Checkmarx SAST provides advanced static application security testing by identifying vulnerabilities in source code. It's ideal for ISOs, security professionals, and developers striving to secure applications during development.
Product | Market Share (%) |
---|---|
Checkmarx SAST | 1.3% |
SonarQube Server (formerly SonarQube) | 20.3% |
Checkmarx One | 9.9% |
Other | 68.5% |
Checkmarx SAST is known for its powerful code scanning capabilities that integrate seamlessly into existing development environments. It supports a wide range of programming languages, which makes it applicable for diverse development projects. Some users suggest improvements in the scan performance speed and enhanced support in handling false positives to further optimize workflow efficiency.
What are the standout features of Checkmarx SAST?Implemented across various industries, Checkmarx SAST supports sectors like finance, healthcare, and technology with their stringent security requirements. By integrating seamlessly into existing workflows, it ensures that applications remain secure while not disrupting industry-specific processes.
Checkmarx SAST was previously known as SAST.
Author info | Rating | Review Summary |
---|---|---|
IT Transformation Project Manager at a financial services firm with 10,001+ employees | 4.5 | We integrated Checkmarx with Jenkins pipelines for automated static security scanning, which effectively protected our company against code leakages. Although an unrecognized vulnerability required vendor intervention, we ultimately deployed secure code to production without issues. |
Key Account Manager at a tech services company with 11-50 employees | 4.5 | I've worked with Checkmarx SAST for two years and found it reliable, scalable, and favored by clients, though costly. Its on-premise, unified AI-enabled platform is valuable, but deployment can be complex and support could improve. |
Founder & Chairman at Endpoint-labs Cyber Security R&D | 5.0 | I primarily use Checkmarx SAST for application security through static application security testing. Its standout feature is detecting vulnerabilities early in the source code. However, improvements are needed in technical support, pricing, and configuration. ROI remains unmeasured. |