Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D
Reseller
Top 5Leaderboard
Efficiently identifies any open-source components that may contain vulnerabilities
Pros and Cons
  • "The product is stable and scalable."
  • "The quality of technical support has decreased over time, and it is not as good as it used to be."

What is our primary use case?

The purpose of software composition analysis is to identify any open-source components that may contain vulnerabilities. It is especially important because, nowadays, developers often download algorithms from the internet while they are developing software, but these downloaded components need to be scanned for vulnerabilities.

Additionally, developers may not pay close attention to open-source components' legal and licensing aspects, which can cause serious problems. Therefore, it is necessary to use software composition analysis as protection, and Checkmarx's SCA tool is very beneficial for this purpose.

What is most valuable?

The most valuable feature is that it can ensure the security of the software when downloading open-source components from the internet. It is the first and foremost benefit. Secondly, even though these components may be shared or free, there can still be license issues, and young developers may not pay attention to this aspect, which can be very dangerous and lead to serious penalties in the future.

What needs improvement?

In terms of time and quality of support, Checkmarx SCA needs improvement. The quality of support people needs improvement.

For how long have I used the solution?

We have been using it since the first day it was released. We always use the latest version.

Buyer's Guide
Checkmarx Software Composition Analysis
April 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,886 professionals have used our research since 2012.

What do I think about the stability of the solution?

The software is very stable and works very well.

What do I think about the scalability of the solution?

It is a very scalable product.

How are customer service and support?

This is the most critical point for me. Their support was much better in the past, like last year or two years ago. As compared to the previous timeline, I feel that their support should be much better.

How was the initial setup?

The initial setup is very easy.

What's my experience with pricing, setup cost, and licensing?

From my point of view, according to the value they generate for the customers, it is not expensive. But as compared to competitive products in the market, it is gradually becoming more expensive. It's like choosing between a BMW and a cheaper car.

So, it's worth the money someone spends to use this product.

What other advice do I have?

It's one of the best in the market, honestly.

Overall, I would rate the product a nine out of ten. And I didn't score it ten because of the weakness in the support. I know from the past that the support used to be better because I had been working with Checkmarx for over ten years.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
System Engineer at a manufacturing company with 5,001-10,000 employees
Real User
Top 5Leaderboard
A stable and scalable solution that helped ensure the integrity of our libraries
Pros and Cons
  • "Checkmarx unifies all the features in its service."
  • "I have received complaints from my customers that the pricing could be improved."

What is our primary use case?

My customers' main use cases for this solution are based on its open-source library. Another use case is with supply chain attacks because It checks the integrity of the library and not just the hash, checksum, or version.

What is most valuable?

Checkmarx unifies all the features in its service.

What needs improvement?

I have received complaints from my customers that the pricing could be improved.

For how long have I used the solution?

It's been two years since I started getting familiar with the solution.

What do I think about the stability of the solution?

I rate the solution's stability an eight out of ten.

What do I think about the scalability of the solution?

I rate the solution's scalability a ten out of ten. Software Composition is just the version, the hash, so it consumes less data and can be scaled easily.

How are customer service and support?

Checkmarx's technical support is helpful.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I've used AppDome. Checkmarx protects our apps from the inside, but AppDome protects our apps from the outside. AppCode provides a different aspect of security from Checkmarx by healing apps since Checkmarx doesn't scan for vulnerabilities in code.

What other advice do I have?

I recommend Checkmarx Software Composition Analysis and rate it a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer:
Flag as inappropriate
PeerSpot user
Buyer's Guide
Checkmarx Software Composition Analysis
April 2024
Learn what your peers think about Checkmarx Software Composition Analysis. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,886 professionals have used our research since 2012.
Frontend Developer at a tech services company with 51-200 employees
Consultant
Top 20
Stable tool that identifies open-source vulnerabilities and critical issues
Pros and Cons
  • "What's most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in open-source components, especially if some critical issues exist."
  • "Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved."

What is our primary use case?

We use Checkmarx Software Composition Analysis in our development process. We use it when we work with end users for the development of software.

What is most valuable?

What I found most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in components, especially if some critical issues exist.

What needs improvement?

An area for improvement in Checkmarx Software Composition Analysis is for the updates to be fast. I see that open-source and third party solutions have a lot of vulnerabilities discovered day by day, so it's important for the end users to get updates instantly, so we can identify those vulnerabilities as soon as possible.

What I'd like to see in the next release of Checkmarx Software Composition Analysis is the improvement of its UI. For example, reconciling the live code in a more convenient way.

Improving Checkmarx Software Composition Analysis to make it more convenient for end users to work, plus verifying and analyzing reports from it, is another thing I'd like to see in the next release.

What do I think about the stability of the solution?

Checkmarx Software Composition Analysis is a stable solution. Even during upgrades, user experience is stable, and I don't have any major issues with the solution.

What do I think about the scalability of the solution?

Usage of Checkmarx Software Composition Analysis in our company is not too high, so I'm not really sure how scalable it is. We currently have 20 users of the solution.

How are customer service and support?

We don't directly work with the technical support team of Checkmarx Software Composition Analysis, because we have a team who handles the support for the solution, so we contact that team whenever we have issues, instead of contacting the vendor directly.

How was the initial setup?

I have no idea how easy or complex the initial setup for the solution is, because the deployment phase for Checkmarx Software Composition Analysis in my company is through the portal.

What other advice do I have?

I'm working with Checkmarx Software Composition Analysis. I started in this field of work in 2020. This is when I started using SonarQube in my previous company.

Checkmarx Software Composition Analysis can be deployed both on cloud and on-premises, but ours is deployed on-premises.

My advice to people who want to implement Checkmarx Software Composition Analysis is to use it, especially if their software development framework relies on open-source plugins or public open-source solutions. They would need a software composition analysis solution to scan for vulnerabilities in components, because a lot of issues and critical vulnerabilities come from public open-source framework, so my suggestion is for them to use Checkmarx Software Composition Analysis.

My rating for Checkmarx Software Composition Analysis is eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Cuneyt KALPAKOGLU Phd. - PeerSpot reviewer
Founder & Chairman at Endpoint-labs Cyber Security R&D
Reseller
Top 5Leaderboard
Very easy, user friendly, and stable
Pros and Cons
  • "It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own."
  • "It can have better licensing models."

What is our primary use case?

We are an IT security research and development lab. We have around 22 engineers doing research and testing and developing add-ons and complementary solutions. We are the strategic development partner of Checkmarx. We are using the latest version of this solution.

What is most valuable?

It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own.

What needs improvement?

It can have better licensing models.

For how long have I used the solution?

We have been working with Checkmarx for more than six years.

What do I think about the stability of the solution?

It is stable. I have never faced any issues.

What do I think about the scalability of the solution?

It is scalable.

How are customer service and technical support?

It doesn't need any technical support, but when you open a ticket, you get a response on the same day. Sometimes, you get a response in an hour or two hours. They are a very dedicated organization.

How was the initial setup?

The initial setup is straightforward and very user friendly. It is a cloud product, so you don't need to install it. It is plug and play.

What other advice do I have?

I would recommend this solution. Checkmarx Software Composition Analysis is one of the most important products in the IT security market. According to the Gartner report, Checkmarx has been a leading company for the last three years. 

I would rate Checkmarx Software Composition Analysis a nine out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Checkmarx Software Composition Analysis Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Checkmarx Software Composition Analysis Report and get advice and tips from experienced pros sharing their opinions.