Acunetix and SonarQube Server compete in the security testing and code quality analysis space. While both offer compelling features, Acunetix's strengths in vulnerability detection and usability provide an edge in security, whereas SonarQube excels in language support and integration within development pipelines.
Features: Acunetix includes Interactive Application Security Testing for granular vulnerability identification, comprehensive scanning capabilities with minimal false positives, and swift scheduling for efficient security testing. SonarQube Server offers extensive language support, seamless integration within development pipelines, and rich analytics tools providing deep insights into code quality.
Room for Improvement: Acunetix could improve its licensing model, enhance database integration with PCI standards, and provide clearer reporting. Users have noted occasional false positives and seek better functionality for manual validation. SonarQube Server would benefit from improved handling of false positives, more robust security scanning, and simpler integration with third-party security tools.
Ease of Deployment and Customer Service: Both products support multiple deployment options, including On-premises, Private Cloud, and Hybrid Cloud. Acunetix offers broader cloud configuration support. Its customer service is noted for being responsive and available 24/7, while SonarQube’s support is primarily ticket-based with average response times.
Pricing and ROI: Acunetix, known for its advanced features, is considered expensive, which has raised questions about its cost-effectiveness. In contrast, SonarQube Server appeals to cost-conscious organizations with open-source options, including a free Community Edition, making it more accessible despite less comprehensive vulnerability reporting compared to Acunetix.
It saves a significant amount of time by covering attack surfaces.
I have seen a return on the investment from SonarQube Server (formerly SonarQube) because the value it adds relates to static code analysis and vulnerability assessments needed for our FDA approval process.
We see productivity increasing based on the fact that the code review is mostly automated, allowing the developer to fix the code themselves before assigning it to someone else to review, thus receiving that ROI.
The technical support from Invicti is very good and fast.
The technical support from Acunetix is quite good
They showed us where we can actually get those granular level reporting extracted for Excel, which was a quick guide.
I would rate the technical support for SonarQube Server (formerly SonarQube) as a 10 because we have not faced any specific issues that required us to contact tech support, which is a very rare case.
The community support is quite effective.
I find SonarQube Server (formerly SonarQube) very scalable because we're able to create a new repository and integrate all the tools on that project and it just works.
I would rate the scalability of SonarQube Server as a 10 because we can configure the server to scan multiple projects based on the number of lines.
I think SonarQube Server (formerly SonarQube) is stable, and we did not face any problems unless there was a power outage or if the LAN cable was plugged out.
Acunetix should have better integration with newer tools such as GitHub and Azure DevOps.
The support program was helpful in addressing it.
Currently, it should also be able to analyze the code and generate and fix the code for specific developers or features that the developers are tracking.
If I fix some vulnerabilities today, they reappear in the next scan, and there will be completely different issues that need to be fixed.
The pricing of Acunetix is pretty expensive and could be improved.
We secured a special licensing model for penetration testing companies, which is cost-effective.
I would rate the pricing for SonarQube Server (formerly SonarQube) as an 8, where 1 is very cheap and 10 is very expensive, because Coverity is very expensive, and while SonarQube is not cheap, it is still less expensive than Coverity.
They always offer around a two-year contract, but we always take a one-year contract because it's expensive.
The freemium version of SonarQube Server offers excellent value, especially compared to the high costs of Snyk.
Acunetix integrates with every type of tool, including CI/CD tools, offering 100% integration in DevOps environments.
Its most valuable role is in enhancing security by identifying potential vulnerabilities efficiently.
I find it to be one of the most comprehensive tools, with support for manual intervention.
We use SonarQube Server's centralized management and visualization of code quality metrics on the dashboard because that's the executive dashboard that we send to the executives to show where we are in terms of quality, security, and where the company can improve.
Some of the static code analysis capabilities are the most beneficial.
The most valuable features of SonarQube Server (formerly SonarQube) for us include having control of the rules, enabling and disabling them.
Acunetix Web Vulnerability Scanner is an automated web application security testing tool that audits your web applications by checking for vulnerabilities like SQL Injection, Cross site scripting, and other exploitable vulnerabilities.
SonarQube Server enhances code quality and security via static code analysis. It detects vulnerabilities, improves standards, and reduces technical debt, integrating into CI/CD pipelines.
SonarQube Server is a comprehensive tool for enhancing code quality and security. It offers static code analysis to identify vulnerabilities, improve coding standards, and reduce technical debt. By integrating into CI/CD pipelines, it provides automated checks for adherence to best practices. Organizations use it for code inspection, security testing, and compliance, ensuring development environments with better maintainability and fewer issues.
What are the key features of SonarQube Server?Many industries implement SonarQube Server to uphold coding standards, maintain security protocols, and streamline their software development lifecycle. In sectors like finance and healthcare, adhering to regulations and ensuring reliable software is critical, making SonarQube Server invaluable. It is often integrated into CI/CD pipelines, ensuring that code changes meet set standards before deployment. This approach enhances productivity and maintains compliance with industry-specific requirements.
We monitor all Application Security Tools reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.