Acunetix and SonarQube Cloud operate in the domain of security and code quality, focusing on web vulnerability scanning and code analysis, respectively. Acunetix takes the lead in web vulnerability scanning, providing rapid and detailed reporting, while SonarQube Cloud excels in code inspection, efficiently identifying code odors, bugs, and security hotspots.
Features: Acunetix is equipped with Interactive Application Security Testing, advanced crawling, login sequence recording, and the ability to schedule scans. SonarQube Cloud offers continuous code inspection, seamless integration with version control systems, and excellent identification of security hotspots and code smells.
Room for Improvement: Acunetix can enhance its Interactive Application Security Testing tool, improve dataset precision, and simplify its licensing model. It can also explore more integrations and address scanning limitations. SonarQube Cloud could refine documentation customization, reduce false positives, and streamline configuration and initial setup processes.
Ease of Deployment and Customer Service: Acunetix offers flexible deployment options, including on-premises and hybrid cloud, but has costly 24/7 support with reported delays. SonarQube Cloud operates mainly on a public cloud model with responsive ticket-based support, offering simplicity in deployment.
Pricing and ROI: Acunetix is priced higher with a complex licensing structure that can be expensive, although it offers significant ROI through reduced application release risks. SonarQube Cloud provides a more transparent pricing model based on lines of code, appealing to budget-conscious buyers, although some small businesses find it prohibitive.
It saves a significant amount of time by covering attack surfaces.
It is easily integrable with the CI/CD pipeline and supports multiple projects with its extensive plugin options.
The product is designed for bigger clients, while smaller companies are often put aside.
The technical support from Invicti is very good and fast.
The technical support from Acunetix is quite good
Integrating it into different solutions is straightforward.
The customer service and support for SonarQube Cloud are responsive and helpful.
It has been used in multiple projects and performs well.
There are limitations, and it seems to have fewer capabilities than Veracode.
SonarQube Cloud is a scalable product, and I rate its scalability at seven out of ten.
From my team's feedback, it is almost an eight out of ten.
It is a quite stable solution.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
The support program was helpful in addressing it.
I need a solution that can bring together three key areas: vulnerabilities, static scanning, and misarchitecture.
I would like to see SonarQube Cloud provide more detailed solutions for fixing code issues, especially solutions related to CVEs.
Static code analysis is good, but the product lacks dynamic code scanning capabilities, an area where Veracode excels.
The pricing of Acunetix is pretty expensive and could be improved.
We secured a special licensing model for penetration testing companies, which is cost-effective.
SonarQube Cloud is roughly equivalent in cost to Veracode, maybe a little cheaper.
From my experience, SonarQube Cloud (formerly SonarCloud) is very expensive for small companies.
We used the open-source version of SonarQube Cloud for its minimum features and did not license its extensive capabilities.
Acunetix integrates with every type of tool, including CI/CD tools, offering 100% integration in DevOps environments.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
I find it to be one of the most comprehensive tools, with support for manual intervention.
I use SonarQube Cloud (formerly SonarCloud) to check the quality of developer code and identify vulnerabilities.
It is integrated easily with the CI/CD pipeline, saving time and cost.
I find SonarQube Cloud very easy to use and simple to integrate initially.
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
SonarQube Cloud offers static code analysis and application security testing, seamlessly integrating into CI/CD pipelines. It's a vital tool for identifying vulnerabilities and ensuring code quality before deployment.
SonarQube Cloud is widely used for its ability to integrate with tools like GitHub, Jenkins, and Bitbucket, providing critical feedback at the pull request level. It's designed to help organizations maintain clean code by acting as a quality gate. This service supports development methodologies including sprints and Kanban for ongoing vulnerability management. While appreciated for its dashboard and integration capabilities, some users find initial setup challenging and note the need for enhanced documentation. The recent addition of mono reports and microservices support offers deeper insights into security and code quality, though container testing limitations and false positives are noted drawbacks. Manual intervention is sometimes required to address detailed reporting, with external tools being necessary for comprehensive analysis. Notifications for larger teams during serious issues and streamlined integration of new features are also areas of improvement.
What are the key features of SonarQube Cloud?In specific industries, SonarQube Cloud finds application in finance and healthcare where code integrity and security are paramount. It allows teams to identify critical vulnerabilities early and ensures that software development aligns with industry regulations and standards. By continuously analyzing code, it aids organizations in deploying secure and reliable applications, fostering trust and compliance.
We monitor all Static Application Security Testing (SAST) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.