Try our new research platform with insights from 80,000+ expert users

CAST Application Intelligence Platform vs SonarQube Server (formerly SonarQube) vs Veracode comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Mindshare comparison

Software Development Analytics
Application Security Tools
Application Security Tools
 

Featured Reviews

Jayanti Rode - PeerSpot reviewer
Application Intelligence Platform that offers useful insights into violations and improvements
There are different products of the CAST solution that we use for different reasons. For quality improvement, we use CAST AIP which is an Application Intelligence Platform. We have a health dashboard where we can view improvements and violations that have been fixed.  Our clients use CAST Highlight…
Sthembiso Zondi - PeerSpot reviewer
Consistent improvements in code quality and security with effective integration and reliable technical support
The features of SonarQube Server (formerly SonarQube) that I find most useful are the suggestions received from reviewing the code. When they review the code, they provide suggestions on how to fix it, and we find those very useful from a development perspective. We use SonarQube Server's (formerly SonarQube) centralized management and visualization of code quality metrics on the dashboard because that's the executive dashboard that we send to the executives to show where we are in terms of quality, security, and where the company can improve. We use that for organizational improvement purposes. The ability to tailor metrics tracking in SonarQube Server (formerly SonarQube) has been beneficial to my team. There are team-specific dashboards which are related to specific repositories they utilize, and we have that aggregative dashboard that shows the whole organization's performance. We can drill down per specific repository, which makes it easier for the team to improve specific things.
Sajal Sharma - PeerSpot reviewer
Offers shift-left security strategy and helps us with the latest security configurations, OWASP standards, and SAST standards
It's robustness is the main benefit to the organization. As it gets upgraded with time, it also improves the coverage – security configuration coverages and vulnerability coverages. It also updates itself with the latest known vulnerabilities that are uploaded to the NVD, OWASP, or other databases. So it gets upgraded itself with that. And so with each upgrade, it gets better and better. The solution offers the ability to prevent vulnerable code from going into production. It provides us with a report containing multiple remediations and mitigations for each vulnerability. For example, if it finds a cross-site scripting vulnerability, it will also include references like CWE and CVE records, instructions on how to fix it, and the specific line of code or module where the vulnerability is present. This helps us fix the issues accordingly. I'm a penetration tester and DevSecOps engineer. I evaluate the findings, mark false positives, and manually exploit vulnerabilities if they exist. If we need further clarification, we raise a ticket with the Veracode team and get consultancy from them. We are a software development team. If we find a vulnerability, I exploit it and come back with the best possible mitigation, and the dev team fixes it. If we use Veracode Fix, it might use third-party implementations or make changes we aren't aware of. We need to be very aware of what our application is using internally. It should be known to us. As per my experience, the solution's policy reporting ensures compliance with industry standards. It comes with multiple features. I get the most out of it, and it's good. The solution provides visibility into application status at every phase of development. Like static analysis, dynamic analysis, software composition, and manual penetration tests - throughout the SDLC We have a pipeline that I maintain. I use the Veracode API account and have integrated it with AWS and our Jenkins pipeline. We use Snyk for SCA and Veracode for SAST scanning. At the earliest stage of the build, the SAST scan runs along with the JS and PHP files. It provides us with reports, which are then handed over to the other tools we depend on. If I validate the report or check the Veracode dashboard and find vulnerabilities, I mark them as false positives or existing issues. We work on multiple projects, but the one I'm handling these days only uses Veracode for SAST. It's been about one and a half years since I've been working with Veracode and this project. It is quite impressive. There are some things Veracode cannot find, like code obfuscations inside the code and some insecure randoms. Sometimes, it misses those flaws. But overall, if I compare it with other tools, it is better. I will definitely recommend others to use this tool. We run the scan before each deployment. If the dev team builds a new module or something, we scan it along with all the files. If we find anything, we get it fixed. That's how it works. Veracode is quite important to the organization's shift-left security strategy because we make a scan for each deployment. Sometimes, if I think we need to perform a shift-left, I just make a scan before deployment and check for any misconfiguration or vulnerability in the code.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It supports most programming languages."
"The most valuable feature of the CAST Application Intelligence Platform is its security dashboard which is a dedicated dashboard that's pretty helpful because it gives compliance checks based on some of the leading frameworks in the industry, such as ISO 5055, OWASP, CWE Top 25, and NIST security guidelines. I find the security dashboard of the solution and the information it provides pretty useful. The security dashboard of the CAST Application Intelligence Platform is a feature that stands out."
"Used for controlling the technical debt and code quality."
"Our clients use CAST Highlight for cloud migration. This allows them to remove or remediate the blockers which are highlighted. This part of the solution shows improvement in quality and captures feedback for our clients."
"CAST's risk and security flow detection capabilities are highly effective, particularly in identifying security vulnerabilities. It is one of the most important and valuable features of the platform."
"SonarQube is scalable. My company has 50 users."
"Offers multi-programming language support"
"I follow Quality Gate's graduation model within organization, and it is extremely helpful for me to benchmark products."
"It helps our developers work more efficiently as we can identify things in a code prior to it being pushed to where it needs to go."
"We can create a Quality Gate in order to fail Jenkins jobs where the code coverage is lower than the set percentage."
"SonarQube's unit test coverage and exhaustive information at the module, project, and overall code repo levels are quite good."
"SonarQube has a lot of value, it reviews the basic coding standards and security vulnerabilities of code that help to reduce issues."
"I am only interested in the security features in SonarQube. There are plenty of features other features, such as test coverage, code anomalies, and pointer access are handled by the business logic teams. They get the reports and they have to fix them in JIRA or Bugzilla."
"Allows us to track the remediation and handling of identified vulnerabilities."
"Integrations into our developer's IDE (Greenlight) and the DevOps Pipeline SAST / SourceClear Integrations has particularly increased our time to market and confidence."
"It is a good product for creating secure software. The static code analysis is pretty good and useful."
"Veracode provides faster scans compared to other static analysis security testing tools."
"It makes it very easy to track and monitor activity."
"I liked that I could easily find out where my errors were. Instead of going through the whole code and the scripts, it showed me where the errors were and gave me an idea of how to fix them."
"I contacted the solution's technical support during the automation part, and it went well, after which I never faced any issues."
"Vericode's policy reporting for ensuring compliance with industry standards and regulations is great. I"
 

