- Put the vulnerability details area on the right side of the application or it may be changeable
- Save and reset screen configuration
Sr. Security Engineer at SugarCRM
Security testing solution with vulnerability details and planned blackout times.
Pros and Cons
- "Vulnerability details is valuable."
- "The initial setup was very easy."
- "Implementing a blackout time for any user or teams: Needs improvement."
- "Vulnerability details: Reduce false positive results and improve it by providing more details how I can resolve the vulnerability."
How has it helped my organization?
What is most valuable?
Vulnerability details part.
What needs improvement?
- Vulnerability details: Reduce false positive results and improve it by providing more details how I can resolve the vulnerability.
- Implementing a blackout time for any user or teams: Needs improvement. I need to place limits for some users or teams within a specific time frame. For example, between 02:00 to 06:00. They can't start any scanning during that time, even if they have scanner privileges.
What do I think about the stability of the solution?
In the latest version, the session logout doesn't work properly.
Buyer's Guide
Checkmarx One
March 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,376 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have two engine licenses, but we can't scan two projects at the same time.
How are customer service and support?
I would give technical support a rating of 9/10.
Which solution did I use previously and why did I switch?
We were using Fortify. Its software capability was limited in terms of mobile code scanning.
How was the initial setup?
The initial setup was very easy.
What's my experience with pricing, setup cost, and licensing?
We don't have any specific advice about these issues.
Which other solutions did I evaluate?
We evaluated Fortify and AppScan.
What other advice do I have?
I don't like the latest license update. I can't set a limit for the reviewer account.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Responsable du Pôle Sécurité des Applications at a tech company with 51-200 employees
Both automatic and manual code review are possible. We can set up proper reports of code vulnerability.
Pros and Cons
- "Both automatic and manual code review (CxQL) are valuable."
- "Security can be part of the SDLC and reduce the cost of vulnerability remediation."
- "Integration into the SDLC (i.e. support for last version of SonarQube) could be added."
- "We had to lock the number of CPUs used to not crash the Checkmarx Audit."
How has it helped my organization?
After a proper on-boarding, we can set up proper reports of code vulnerability and/or misconfiguration to developers.
Security can be part of the SDLC and reduce the cost of vulnerability remediation. Also, we got faster remediation time for high and critical vulnerability.
What is most valuable?
Valuable features include:
- Both automatic and manual code review (CxQL).
- The languages covered by the solution.
What needs improvement?
Integration into the SDLC (i.e. support for last version of SonarQube) could be added.
What do I think about the stability of the solution?
We had to lock the number of CPUs used to not crash the Checkmarx Audit.
What do I think about the scalability of the solution?
We haven’t had scalability issues yet.
How are customer service and technical support?
Professional service is really good. Support is too formal. Quickly answering it is not supported instead of developing a hot fix.
Which solution did I use previously and why did I switch?
We didn’t really have a previous solution but Checkmarx was the best match for .NET support and scan without resolving the dependencies.
How was the initial setup?
Setup was straightforward, but quickly you need complex fine tuning.
What's my experience with pricing, setup cost, and licensing?
Include PS or deployment assistance in order not to miss true positive vulnerabilities. Really powerful tool, but it must be configured to match your application.
What other advice do I have?
Ask to meet another customer with the same needs or the same kind of organization, to learn from their experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Checkmarx One
March 2026
Learn what your peers think about Checkmarx One. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,376 professionals have used our research since 2012.
Security test engineer at a tech vendor with 10,001+ employees
Communicates where to fix the issue for less iterations. Resolutions should be provided for installation issues due to internal security policies.
Pros and Cons
- "The solution communicates where to fix the issue for the purpose of less iterations."
- "The solution communicates where to fix the issue for the purpose of less iterations."
- "The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."
- "The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered."
How has it helped my organization?
Now we have information about which specific sections have to be fixed. We can now remove the issue from most of the sections.
What is most valuable?
The solution communicates where to fix the issue for the purpose of less iterations.
What needs improvement?
The resolutions should also be provided. For example, if the user faces any problem regarding an installation due to the internal security policies of their company, there should be a resolution offered.
What do I think about the stability of the solution?
There were no stability issues.
What do I think about the scalability of the solution?
There were no scalability issues.
