We performed a comparison between SonarQube and Synopsys Defensics based on real PeerSpot user reviews.
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools."The product has a friendly UI that is easy to use and understand."
"Strong code evaluation for budget-minded clients."
"We are using the Community edition. So, we don't have to incur any licensing costs. This is the best part."
"The most valuable features are the wide array of languages, multiple languages per project, the breakdown of bugs, and the description of vulnerabilities and code smells (best practices)."
"I like that it's easy to navigate not just in terms of code findings but you can actually see them in the context of your source code because it gives you a copy of your code with the items that it found and highlights them. You can see it directly in your code, so you can easily go back and make the corrections in the code. It basically finds the problems for you and tells you where they are."
"I like that it has a better dashboard compared to Clockwork. It's also stable."
"Engineers have also learned from the results and have improved themselves as engineers. This will help them with their careers."
"The solution has a wide variety of features and an open-source community that you are able to learn Java, JavaScript, or any other programing language."
"Whatever the test suit they give, it is intelligent. It will understand the protocol and it will generate the test cases based on the protocol: protocol, message sequence, protocol, message structure... Because of that, we can eliminate a lot of unwanted test cases, so we can execute the tests and complete them very quickly."
"The product is related to US usage with TLS contact fees, i.e. how more data center connections will help lower networking costs."
"We have found multiple issues in our embedded system network protocols, related to buffer overflow. We have reduced some of these issues."
"One thing to improve would be the integration. There is a steep learning curve to get it integrated."
"It requires advanced heuristics to recognize more complex constructs that could be disregarded as issues."
"If there was an official Docker image of SonarQube that could easily integrate into the pipeline would help the user to plug in and plug out and use it directly without any custom configuration. I am not sure if this is being offered already in an update but it would be very helpful."
"It would be a great add-on if SonarQube could update its database for vulnerabilities or plugging parts."
"Currently requires multiple tools, lacking one overall tool."
"There is no automation. You need to put the code there and test. You then pull the results and put them back in the development environment. There is no integration with the development environment. We would like it to be integrated with our development environment, which is basically the CI/CD pipeline or the IDE that we have."
"When we have a thousand products published over it, we expect it to be more efficient in terms of serving requests from the browser."
"The product's pricing could be lower."
"Sometimes, when we are testing embedded devices, when we trigger the test cases, the target will crash immediately. It is very difficult for us to identify the root cause of the crash because they do not provide sophisticated tools on the target side. They cover only the client-side application... They do not have diagnostic tools for the target side. Rather, they have them but they are very minimal and not very helpful."
"Codenomicon Defensics should be more advanced for the testing sector. It should be somewhat easy and flexible to install."
"It does not support the complete protocol stack. There are some IoT protocols that are not supported and new protocols that are not supported."
Earn 20 points
SonarQube is ranked 1st in Application Security Tools with 108 reviews while Synopsys Defensics is ranked 5th in Fuzz Testing Tools. SonarQube is rated 8.0, while Synopsys Defensics is rated 8.6. The top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". On the other hand, the top reviewer of Synopsys Defensics writes "Technical support provided protocol-specific documentation to prove that some positives were not false". SonarQube is most compared with Checkmarx, SonarCloud, Coverity, Veracode and Snyk, whereas Synopsys Defensics is most compared with Snyk, Invicti, Fortify on Demand, HCL AppScan and PortSwigger Burp Suite Professional.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.