

Acunetix and SonarQube compete in the realms of security and quality assurance. Acunetix leads in security testing, with its advanced features and insights into vulnerabilities, while SonarQube is preferred for its comprehensive code quality analysis and code integration features.
Features: Acunetix provides robust scheduling for automated scans, Interactive Application Security Testing that reveals application vulnerabilities, and flexible reporting in diverse environments. SonarQube offers extensive support for multiple languages, seamless CI/CD pipeline integration, and customizable, plugin-rich dashboards beneficial for larger teams.
Room for Improvement: Acunetix needs to refine its licensing model, improve manual vulnerability replication, and reduce false positives. Enhancing database support for new OWASP lists is also recommended. SonarQube's complex configuration and high false-positive rates in security assessments require attention. Users also suggest better integration with third-party tools and a boost in security scanning capabilities.
Ease of Deployment and Customer Service: Both Acunetix and SonarQube offer on-premises and cloud deployment options. Acunetix faces critique for slow technical support, pushing users towards resellers for quicker service. SonarQube delivers responsive support, uses user feedback for improvement, and offers comprehensive documentation for ease of setup.
Pricing and ROI: Acunetix's pricing has seen increases, affecting its cost-effectiveness, though its users report positive ROI due to enhanced application security. SonarQube presents a cost-effective solution with its free community edition and valuable plugins, improving coding quality and efficiency, though its advanced features require a paid subscription.
It saves a significant amount of time by covering attack surfaces.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
The technical support from Invicti is very good and fast.
The technical support from Acunetix is quite good
The community support is quite effective.
The customer service and support for SonarQube Cloud are responsive and helpful.
Integrating it into different solutions is straightforward.
There are limitations, and it seems to have fewer capabilities than Veracode.
It has been used in multiple projects and performs well.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
The support program was helpful in addressing it.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
We secured a special licensing model for penetration testing companies, which is cost-effective.
The pricing of Acunetix is pretty expensive and could be improved.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
The freemium version of SonarQube Server offers excellent value, especially compared to the high costs of Snyk.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
The solution is excellent at detecting SQL injection and cross-site scripting vulnerabilities.
I find it to be one of the most comprehensive tools, with support for manual intervention.
Some of the static code analysis capabilities are the most beneficial.
I find SonarQube Cloud very easy to use and simple to integrate initially.
It gives precise reports compared to Coverity and has a slightly lower number of false positives.
| Product | Market Share (%) |
|---|---|
| SonarQube Server (formerly SonarQube) | 19.3% |
| Acunetix | 2.5% |
| Other | 78.2% |


| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 5 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 41 |
| Midsize Enterprise | 24 |
| Large Enterprise | 79 |
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
SonarQube provides comprehensive support for multi-language development, custom coding rules, and quality gates, integrated seamlessly into CI/CD pipelines. It empowers teams with clear insights through intuitive dashboards, identifying vulnerabilities, code smells, and technical debt.
SonarQube is renowned for its extensive capabilities in static code analysis, making it an invaluable tool for maintaining code quality. By fully integrating into development processes, it allows organizations to manage vulnerabilities and ensure compliance with coding standards. Its extensive community and open-source roots contribute to its accessibility, while robust dashboards facilitate code quality monitoring. Despite its strengths, feedback suggests enhancing analysis speed, better integration with DevOps tools, and refining the user interface. Users also point to the need for handling false positives effectively and expanding on AI-based features for dynamic code analysis.
What are SonarQube's main features?In industries like finance and healthcare, SonarQube aids in obtaining regulatory compliance through rigorous code quality assessments. It is implemented to enhance cybersecurity by identifying potential vulnerabilities, while ensuring code meets the stringent standards demanded in these fields. As part of a broader development ecosystem, its integration in CI/CD pipelines ensures smooth and efficient software delivery, catering to phases from code inception to deployment, effectively supporting large-scale and critical software applications.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.