How are customer service and technical support?
I would give technical support a rating of 8/10.
Which solution did I use previously and why did I switch?
We switched solutions due to the client's requirements.
What's my experience with pricing, setup cost, and licensing?
I faced a few issues in the installation due to my local policies. The customer support was very helpful.
Which other solutions did I evaluate?
We looked at other tools, such as HPE Security and ZAP solutions.
What other advice do I have?
Go for it, if you want testing on the code level.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SAP FIORI / HCP Consultant at Silveo
Helps us check vulnerabilities in our applications. I would like to integrate it as a service along with the cloud platform.
Pros and Cons
- "Helps us check vulnerabilities in our SAP Fiori application."
- "One of the most important tools in our building process."
- "I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service."
- "When we have many applications to check, I need to wait a long time in the queue."
How has it helped my organization?
This product helps us to deliver good quality software.
What is most valuable?
- Performs security checks for SAP Fiori applications
- Helps us check vulnerabilities in our SAP Fiori application
- Easy to use and master
- One of the most important tools in our building process
What needs improvement?
I really would like to integrate it as a service along with the SAP HANA Cloud Platform. It will then be easy to use it directly as a service.
This improvement is needed in order to follow up the growth and of SAP cloud platform, it is a Platform as a service created by SAP, many services have been added to SAP HANA Cloud Platform, like GIT repository, Jenkins, Translation etc.
So, if it is possible to add the Checkmarx as a service in this platform, it will be easy to perform security check directly without using a dedicated server.
What do I think about the stability of the solution?
Maybe this issue is related to our configuration. When we have many applications to check, I need to wait a long time in the queue.
What do I think about the scalability of the solution?
We did encounter scalability issues. Maybe this is related to the stability issue mentioned above.
Which solution did I use previously and why did I switch?
We haven't used anything else. This is our first solution.
How was the initial setup?
I don’t know how to set up the product.
Which other solutions did I evaluate?
We did not look at any other options.
What other advice do I have?
It is a good tool. I recommend it in order to ensure software quality.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Program Manager at a engineering company with 10,001+ employees
Acts as the first check point during our consulting for apps that are looking for a security assessment or Penetration Testing.
Pros and Cons
- "The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
- "Checkmarx is a powerful scanning tool, and it’s essential to have one of these products to build a safe and stable application when it comes to inviting customers to use your online services."
- "The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
- "The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode."
How has it helped my organization?
For manual code testing, Checkmarx has been very helpful discarding false positives, filtering and removing a lot of files that are not presenting any threat, as well as indicating the files or functions that should be focused upon.
Checkmarx acts as the first checkpoint during our consulting for apps that are looking for a security assessment or Penetration Testing. It is also a game changer, giving the customer's results from each finding in the Checkmarx results.
What is most valuable?
- The export feature and presentation of the results.
- The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions).
- A wide variety of modern programming languages are supported, including mobile languages).
What needs improvement?
The lack of ability to review compiled source code. It would then be able to compete with other scanning tools, such as Veracode.
Compiled code means that the code written is stored in binaries, for machine reading only. Tools like Veracode read only those binaries (compiled code).
Another way to have the code is “Source Code written only”, which is the only code format that Checkmarx accepts, a process where you don’t compile and everyone is able to read line by line the code.
What do I think about the stability of the solution?
When the workload contains so many source codes being scanned, and none of them present any progress, sometimes they seem to get stuck. There are also a considerable number of false positives (vulnerabilities that do not present a danger against the application or the user).
What do I think about the scalability of the solution?
We have not encountered any scalability issues.
How are customer service and support?
From both customer support and technical support, the response is very swift (less than a day) and the technical people are very skilled on the common issues concerning the management of the scanning tool, even with issues of server saturation and scanners stuck at a percentage.
Which solution did I use previously and why did I switch?
I used to work mostly on checking the source code manually, and estimated the time of completion counting the lines of code to review. With Checkmarx that time was hugely reduced.
I also worked with Veracode, which I use for compiled code, but most of the customer’s applications have uncompiled code, so that is why I use Checkmarx more frequently.
How was the initial setup?
The initial setup was complex. There is a curve of learning, and you also need technical knowledge on reviewing the results of Checkmarx’s work.
