SonarQube Other Solutions Considered

Wang Dayong - PeerSpot reviewer
Senior Software Engineering Manager at Hill

Though some employees in the organization use Coverity, I chose SonarQube because it is easy to integrate with our software component.

View full review »
SG
Lead Engineer at a healthcare company with 10,001+ employees

We did look at a lot of other ones. Some of the names I actually can't recall. There were code quality analyzers out there besides that. We did review them and settled on this one because it's very widely used, and the open-source capabilities are pretty well-supported to where you can use it without obligation. None of them are trivial to set up and use because they are doing a very complicated process. They all have their different ways of going about things, but you've got to understand any one of them. We picked this route.

View full review »
Devid William - PeerSpot reviewer
Application Security Architect at Banco Votorantim

Veracode is more efficient in security analysis. It also has software composition analysis features. So, it would be difficult for SonarQube to compete with Veracode.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,667 professionals have used our research since 2012.
MarkRyall - PeerSpot reviewer
Strategist Individual Contributor at Peraton

We evaluated other products such as Veracode, Checkmarx as well as SonarQube.

The main difference is that SonarQube is free.

View full review »
WW
System Quality Assurance Manager at AIS - Advanced Info Services Plc.

I have evaluated Fortify Application Defender.

View full review »
Gert Kersten - PeerSpot reviewer
Software Developer at BKWI

We used some main code quality tools before, along with certain plugins. SonarQube is better due to its integrated nature and easier management. There is no hassle to keep everything up to date.

View full review »
AF
Senior Security Engineer at a financial services firm with 10,001+ employees

I have evaluated Fortify.

View full review »
Angelo Quaglia - PeerSpot reviewer
Independent Professional at Studio Dott. Ing. Angelo Quaglia
Daniel Antonio Jimenez Quintana - PeerSpot reviewer
IT Systems Architect at Banco Ripley

We are currently evaluating other solutions that are open-source. The company is trying to reduce the amount of money spent on solutions.

We are looking for the newest technologies but the biggest stopper for us is money.

View full review »
Denis Walrave - PeerSpot reviewer
Project Leader / Technical Expert at La francaise des jeux

Once we identified the need, I researched different solutions. I tried SonarQube and one or two others.

View full review »
AE
Test Expert at Saudi Telecom Company

We evaluated Micro Focus Fortify. From a cost perspective, we selected SonarQube. Now we are using the enterprise license as well. 

View full review »
MV
Tools manager at a retailer with 10,001+ employees

SonarQube is the only code scanning software I've tried, but I've also seen Nexus Scanner. However, it's not for binary scanning and so forth. It won't scan your source code. It's just an artifact scanner. 

View full review »
DG
Head of Software Delivery at a tech services company with 51-200 employees

We also evaluated Checkmarx, Veracode and open source solutions specific to each programming language. 

View full review »
SG
Lead Engineer at a healthcare company with 10,001+ employees

We had looked at other code quality systems. We had looked at a number of them. I don't remember them all, but Clockwork was on that list. I think it comes down to picking one and getting used to how it works because they all do mostly the same thing. Some of them focus more on Java, some more on C++. I think Java seems to be the favorite. As far as what they can really do for you, there didn't seem to be any one of them that does ten times what another does. There were some differences, but not no show-stoppers that I recall. I guess the advice would be that one of several tools could do a good job for you, but you still have to manage it and manage the behavior that goes along with it.

View full review »
HK
Country Manager Senegal at a financial services firm with 10,001+ employees

We did not evaluate other options before choosing this solution.

View full review »
KH
Manager, Software Development Engineering at a computer software company with 51-200 employees

I looked at Checkmarx but it wasn't as straightforward as SonarQube because it's only supporting Linux and maybe Windows, but I wasn't able to find any local scanning support for Mac computers, and that was an issue. I'd like to learn more about Checkmarx. 

View full review »
PC
Engineer at a pharma/biotech company with 201-500 employees

Now we are looking for a more mature solution and evaluating other products. We want a complete code analysis platform that is more mature.

We will either go with the paid Developer active license or solutions such as Checkmarx or MicroFocus.

View full review »
AB
Director IT Security, CISO at a transportation company with 10,001+ employees

You cannot really compare this product to commercial solutions. However, the features that it provides out of the box are very good.

When it comes to other technologies, such as the Checkmarx of the world, they are better than SonarQube. This is something that they should look at as this project evolves.

View full review »
JI
Automation Tool Specialist at a comms service provider with 1,001-5,000 employees

We are looking into corporate security and a couple different tooling options for doing data code analysis and security scanning.

We have looked into a few options: 

  • We are looking at IBM AppScan.
  • I am going to be running a small PoC next week with Veracode. I started doing a bit of research on Veracode, and I saw how it ties in compared with SonarQube.
View full review »
EG
Backend Architect at Sngular

We didn't evaluate other options. 

View full review »
DH
Technical Architect at Dwr Cymru Welsh Water

We evaluated the Checkmark Software Exposure Platform and Veracode, but they were expensive for a first go.

View full review »
Calinescu Tudor - PeerSpot reviewer
Security Project Leader at ATOSS AG

I have evaluated many other solutions similar to SonarQube.