Cons

"The integration of this solution could be improved."
"The overall coverage of rules could be improved in the CAST Application Intelligence Platform because it does not cater to or cover all. For example, 2022 CWE coverage is still not available in the CAST Application Intelligence Platform. The solution also covers some NIST rules, but it does not cater to all rules. An additional feature I'd like to see in the next update of the CAST Application Intelligence Platform is for it to provide source code developer and contributor details, especially information on which areas of code were touched. This would be a good insight as the CAST Application Intelligence Platform looks into the source code."
"It has very few plugins to access different code repositories, so source code has to be fed."
"Areas for improvement in CAST AIP include enhancing support for implementation in complex environments and improving technical support to address organizational challenges alongside engineering issues."
"Implementation could be made more simpler as it is complex."
"The reporting is good, but I am not able to download a specific report as a PDF, so downloading reports is something that should be looked at."
"We did have some trouble with the LDAP integration for the console."
"I think the code security can be improved."
"Currently requires multiple tools, lacking one overall tool."
"The reporting can be improved."
"SonarQube could improve by adding automatic creation of tasks after scanning and more support for the Czech language."
"The solution could improve by having better-consulting services."
"There needs to be a shareable reporting piece or something we can click and generate easily."
"Veracode does not support scans for .NET Blazor server applications."
"The interface is basic and has room for improvement."
"The overall reporting structure is complicated, and it's difficult to understand the report."
"Their scanning engine is sometimes a little bit slow. They can improve the scan time."
"I would love to be able to do a dynamic sandbox scan. I think that that would allow us to really get a lot more buy-in from the software development teams."
"I am expecting some AI-related features in it. Also, if someone is using AI-generated code, Veracode should be able to detect that."
"The solution could improve the Dynamic Analysis Security Testing(DAST)."
"Raw file scans and dynamic scans would be an improvement, instead of dealing with code binaries."
 