What's my experience with pricing, setup cost, and licensing?
Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products to build a safe and stable application when it comes to inviting customers to use your online services.
Which other solutions did I evaluate?
We evaluated AppScan and Veracode. Neither covers the needs of my clients, the way I work, and the programming languages that Checkmarx covers.
What other advice do I have?
I recommend to have a live session with the marketing team, to have a demo and to track all your doubts before purchasing. Checkmarx is a powerful tool but you need to be sure what you are using, and what it is for. You could use just 20% of what the tool can do, and therefore waste your money. So either fully learn how to use it and evaluate if it’s the right scanning tool to have, or go for a better and cheaper option.
Disclosure: My company has a business relationship with this vendor other than being a customer. We support together a huge list of clients, we have credentials and provide support to each
business and division. So, we have the capacity to escalate any trouble or problem in case it is
necessary. We have our own community and are able to provide and remove access to users.
Innovation Consultant (Security Analyst) at a tech services company with 1,001-5,000 employees
It makes it easier to identify code vulnerabilities by presenting the flow of malicious input and fixing it.
Pros and Cons
- "Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
- "We have been using this product extensively for a lot of applications to identify as well as employ proper remediation which makes the application secure including information issues which might get neglected with a manual code review process."
- "Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed."
- "Unfortunately, Checkmarx doesn't do any automated backups which is quite inconvenient."
How has it helped my organization?
We have been using this product extensively for a lot of applications to identify as well as employ proper remediation which makes the application secure including information issues which might get neglected with a manual code review process.
What is most valuable?
Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application. It therefore makes it easier to identify these as well as fix them.
What needs improvement?
Checkmarx has the detailed description of all the vulnerabilities which it identifies after the source code scan. These descriptions are just a click away. Some of the descriptions were found to be missing or were not as elaborate as compared to other descriptions. Although, they could be found across various standard sources but it would save a lot of time for developers, if this was fixed.
What do I think about the stability of the solution?
We have not yet encountered any stability issues.
What do I think about the scalability of the solution?
The solution provides high scalability. I am not sure about the limit of scans but it is sufficiently high. However, the issues which we faced were related to database backup. Unfortunately, Checkmarx doesn't do any automated backups which is quite inconvenient.
How are customer service and technical support?
I would rate the technical support as average. We never had to communicate much with the technical team but based on my knowledge the response from their end was delayed.
Which solution did I use previously and why did I switch?
I am not aware of any previous solutions.
How was the initial setup?
The setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
It is a good product but a little overpriced.
Which other solutions did I evaluate?
I don't have much idea about other options since the organization had already purchased the product before I joined.
What other advice do I have?
Better to look out for other products available in the market as well.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager at a financial services firm
We felt like we were the extended quality organization as they frequently released poor quality patches that broke the existing functionality.
Pros and Cons
- "Scan reviews can occur during the development lifecycle."
- "It moved our organization towards being agile vs. waterfall."
- "C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
- "We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality."
How has it helped my organization?
It moved our organization towards being agile vs. waterfall.
What is most valuable?
Scan reviews can occur during the development lifecycle.
What needs improvement?
The areas in which this product needs to improve are:
- C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported.
- There were issues in regards to the JSP parsing.
- Defect report generation takes multiple hours for large projects.
- The Jenkins plugin does not work for projects that are larger than 4 million lines of code.
- The Eclipse plugin does not work.
- The hardware requirements for the tool add to the substantial cost of the solution and thus, increase the total cost of ownership.
- There seems to be a decline in the support team's responsiveness as our contract nears its end.
- We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality. A lot of the organizational hours, almost 1 FTE per year since Checkmarx was implemented, were spent to allow regression testing of the product. The Checkmarx SME team at my company had to do this testing to ensure that we do not expose product flaws to our user community.
What do I think about the stability of the solution?
We did encounter stability issues. The different versions of this product provide inconsistent results when the same piece of code is scanned.
What do I think about the scalability of the solution?
We did not encounter any scalability issues.
How are customer service and technical support?
The support team is knowledgeable. However, we still have tickets open from 2014. There is a lot of follow up required to get closure on issues.
Which solution did I use previously and why did I switch?
