Apiiro vs Checkmarx Software Composition Analysis comparison

Cancel
You must select at least 2 products to compare!
Apiiro Logo
477 views|273 comparisons
100% willing to recommend
Checkmarx Logo
1,653 views|1,240 comparisons
100% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between Apiiro and Checkmarx Software Composition Analysis based on real PeerSpot user reviews.

Find out in this report how the two Software Composition Analysis (SCA) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed Apiiro vs. Checkmarx Software Composition Analysis Report (Updated: March 2024).
770,924 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"Apiiro's secrets detection feature has saved us several times, which we appreciate greatly.""The workflow automation is likely the best aspect of the solution."

More Apiiro Pros →

"One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good. It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely.""It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own.""The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all libraries that are vulnerable and the extent of their vulnerability.""The product is stable and scalable.""It is a stable solution...It is a scalable solution.""What's most valuable in Checkmarx Software Composition Analysis is that it provides security from the start. In the traditional approach, an enterprise or company validates the solution before launching to a production environment, but in the modern approach, security must be checked and provided from the beginning and from the design, and this is where Checkmarx Software Composition Analysis comes in. The solution helps you make sure that every open-source application that you use is secure, and that there's no vulnerability inside that open-source application.""What's most valuable in Checkmarx Software Composition Analysis is its ability to identify vulnerabilities in open-source components, especially if some critical issues exist.""Checkmarx unifies all the features in its service."

More Checkmarx Software Composition Analysis Pros →

Cons
"User management is a little bit clunky.""I would like support for our self-hosted Git server, other than GitHub, just regular Git."

More Apiiro Cons →

"In terms of areas for improvement, what could be improved in Checkmarx Software Composition Analysis is pricing because customers always compare the pricing among secure DevOps solutions in the market. Checkmarx Software Composition Analysis has a lot of competitors yet its features aren't much different. Pricing is the first thing customers consider, and from a partner perspective, if you can offer affordable pricing to your customers, it's more likely you'll have a winning deal. The performance of Checkmarx Software Composition Analysis also needs improvement because sometimes, it's slow, and in particular, scanning could take several hours.""The quality of technical support has decreased over time, and it is not as good as it used to be.""Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved.""It can have better licensing models.""Parts of the implementation process could improve by making it more user-friendly.""Its pricing can be improved. It is a little bit high priced. It would be better if it was a little less expensive. It is a good tool, and we're still figuring out how to fully leverage it. There are some questions regarding whether it can scan the MuleSoft code. We don't know if this is a gap in the tool or something else. This is one thing that we're just working through right now, and I am not ready to conclude that there is a weakness there. MuleSoft is kind of its own beast, and we're trying to see how we get it to work with Checkmarx.""I have received complaints from my customers that the pricing could be improved.""Checkmarx Software Composition Analysis should improve dynamic analysis."

More Checkmarx Software Composition Analysis Cons →

Pricing and Cost Advice
Information Not Available
  • "It is a little bit high priced. It would be better if it was a little less expensive."
  • "Pricing for Checkmarx Software Composition Analysis needs to be competitive."
  • "The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
  • "My customers need to pay for the licensing part, and they need to opt for an annual subscription."
  • "We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
  • More Checkmarx Software Composition Analysis Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
    770,924 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:Apiiro's secrets detection feature has saved us several times, which we appreciate greatly.
    Top Answer:My understanding is the pricing is pretty competitive.
    Top Answer:Apiiro recently integrated SaaS, and we would love to see them expand on that. They provide many integrations to different products, including SaaS products such as Snyk. Ideally, Apiiro would include… more »
    Top Answer:The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all… more »
    Top Answer:We have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage.
    Top Answer:Checkmarx Software Composition Analysis should improve dynamic analysis.
    Ranking
    Views
    477
    Comparisons
    273
    Reviews
    2
    Average Words per Review
    1,148
    Rating
    8.5
    Views
    1,653
    Comparisons
    1,240
    Reviews
    9
    Average Words per Review
    460
    Rating
    9.1
    Comparisons
    Also Known As
    Apiiro Control Plane (ASOC), Apiiro API Security (SAST), Apiiro Open Source (SCA)
    CxSCA
    Learn More
    Overview

    Apiiro is the leader in application security posture management (ASPM), unifying risk visibility, prioritization, and remediation with deep code analysis and runtime context.

