Try our new research platform with insights from 80,000+ expert users
2017-05-04T10:40:00Z

Top 6 Application Security Solutions 2022

it_user326337 - PeerSpot reviewer
  • 135
Published:May 4, 2017
Explore related topics
Product comparison that may be of interest to you
PeerSpot user
PeerSpot user
Find out what your peers are saying about Sonar, Veracode, Checkmarx and others in Application Security Tools. Updated: April 2025.
849,963 professionals have used our research since 2012.
Related Questions
JB
May 23, 2023
May 23, 2023
Hi Joe - SonarQube is essentially a static code quality tool and has multiple versions (community is free and then we have developer, enterprise, and data center versions which are paid). As per the latest branding from CAST, they don't market AIP as a separate product and are bundled with CAST Imaging. CAST AIP is used to onboard the code base and perform analysis and the actual products are I...
See 1 answer
VG
May 23, 2023
Hi Joe - SonarQube is essentially a static code quality tool and has multiple versions (community is free and then we have developer, enterprise, and data center versions which are paid). As per the latest branding from CAST, they don't market AIP as a separate product and are bundled with CAST Imaging. CAST AIP is used to onboard the code base and perform analysis and the actual products are Imaging for architecture analysis and health, engineering, and security dashboards. The dashboards in CAST are richer and have more security features compared to SonarQube. Also, CAST does not have any free community version available. Both of them do static code analysis and do not look at run time code.
TM
May 16, 2023
May 16, 2023
@Tej Muchhala ​: Code Quality and Security are 2 different domains and depending on how deep you want to go, the choice of tools will vary.1. SonarQube - This has both community editions and commercial editions. The community has limited scope and no reporting. The enterprise version has a far broader scope covered with excellent reporting capabilities. SQ does have rules to compare against OWA...
2 out of 3 answers
May 15, 2023
Hi Tej, as per my experience, SonarQube provides a better understanding of the code, it gives you a detailed analysis of the code up to the line level. It finds vulnerabilities in the code and runs test cases for you (if you add them). Also, you can customize the quality gate rules to define the parameters your code should pass like reliability, repetition of lines, etc. On the other hand, Snyk offers you an overview of the tools you are using, or the APIs you are using inside the code and gives vulnerability notifications and fixes. SonarQube doesn't fix or doesn't give any suggestions but Snyk will give you suggestions on which version of that dependency should be used and why. I have integrated both Snyk and SonarQube as both are open source up to a certain level. 
LL
May 15, 2023
Hi Tej, you should also check out CAST (castsoftware.com). Their kit does a very thorough analysis that may be a good option depending on the complexity of your codebase. 
Related Articles
LW
Oct 22, 2023
Oct 22, 2023
Top 3 Tech Leaders in Application Security Tools 2023 Discover the leading technology solutions in Application Security Tools with PeerSpot's annual Tech Leaders awards. The awards are based on comprehensive user reviews and other criteria as outlined below, offering you a window into the top products in this category and a way to explore and compare outstanding products. Join us as we unveil t...
Product Comparisons
Related Categories
Related Articles
LW
Oct 22, 2023
Application Security Tools - Tech Leaders
Top 3 Tech Leaders in Application Security Tools 2023 Discover the leading technology solutions i...
Download Free Report
Download our free Application Security Tools Report and find out what your peers are saying about PortSwigger, Invicti, HCLSoftware , and more! Updated: April 2025.
DOWNLOAD NOW
849,963 professionals have used our research since 2012.