud managers such as Azure, Amazon, and so on."
"The solution is stable."
"It is fully automated."
"Our customers adopt this solution because of the replication testing and the vulnerability assessment it can do. It is a multi-faceted product."
"The most valuable features of Tenable.io Web Application Scanning are the integration into specific use cases and scanning. All of the features of the solution are useful."
 

Cons

"New plug-ins should be integrated into SonarCloud to give more flexibility to the product."
"Monitoring is a feature that can be improved in the next version."
"The exporting capabilities could be improved. Currently, exporting is fully dependent on the SonarQube environment."
"The product needs to integrate other security tools for security scanning."
"Expression of common vulnerabilities and exposures is not always current."
"Technical support and the price could be better."
"Their dashboarding is very limited. They can improve their dashboards for multiple areas, such as security review, maintainability, etc. They have all this information, so they should publish all this information on the dashboard so that the users can view the summary and then analyze it further. This is something that I would like to see in the next version."
"Our developers have complained about the Quality Gates and the number of false positives that this product reports."
"I would like for them to add proxy filtering, where you can transfer and alter the package. It is fully automated. Other web application testers programs are actually proxy software, and the proxy software gives you the flexibility of modifying the outgoing package, which will actually help you in exploiting any vulnerability in detail."
"Tenable.io Web Application Scanning conducts a general scan, which wastes time. The scan needs to be specific."
"The technical support should be improved. Currently, some attacks are detected while others are not."
"The report customization needs to be better."
"It isn't easy to manage vulnerabilities in Tenable."
"The dashboard could be more user-friendly."
"The platform's technical support services could be better."
"Tenable.io Web Application Scanning is not very user-friendly and you need a lot of information to get proper reports. The tool's support is not very responsive."
 

Pricing and Cost Advice

"The tool's pricing is reasonable."
"The price point on SonarQube is good."
"SonarQube is an open-source product that can be used free of charge."
"The price of this solution is more expensive than competitors. However, it works better than competitors."
"We are using the free, unlicensed version."
"For the Community edition, there is no extra cost. It's totally free. The Enterprise edition, Data Center edition, and Developer edition are the paid versions."
"Compared to similar solutions, SonarQube was more accessible to us and had more benefits, with regards to size of the code base and supported languages. Apart from the Enterprise licensing fee, there are no additional costs."
"We pay €10 per month for this solution, which is good. It provides a good value for money."
"The pricing is okay."
"I rate the product's pricing a four out of ten."
"The application is extremely affordable. There are no additional costs involved with licensing. We switched to Tenable.io Web Application Scanning from other solutions due to pricing."
"It follows the same licensing scheme as Tenable.io and Tenable. sc."
"The price of the solution is reasonable compared to the competitors. The license cost is based on the number of users and the annual usage."
"Tenable.io Web Application Scanning is expensive for small businesses."
report
Use our free recommendation engine to learn which Application Security Tools solutions are best for your needs.
787,061 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Computer Software Company
15%
Manufacturing Company
12%
Government
6%
Computer Software Company
15%
Financial Services Firm
12%
Government
11%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which tools that are the best for for Static Code Analysis, I suggest you have a look...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. SonarQube has a great community edition, which is open-source and free. Easy to use...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Tenable.io Web Application Scanning?
The most effective feature of the product is the ability to scan the entire environment.
What needs improvement with Tenable.io Web Application Scanning?
The platform's technical support services could be better.
What advice do you have for others considering Tenable.io Web Application Scanning?
Implementing Tenable.io Web Application Scanning has been beneficial in identifying numerous vulnerabilities within application code. I rate its scanning capabilities in terms of user-friendliness ...
 

Also Known As

Sonar
No data available
 

Learn More

 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

IMDEX
Find out what your peers are saying about SonarQube vs. Tenable.io Web Application Scanning and other solutions. Updated: May 2024.
787,061 professionals have used our research since 2012.