Acunetix and SonarQube Cloud compete in the application security testing category. Acunetix appears to have the upper hand in detailed reporting and custom configurations, making it a comprehensive tool for web application analysis, while SonarQube Cloud stands out in continuous code analysis and CI/CD integration.
Features: Acunetix is known for its Advanced Interactive Application Security Testing, providing in-depth insights into vulnerabilities, customizable scan configurations, and seamless automated scanning. It also features a PCI DSS scoring mechanism for detailed reporting. SonarQube Cloud offers continuous code analysis, precise vulnerability identification, and seamless integration with CI/CD pipelines, all managed efficiently through its cloud platform.
Room for Improvement: Acunetix could enhance advanced manual intervention settings, expand its OWASP vulnerability database integration, and improve false positive handling and dynamic code analysis support, especially for mobile applications. SonarQube Cloud could offer better documentation for CI/CD integration, improve handling of false positives, and enhance its dynamic code analysis and reporting features to strengthen user confidence.
Ease of Deployment and Customer Service: Acunetix is deployed both on-premises and in cloud environments, offering versatility. However, its customer service, though generally responsive, sometimes delays responses in time-critical situations. SonarQube Cloud’s public cloud model ensures easy integration and accessibility, although its email-based support's typical response time of about a day may fall short in demanding scenarios.
Pricing and ROI: Acunetix has experienced price increases, affecting its previous cost-effective reputation. Despite this, users still note a significant ROI through enhanced security posture. SonarQube Cloud is competitively priced for small to midsize enterprises, aligning with market standards, although costs might be high for small companies. ROI is realized through improved code quality and integration efficiencies.
It saves a significant amount of time by covering attack surfaces.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
The product is designed for bigger clients, while smaller companies are often put aside.
The technical support from Invicti is very good and fast.
The technical support from Acunetix is quite good
Integrating it into different solutions is straightforward.
The customer service and support for SonarQube Cloud are responsive and helpful.
It has been used in multiple projects and performs well.
There are limitations, and it seems to have fewer capabilities than Veracode.
SonarQube Cloud is a scalable product, and I rate its scalability at seven out of ten.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
The support program was helpful in addressing it.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
The pricing of Acunetix is pretty expensive and could be improved.
We secured a special licensing model for penetration testing companies, which is cost-effective.
SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.
From my experience, SonarQube Cloud (formerly SonarCloud) is very expensive for small companies.
We used the open-source version of SonarQube Cloud for its minimum features and did not license its extensive capabilities.
Acunetix integrates with every type of tool, including CI/CD tools, offering 100% integration in DevOps environments.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
I find it to be one of the most comprehensive tools, with support for manual intervention.
I use SonarQube Cloud (formerly SonarCloud) to check the quality of developer code and identify vulnerabilities.
It is integrated easily with the CI/CD pipeline, saving time and cost.
I find SonarQube Cloud very easy to use and simple to integrate initially.
Product | Market Share (%) |
---|---|
SonarQube Cloud (formerly SonarCloud) | 4.2% |
Acunetix | 3.1% |
Other | 92.7% |
Company Size | Count |
---|---|
Small Business | 15 |
Midsize Enterprise | 5 |
Large Enterprise | 14 |
Company Size | Count |
---|---|
Small Business | 8 |
Midsize Enterprise | 3 |
Large Enterprise | 4 |
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
SonarQube Cloud offers static code analysis and application security testing, seamlessly integrating into CI/CD pipelines. It's a vital tool for identifying vulnerabilities and ensuring code quality before deployment.
SonarQube Cloud is widely used for its ability to integrate with tools like GitHub, Jenkins, and Bitbucket, providing critical feedback at the pull request level. It's designed to help organizations maintain clean code by acting as a quality gate. This service supports development methodologies including sprints and Kanban for ongoing vulnerability management. While appreciated for its dashboard and integration capabilities, some users find initial setup challenging and note the need for enhanced documentation. The recent addition of mono reports and microservices support offers deeper insights into security and code quality, though container testing limitations and false positives are noted drawbacks. Manual intervention is sometimes required to address detailed reporting, with external tools being necessary for comprehensive analysis. Notifications for larger teams during serious issues and streamlined integration of new features are also areas of improvement.
What are the key features of SonarQube Cloud?In specific industries, SonarQube Cloud finds application in finance and healthcare where code integrity and security are paramount. It allows teams to identify critical vulnerabilities early and ensures that software development aligns with industry regulations and standards. By continuously analyzing code, it aids organizations in deploying secure and reliable applications, fostering trust and compliance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.