We performed a comparison between Checkmarx One and HCL AppScan based on real PeerSpot user reviews.
Find out in this report how the two Application Security Tools solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI."The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
"The UI is very intuitive and simple to use."
"I like that you don't have to compile the code in order to execute static code analysis. So, it's very handy."
"We use the solution to validate the source code and do SAST and security analysis."
"The solution has good performance, it is able to compute in 10 to 15 minutes."
"The product's most valuable feature is static code and supply chain effect analysis. It provides a lot of visibility."
"It is very useful because it fits our requirements. It is also easy to use. It is not complex, and we are satisfied with the results."
"The main benefit to using this solution is that we find vulnerabilities in our software before the development cycle is complete."
"It's generally a very user-friendly tool. Anyone can easily learn how to scan"
"I like the recording feature."
"We are now deploying less defects to production."
"The solution is easy to install. I would rate the product's setup between six to seven out of ten. The deployment time depends on the applications that need to be scanned. We have a development and operations team to take care of the product's maintenance."
"It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code."
"It was easy to set up."
"Usually when we deploy the application, there is a process for ethical hacking. The main benefit is that, the ethical hacking is almost clean, every time. So it's less cost, less effort, less time to production."
"This is a stable solution."
"The pricing can get a bit expensive, depending on the company's size."
"The integration could improve by including, for example, DevSecOps."
"Updating and debugging of queries is not very convenient."
"Meta data is always needed."
"I expect application security vendors to cover all aspects of application security, including SAST, DAST, and even mobile application security testing. And it would be much better if they provided an on-premises and cloud option for all these main application security features."
"Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
"Micro-services need to be included in the next release."
"The plugins for the development environment have room for improvements such as for Android Studio and X code."
"The penetration testing feature should be included."
"In future releases, I would like to see more aggressive reports. I would also like to see less false positives."
"The product has some technical limitations."
"The databases for HCL are small and have room for improvement."
"Sometimes it doesn't work so well."
"A desktop version should be added."
"It's a little bit basic when you talk about the Web Services. If AppScan improved its maturity on Web Services testing, that would be good."
"We have experienced challenges when trying to integrate this solution with other products. When you compare it with the other SecOps products, the quality of the output is too low. It is not a new-age product. It is very outdated."
Checkmarx One is ranked 3rd in Application Security Tools with 67 reviews while HCL AppScan is ranked 14th in Application Security Tools with 39 reviews. Checkmarx One is rated 7.6, while HCL AppScan is rated 7.6. The top reviewer of Checkmarx One writes "The report function is a great, configurable asset but sometimes yields false positives". On the other hand, the top reviewer of HCL AppScan writes " A stable and scalable product useful for application security scanning". Checkmarx One is most compared with SonarQube, Veracode, Fortify on Demand, Snyk and Acunetix, whereas HCL AppScan is most compared with SonarQube, Veracode, Acunetix, PortSwigger Burp Suite Professional and OWASP Zap. See our Checkmarx One vs. HCL AppScan report.
See our list of best Application Security Tools vendors and best Application Security Testing (AST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.