We performed a comparison between HCL AppScan and Sonarqube based on our users’ reviews in four categories. After reading all of the collected data, you can find our conclusion below.
Comparison Results: Sonarqube offers better integration capabilities than HCL AppScan. Additionally, Sonarqube users are happier with the pricing. For these reasons, Sonarqube is the more desirable product in this comparison.
"The solution is easy to install. I would rate the product's setup between six to seven out of ten. The deployment time depends on the applications that need to be scanned. We have a development and operations team to take care of the product's maintenance."
"The solution is cheap."
"The product has valuable features for static and dynamic testing."
"AppScan is stable."
"This is a stable solution."
"It highlights, with several grades of severity, the types of vulnerabilities, so we can focus on the most severe security vulnerabilities in the code."
"The most valuable feature of the solution is Postman."
"This solution saves us time due to the low number of false positives detected."
"Improve the code coverage and evaluates the technical steps and percentage of code being resolved."
"The product itself has a friendly UI."
"It is very good at identifying technical debt."
"The tool helps us to monitor and manage violations. It manages the bugs and security violations."
"It automatically scans for code, detects vulnerabilities, and generates daily reports."
"All the features of the solution are quite good."
"SonarQube is scalable. My company has 50 users."
"The most valuable features are code scanning and Quality Gates."
"We would like to see a check in the specific vulnerabilities in mobile applications or rooted devices, such as jailbreaking devices."
"They should have a better UI for dashboards."
"One thing which I think can be improved is the CI/CD Integration"
"IBM Security AppScan Source is rather hard to use."
"Improving usability could enhance the overall experience with AppScan. It would be beneficial to make the solution more user-friendly, ensuring that everyone can easily navigate and utilize its features."
"I think being able to search across more containers, especially some of the docker elements. We need a little tighter integration there. That's the only thing I can see at this point."
"Scans become slow on large websites."
"Improvement can be done as per customer requirements."
"I would like to see more options for security, beyond the basics like SQL injection."
"We called support and complained but have not received any information as we use the free version. We had to fix it on our own and could not escalate it to the tool's developer."
"When we have a thousand products published over it, we expect it to be more efficient in terms of serving requests from the browser."
"SonarQube's detail in the security could be improved. It may be helpful to have additional details, with regards to Oracle PL/SQL. For example, it's neither as built nor as thorough as Java. For now, this is the only additional feature I would like to see."
"Monitoring is a feature that can be improved in the next version."
"I would like to see dynamic code analysis in the next version of the software."
"I am not very pleased with the technical debt computation."
"Ease of use/interface."
HCL AppScan is ranked 15th in Application Security Tools with 41 reviews while SonarQube is ranked 1st in Application Security Tools with 111 reviews. HCL AppScan is rated 7.8, while SonarQube is rated 8.0. The top reviewer of HCL AppScan writes " A stable and scalable product useful for application security scanning". On the other hand, the top reviewer of SonarQube writes "Easy to integrate and has a plug-in that supports both C and C++ languages". HCL AppScan is most compared with Veracode, Acunetix, OWASP Zap, PortSwigger Burp Suite Professional and Checkmarx One, whereas SonarQube is most compared with Checkmarx One, SonarCloud, Coverity and Veracode. See our HCL AppScan vs. SonarQube report.
See our list of best Application Security Tools vendors and best Static Application Security Testing (SAST) vendors.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.