    Companies like Morgan Stanley, SoFi, Rakuten, and Navan leverage Apiiro's ASPM to...

    Get complete application and risk visibility: Apiiro takes a deep, code-based approach to ASPM. Its Cloud Application Security Platform analyzes source code and pulls in runtime context to build a continuous, graph-based inventory of application and software supply chain components.

    Prioritize risks with code-to-runtime context: With its proprietary Risk Graph™️, Apiiro contextualizes security alerts from third-party tools and native security solutions based on the likelihood and impact of risk to uniquely minimize alert backlogs and triage time by 95%.

    Fix and prevent risks that matter—faster: By tying risks to code owners, providing LLM-enriched remediation guidance, and embedding risk-based guardrails directly into developer tools and workflows, Apiiro improves remediation times (MTTR) by up to 85%.

    Apiiro's native security solutions include API security testing in code, secrets detection and validation, software bill of materials (SBOM) generation, sensitive data exposure prevention, software composition analysis (SCA), and CI/CD and SCM security.



    Checkmarx Software Composition Analysis (SCA) helps organizations manage the risks associated with open source and third-party components in their software applications. While leveraging open source libraries and third-party dependencies is common practice, it can also introduce security vulnerabilities and license risks.


    Checkmarx SCA offers a multifaceted approach to managing these risks by:


    • Automatically scanning project repositories, build configurations, and manifests to create a comprehensive inventory of all components, including version information and associated licenses.

    • Performing vulnerability assessments on each component, including identifying and prioritizing actual exploitable or reachable vulnerabilities.

    • Protecting organizations from software supply chain attacks involving malicious packages, such as the XZ Utils backdoor.

    • Identifying licenses associated and providing insights into license obligations, restrictions, and potential conflicts.

    • Integrating seamlessly into existing development workflows and CI/CD pipelines.

    • Providing actionable remediation guidance to help organizations address identified vulnerabilities and compliance issues effectively.

    Sample Customers
    Morgan Stanley, Rakuten, Jack Henry, SoFi, Colgate, Navan
    AXA, Liveperson, Aaron's, Playtech, Morningstar
    Top Industries
    VISITORS READING REVIEWS
    Computer Software Company24%
    Comms Service Provider10%
    Outsourcing Company8%
    Financial Services Firm8%
    REVIEWERS
    Energy/Utilities Company22%
    Manufacturing Company22%
    Outsourcing Company11%
    Financial Services Firm11%
    VISITORS READING REVIEWS
    Financial Services Firm38%
    Manufacturing Company13%
    Computer Software Company12%
    Healthcare Company4%
    Company Size
    VISITORS READING REVIEWS
    Small Business39%
    Midsize Enterprise21%
    Large Enterprise40%
    REVIEWERS
    Small Business57%
    Large Enterprise43%
    VISITORS READING REVIEWS
    Small Business13%
    Midsize Enterprise8%
    Large Enterprise79%
    Buyer's Guide
    Apiiro vs. Checkmarx Software Composition Analysis
    March 2024
    Find out what your peers are saying about Apiiro vs. Checkmarx Software Composition Analysis and other solutions. Updated: March 2024.
    770,924 professionals have used our research since 2012.

    Apiiro is ranked 12th in Software Composition Analysis (SCA) with 2 reviews while Checkmarx Software Composition Analysis is ranked 8th in Software Composition Analysis (SCA) with 12 reviews. Apiiro is rated 8.6, while Checkmarx Software Composition Analysis is rated 9.2. The top reviewer of Apiiro writes "A great secrets detection feature, good visibility, and integrates well". On the other hand, the top reviewer of Checkmarx Software Composition Analysis writes "Comprehensive security scan, helpful support, and high availability". Apiiro is most compared with Snyk, Ox Security, Cycode, SonarQube and Semgrep Supply Chain, whereas Checkmarx Software Composition Analysis is most compared with Black Duck, JFrog Xray, Semgrep Supply Chain, Fortify Static Code Analyzer and Mend.io. See our Apiiro vs. Checkmarx Software Composition Analysis report.

    See our list of best Software Composition Analysis (SCA) vendors.

    We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.