Checkmarx Primary Use Case

Don Robbins
Software Configuration Manager at a tech vendor with 501-1,000 employees
The primary use that we have for Checkmarx is the evaluation of source code vulnerabilities. We use Git to connect to Checkmarx. We don't use GitHub. We use our own self-hosted Git. We're just using generic Git. One of the biggest thorns in our side is managing that aspect of it. It wouldn't matter if it was GitHub or Bitbucket or any of the other tools that you can use to connect Git to Checkmarx. The issue is the same. The tool is good at telling us what repository we're connected to, but it is horrible in telling us what branch we're connected to. View full review »
Milind Dharmadhikari
Practice Head - IT Risk & Security Management Services at Suma Soft Private Limited
My team uses this product extensively for application vulnerability assessment. This solution is for static application security testing and is used within our software development process. As the software developers are creating solutions, they are able to identify vulnerabilities while the application is being written, rather than after the entire development is over. We were interested in having the raw source code scanned, so that was the primary requirement and that is where Checkmarx comes in. We do not need any precompiled libraries, or compiled source code, to be checked by the source code analysis solution. We have a security team that uses this product to scan source code, rather than have the developers handle it. We do not have any developer licenses (i.e. the SDLC Edition). Instead, the security team identifies the vulnerabilities and shares the report with the development team. View full review »
reviewer971370
CEO at a tech services company with 11-50 employees
The primary use case is for a white-box penetration testing security. When we work with source code, it's a tool to help us conduct a deep analysis on a source code level. We push the zip file with source code to our own stent with the solution and receive a report. Also, we work with the interface to find the vulnerabilities we may have. The most popular projects for us are the mobile application security assessment. We propose this option to our customers to check source code for iOS and Android mobile applications. View full review »
Learn what your peers think about Checkmarx. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
441,726 professionals have used our research since 2012.
Deepak Kamra
Vice President at Arisglobal Software Pvt Ltd
We are using it for static security scanning and static security testing. We also use it for code dependency analysis. We use two of the solution's tools for each variable. View full review »
reviewer1295802
Founder & Chairman at a tech services company with 11-50 employees
I am the founder and the chairman of an internationally certified cybersecurity research lab. I have a Ph.D. in cryptology and network security. We are a strategic partner of Checkmarx. Our job is to help them develop solutions. Currently, we are developing some algorithms and strategic solutions for them. Checkmarx informs us about what is happening, in advance, before they launch a product. We are also one of their testers. View full review »
EduardoBeltran
Director and Co-Founder at Ushiro-tec
We use Checkmarx to review the source code for the external applications that we expose to the cloud or other servers on the internet. View full review »
reviewer1375824
Technical Lead at a tech services company with 1,001-5,000 employees
We use this solution to check our systems for any vulnerabilities in our applications. Currently, I'm working on a banking tool, which is aligned with the menu. Our system was created 30 years ago and still is running in the market and doing well. However, currently, there are so many changes happening. Any solution coming into the technology needs to have a security check to ensure everything is safe. View full review »
Tusnin Das
General Manager at a consultancy with 1,001-5,000 employees
We use Checkmarx for static analysis as part of our software development lifecycle. It is very important because it helps us identify the security flaws in the code at a very early stage. Ultimately, this helps in reducing costs. View full review »
reviewer1263726
Sr. Application Security Manager at a tech services company with 201-500 employees
I am in charge of application security and Checkmarx is one of the products that I use in this capacity. We use this product for code scanning and static code analysis. View full review »
reviewer1410597
Vice President Of Technology at a computer software company with 5,001-10,000 employees
We primarily use Checkmarx for application security and tracking. View full review »
CyberSecAn08987
Cyber Security Analyst at a tech vendor with 1,001-5,000 employees
Our primary use case for this solution is SAST, Static Application Security Testing. View full review »
Samuel Baguma
Senior Security Engineer at a pharma/biotech company with 501-1,000 employees
When I had an issue that was causing trouble in my code, I would upload it to Checkmarx to perform static code analysis. I would then study the reports. View full review »
Bus432Anly
Business Analyst at a tech services company with 201-500 employees
Our primary use case solution is for code scanning. View full review »
James Barwick
Principal Software Engineer at SingTel Internet Exchange
Code scan. We performed periodic static code scans on copies of our Git repository to identify possible vulnerabilities. View full review »
reviewer1286010
Senior Software Engineer at a computer software company with 10,001+ employees
We use Checkmarx for scanning our source code. View full review »
Learn what your peers think about Checkmarx. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
441,726 professionals have used our research since 2012.