OpenText Core Application Security offers robust features like static and dynamic scanning, real-time vulnerability tracking, and seamless integration with development platforms, designed to enhance code security and reduce operational costs.


| Product | Market Share (%) |
|---|---|
| OpenText Core Application Security | 3.4% |
| SonarQube | 19.2% |
| Checkmarx One | 10.2% |
| Other | 67.2% |
| Type | Title | Date | |
|---|---|---|---|
| Category | Application Security Tools | Dec 29, 2025 | Download |
| Product | Reviews, tips, and advice from real users | Dec 29, 2025 | Download |
| Comparison | OpenText Core Application Security vs SonarQube | Dec 29, 2025 | Download |
| Comparison | OpenText Core Application Security vs Veracode | Dec 29, 2025 | Download |
| Comparison | OpenText Core Application Security vs Checkmarx One | Dec 29, 2025 | Download |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube | 4.0 | 19.2% | 83% | 134 interviewsAdd to research |
| Snyk | 4.1 | 6.1% | 100% | 50 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 13 |
| Midsize Enterprise | 6 |
| Large Enterprise | 38 |
| Company Size | Count |
|---|---|
| Small Business | 234 |
| Midsize Enterprise | 149 |
| Large Enterprise | 836 |
OpenText Core Application Security is a cloud-based, on-demand service providing accurate and deep scanning capabilities with detailed reporting. Its integrations with development platforms ensure an enhanced security layer in the development lifecycle, benefiting users by lowering operational costs and facilitating efficient remediation. The platform addresses needs for intuitive interfaces, API support, and comprehensive vulnerability assessments, helping improve code security and accelerate time-to-market. Despite its strengths, challenges exist around false positives, report clarity, and language support, alongside confusing pricing and package options. Enhancements are sought in areas like CI/CD pipeline configuration, report visualization, scan times, and integration with third-party tools such as GitLab, container scanning, and software composition analysis.
What features define OpenText Core Application Security?Industries like mobile applications, e-commerce, and banking leverage OpenText Core Application Security for its ability to identify vulnerabilities such as SQL injections. Integrating seamlessly with DevSecOps and security auditing processes, this tool supports developers in writing safer code, ensuring secure application deployment and enhancing software assurance.
OpenText Core Application Security was previously known as Micro Focus Fortify on Demand.
SAP, Aaron's, British Gas, FICO, Cox Automative, Callcredit Information Group, Vital and more.
| Author info | Rating | Review Summary |
|---|---|---|
| Lead Cybersecurity at TBO | 3.5 | I've used Fortify for seven years and found it effective for early vulnerability detection, especially in AWS environments, though it's costly and less suitable for in-house teams; support is strong, but VB.NET support was initially lacking. |
| Chief Innovation Officer at SAGGA | 3.5 | I find Fortify on Demand effective for security analysis with a better licensing model, though it lacks quality code analysis and broader ISO 25000 coverage; support is poor, and pricing is confusing for customers despite easier setup. |
| Lead Developer at a legal firm with 1,001-5,000 employees | 3.5 | I use Fortify to identify security vulnerabilities and sensitive information in source code, particularly access tokens. It's effective but prone to false positives and doesn't check CVEs in third-party libraries, which necessitates using an additional tool. |
| Principal Technical Consultant at EOH | 5.0 | I find Fortify on Demand to be effective in enhancing security posture through SAST and DAST scanning. It offers valuable dashboards for vulnerability analysis, though there's a learning curve. Its AI-driven engine significantly reduces bug densities and security incidents. |
| Architecture Manager at Alinma Bank | 4.0 | We used Fortify on Demand for cybersecurity threats, but its limited programming support and lack of dynamic testing led us to transition to SonarQube. SonarQube’s broader language support and pipeline integration improved testing for our core banking application. |
| Cloud architect at Vodafone | 4.0 | We use Fortify on Demand to secure APIs and systems throughout development, testing, and production stages, finding its scanning capabilities crucial. Integration with pipelines like Jenkins could be smoother, but it remains essential for our security infrastructure. |
| Pre-Sales Manager at Ejada Company Limited | 4.5 | I use Fortify On Demand for identifying application vulnerabilities in sales and desk operations. Its seamless integration with DevOps enhances security testing. It's affordable, but I wish it had AI features like other vendors. |
| Security Tester at Ray Business Technologies Private Limited | 4.5 | We utilize Fortify on Demand for static code analysis. Its user-friendly automatic scanning and AI features excel in detecting vulnerabilities and recommending solutions. The integration with CI/CD tools is beneficial, though pricing could be improved. |