View full review »
it_user100635 - PeerSpot reviewer
Technical Authority Digital at a insurance company with 1,001-5,000 employees

Yes, and we did so again recently (2016). We had an encumbant Coverity solution which was very expensive and very under-used (too complicated). Since then we have also considered specific security analysis tools as complementary products (e.g. CheckMarx, Veracode, Nexus Life-cycle/Firewall, and a few others). We have since selected from these.

View full review »
TS
Security consultant at a computer software company with 1,001-5,000 employees

We have already used SonarLint. I am considering both SonarLint and SonarQube.

View full review »
SR
Team Lead at a computer software company with 10,001+ employees

We are using Sonar, and we also evaluated Checkmarx. The version of Sonar we are using is the free version of it. Checkmarx is quite a bit different and more helpful compared to Sonar. There are a lot of features missing in the free version of SonarQube that I want to have that already exist in Checkmarx.  

View full review »
it_user727500 - PeerSpot reviewer
Senior Java Developer at a financial services firm

I didn't. I am not sure if there are any other open source static analysis tools as good as this that I have found; Well at least three or four years ago there weren't.

View full review »
it_user718230 - PeerSpot reviewer
Devops Engineer at a healthcare company with 10,001+ employees
it_user697050 - PeerSpot reviewer
SW Automation Team Leader at a tech services company with 201-500 employees

We did not evaluate other static code analysis solutions.

View full review »
EK
Director of consultory at a non-tech company with 1,001-5,000 employees

I have evaluated other solutions.

View full review »
CV
CTO at a computer software company with 11-50 employees

Yes, we have evaluated plenty of alternatives nothing really comparable.

View full review »
GL
Chief Solutions Officer at CleverIT B.V.

We did evaluate other options, for example Q1 and Veracode. In specific cases we created different aspects with different tools and these were the top peers that we would compare it to - Q1 and Veracode.

In terms of differences, Veracode is used more for the security of the development and you can configure the gates while thinking about software security and things like that. With Q1, the difference is the type of the license. In Q1 you have projects and you pay for the line. I know that SonarQube was changing the licensing plan. Right now, before you pay for a license, you pay for fair lines that you extend. This is the difference between these three tools.

View full review »
it_user333735 - PeerSpot reviewer
QA Engineer at a tech services company with 51-200 employees

Only one option we found competitive was CAST, but the prices and the functionality didn't convince us at all.

View full review »
AR
CEO at ITShare

We are also evaluating Acunetix and will know what direction we want to go in the next few weeks.

Based on the testing, Acunetix offers something different. Acunetix has many features that are not found in SonarQube.

View full review »
BR
Company Director at Alwyn Technologies

We evaluated other solutions including Cobra Static Code Analyzer, but we were not satisfied with their customer support in the open source community.

View full review »
LZ
Application Security Analyst at a agriculture with 501-1,000 employees

We are looking for how we can integrate several products. We are using static code analysis, we are looking into runtime code analysis, and of course, we have a web application firewall. The problem with all of these tools is that you need a lot of maintenance, and you have a lot of false positives. So, we have tried to find the best solution.

View full review »
AS
Senior/Lead Software Engineer at a government with 51-200 employees

I did an exercise a couple of months ago with my colleague. After this, I listed other products and their security aspects. I don't know if we found a solution that can offer us better features for security. I don't know if we will keep SonarQube in the pipeline or we will sell the product and get another product. I'm not sure at this point.

View full review »
HJ
IT Infrastructure Head / Facilities Manager - ITIL V3 Certified ,Vmware Vsphere5 at a financial services firm with 51-200 employees

We are constantly evaluating other products. So it might be that we will go with Micro Focus, for example, or any other tool in the future. It depends on what is offered by the product and what fits the client needs and budget.

View full review »
SK
Independent Consultant at Klusener Consultancy

I have experience with Parasoft and other similar tools. 

View full review »
JS
DevSecOps Lead at a tech services company with 11-50 employees

We evaluated other open-source products and found that SonarQube was the best one of the set.

View full review »
it_user347733 - PeerSpot reviewer
DevOps Engineer at Trantor Software Private Limited

We did some R&D according to our product need and found SonarQube as a solution.

View full review »
RP
Senior Manager at Digichorus Technologies

We considered using Fortify.

View full review »
it_user347595 - PeerSpot reviewer
Java Developer at a tech consulting company with 51-200 employees

No, I didn't. I was employed specifically for this plugin, and while know other code-quality control solutions exist, I didn't explore any of them.

View full review »
it_user336438 - PeerSpot reviewer
Web Developer/DevOps Engineer with 501-1,000 employees

We evaluated the market, and because security scans are so different, there was not a good COTS or open source solution that met our needs so we went with the best open source solution, which was SonarQube.

View full review »
it_user333624 - PeerSpot reviewer
Software Developer at a tech services company with 501-1,000 employees

I did not evaluated other options.

View full review »
it_user732738 - PeerSpot reviewer
Technical Architect and Software Engineer at a tech services company
TL
Software Engineer at Adfolks

I evaluated other products including Veracode and I felt that SonarQube was the best product.

View full review »
Buyer's Guide
SonarQube
March 2024
Learn what your peers think about SonarQube. Get advice and tips from experienced pros sharing their opinions. Updated: March 2024.
767,667 professionals have used our research since 2012.