Previously, we were using a different solution. We were leveraging multiple tools since we have code in multiple languages. Checkmarx advertised that they provide support for C, C+++, Java, etc. It turned out that they aren’t able to scan C and C++ for us. Our reason to switch to Checkmarx didn’t work out for us.
How was the initial setup?
The initial setup was straightforward.
What's my experience with pricing, setup cost, and licensing?
The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies.
I suggest using a trial term to run a gamut of scenarios that need to be leveraged before settling in with the Checkmarx solution.
Which other solutions did I evaluate?
We evaluated the Veracode option.
What other advice do I have?
The product is not mature and ready for the enterprise usage yet. It is okay to use it when the support expectations are low and the code is in languages that require support only in Java and .NET.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder at a tech company with 51-200 employees
It can scan precompiled (source) code, as well as compiled (binary) code.
Pros and Cons
- "The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled."
- "The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools."
- "The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities."
How has it helped my organization?
The process of remediating software security vulnerabilities can now be performed (ongoing) as portions of the application are being built in advance of being compiled. Among other benefits, this reduces the cost to fix the problem(s) as the fix can occur earlier in the SDLC.
What is most valuable?
The ability to identify a vulnerability, the optimal place for remediation and the correct syntax is very valuable. This feature helps ensure that the software fix is comprehensive and effective. The CxSuite is easy to use and because it provides the correct coding syntax to address a vulnerability, it helps improve the secure coding skill set among developers. The product can scan precompiled (source) code, as well as compiled (binary) code, delivering effectiveness and efficiency throughout the SDLC.
What needs improvement?
The product can be improved by continuing to expand the application languages and frameworks that can be scanned for vulnerabilities. This includes expanded coverage for mobile applications as well as open-source development tools.
The Checkmarx CxSuite covers a wide range of programming languages including many of the most popular languages used by developers today. As matter of general improvement, expanding coverage to languages (emerging, legacy) and open source frameworks will increase the overall effectiveness of product.
*2017 Update. A number of leading Open Source Frameworks are now supported.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The product scales well.
How are customer service and technical support?
The technical support is high quality. The support team is well versed in how best to configure, implement and operate the product.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
The initial set up is straightforward. The product requires a fairly simple computing environment for operation.
What's my experience with pricing, setup cost, and licensing?
The product licensing offers the flexibility to cover a wide range of environments. The pricing is competitive and provides a lower TCO (total cost of ownership) for achieving application security.
Which other solutions did I evaluate?
We considered several other commercial-grade application security solutions. The Checkmarx solution offers an ideal combination of code coverage, functionality, usability and TCO.
What other advice do I have?
The Checkmarx CxSuite product works well, delivers efficiency to the SDLC, and most important of all, it effectively improves application security.
It works!
Disclosure: My company has a business relationship with this vendor other than being a customer. My company is a Checkmarx Certified Partner.
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Application Security Tools Static Application Security Testing (SAST) Vulnerability Management Container Security Static Code Analysis API Security Dynamic Application Security Testing (DAST) DevSecOps Risk-Based Vulnerability Management Application Security Posture Management (ASPM) AI SecurityPopular Comparisons
SonarQube
SentinelOne Singularity Cloud Security
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
GitLab
Veracode
Qualys VMDR
Imperva Application Security Platform
CrowdStrike Falcon Cloud Security
Coverity Static
JFrog Xray
Orca Security
Tenable Security Center
Buyer's Guide
Download our free Checkmarx One Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Veracode and Checkmarx?
- Checkmarx or Veracode. Which should we choose?
- What is the Biggest Difference Between Checkmarx and Fortify?
- What is the biggest difference between Checkmarx and SonarQube?
- Checkmarx vs SonarQube; SonarQube interoperability with Checkmarx or Veracode
- If you had to both encrypt and compress data during transmission, which would you do first and why?
- When evaluating Application Security, what aspect do you think is the most important to look for?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- What are the Top 5 cybersecurity trends in 2022?
- Which application security solutions include both vulnerability scans and quality checks?

















The software and application security should be the mandatory thing because most of the applications crash because of virus or harmful attacks. I was also getting the virus issue in my application then avastsupportnumber.co.uk/avast-customer-support avast customer service helped me a lot.