Checkmarx One delivers robust security through seamless integration with SCM and CI/CD tools, ensuring reliable SAST and SCA. Primarily used by organizations for vulnerability detection, it supports cloud and on-premises deployment to enhance secure coding practices.



| Product | Mindshare (%) |
|---|---|
| Checkmarx One | 8.8% |
| SonarQube | 13.6% |
| Snyk | 5.1% |
| Other | 72.5% |
| Title | Rating | Mindshare | Recommending | |
|---|---|---|---|---|
| SonarQube | 4.0 | 13.6% | 84% | 136 interviewsAdd to research |
| SentinelOne Singularity Cloud Security | 4.4 | N/A | 99% | 123 interviewsAdd to research |
| Company Size | Count |
|---|---|
| Small Business | 24 |
| Midsize Enterprise | 9 |
| Large Enterprise | 42 |
| Company Size | Count |
|---|---|
| Small Business | 598 |
| Midsize Enterprise | 346 |
| Large Enterprise | 1329 |
Checkmarx One provides organizations with comprehensive tools for secure software development, integrating effectively with CI/CD pipelines to scan thousands of applications. Its capabilities extend to identifying vulnerabilities in both code bases and third-party software. Enhancing workflow by supporting SCM solutions, it assists in maintaining secure coding standards and compliance. While excelling in various areas, it requires improvements in scan speed, reduction of false positives, and broader platform integration, particularly for COBOL and Swift. Its pricing model is noted as high, and demand exists for better tutorials and documentation.
What are the key features of Checkmarx One?Industries implement Checkmarx One for secure coding compliance and vulnerability management across varying environments, choosing between cloud and on-premises deployment based on requirements. Its extensive language support and integration with DevSecOps practices make it a popular choice for organizations aiming to enhance software security.
YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech
Case Study: Liveperson Implements Innovative Secure SDLC
| Author info | Rating | Review Summary |
|---|---|---|
| Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution | 3.5 | I’ve used Checkmarx One extensively to improve developer workflow and application security, appreciating its strong SAST, SCA, and CI/CD integrations, though it could benefit from faster scans, deeper language support, and more contextual IDE guidance. |
| Senior Software Engineer at a tech vendor with 10,001+ employees | 4.5 | I've been using Checkmarx One for years to streamline code validation, improve quality, and ensure compliance, saving significant time weekly, though I’d like to see faster reporting speeds and a more intuitive UI. |
| Cyber Security Expert at Nestle | 4.5 | I use Checkmarx One for SAST and SCA scans, appreciating its CI/CD integration and SCM support; while reporting could improve, it’s boosted our speed to market and handles extensive global code scanning effectively. |
| Senior GenAI Engineer at a tech vendor with 10,001+ employees | 4.0 | I've used Checkmarx One for three years to streamline vulnerability detection through CI/CD integration, saving time and reducing manual reviews, though it could improve scan speed, false positives, and integration with modern development tools. |
| ML Engineer - Specialist at a tech vendor with 10,001+ employees | 4.5 | I've used Checkmarx One extensively in DevSecOps for secure code scanning and CI/CD integration; it's versatile and stable, though scan speed and false positives could improve. It supports many languages and helps ensure compliance in cloud and on-prem environments. |
| Chief Technology Officer at 3CS Aquarah Limited | 4.0 | I implement Checkmarx One for clients, and it's reliable, easy to set up, and delivers quick results, especially in secure code development. Its Codebashing feature stands out, though I’d like to see RASP capabilities in the future. |
| Specialist Leader at Deloitte | 4.5 | I work as a partner with Checkmarx One and find its initial setup straightforward, although hybrid deployment is preferred. The tool shows clear ROI, but automated code fixing would enhance its capabilities. Enterprise clients benefit from its effective security scans. |
| Software Engineer at a manufacturing company with 10,001+ employees | 4.5 | I've used Checkmarx One daily for three years, mainly for SAST scans and vulnerability detection. It's easy to use, integrates well with our pipeline, helps reduce vulnerabilities quickly, and support is responsive within 24 hours. |