Pricing and Cost Advice

"I do know how the CAST Application Intelligence Platform is licensed, but I'm not able to give the cost because the price is not listed. My company works with individual vendors, so pricing is on a case-to-case basis, but the vendors give specialized pricing because of the enterprise deployment, though my team is aware of product pricing based on lines of code, based on the number of applications, etc., I'm unable to give the exact licensing costs of the CAST Application Intelligence Platform. My company doesn't have to pay extra for some features or services because all are included as part of the enterprise license. On a scale of one to five, with five being very cheap and one being very expensive, I would rate the CAST Application Intelligence Platform as three out of five."
"It's an open-source product."
"SonarQube is a cost-effective solution."
"I was using the Community Edition, which is available free of charge."
"SonarQube is a fairly affordable solution for a larger scale if you have a specific role or specific department for secure code."
"The price point on SonarQube is good."
"It's a bit expensive for us. The currency rate of the dollar is a problem but it may be fine for other countries."
"Compared to similar solutions, SonarQube was more accessible to us and had more benefits, with regards to size of the code base and supported languages. Apart from the Enterprise licensing fee, there are no additional costs."
"Can try developer version for 14 days on the free trial."
"The pricing for Veracode is high, making it difficult for beginners to afford."
"The worst part about the product is that it does not scale at all. Also, microservices apps will cost you a fortune."
"I wouldn't really recommend Veracode for a small firm, because it might be a little pricey for them. But for a large organization, with more than 1,000 applications in the enterprise, there are tiered levels of pricing."
"Veracode is expensive. But the solution is worth it."
"It has good, fair licensing. If the price could depend on the scope of its scanning or the languages supported, then that would be better."
"We're very comfortable with their model. We think they're a good value. We worked very closely with Veracode on understanding their license model, understanding what comprises the fee and what does not. With their assistance in design, we decomposed our application in a way where we are scanning a very significant amount of code without wasting their capacity and generating redundant reported issues. You scan in profiles, per se. And we work with them, in their offices, to design the most effective approach. So the advice I would have for customers is, you can get up and live fast, but work closely with Veracode to refine the method you use for scanning and the way you compile the applications. There's a concept called entry-point scanning, and that's probably not used well by the rest of their customers. We see our licensing as a good value because we leverage it heavily."
"The pricing is pretty high."
"The price of Veracode Static Analysis could improve."
report
Use our free recommendation engine to learn which Software Development Analytics solutions are best for your needs.
862,077 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
28%
Computer Software Company
13%
Manufacturing Company
8%
Government
6%
Financial Services Firm
16%
Computer Software Company
15%
Manufacturing Company
13%
Government
6%
Financial Services Firm
16%
Computer Software Company
16%
Manufacturing Company
8%
Insurance Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about CAST Application Intelligence Platform?
CAST's risk and security flow detection capabilities are highly effective, particularly in identifying security vulne...
What needs improvement with CAST Application Intelligence Platform?
Areas for improvement in CAST AIP include enhancing support for implementation in complex environments and improving ...
What is your primary use case for CAST Application Intelligence Platform?
CAST AIP is a valuable solution for quality metrics and application security. It is beneficial for software architect...
Is SonarQube the best tool for static analysis?
I am not very familiar with SonarQube and their solutions, so I can not answer. But if you are asking me about which ...
Which gives you more for your money - SonarQube or Veracode?
SonarQube is easy to deploy and configure, and also integrates well with other tools to do quality code analysis. Son...
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and securi...
What do you like most about Veracode?
The SAST and DAST modules are great.
What is your experience regarding pricing and costs for Veracode?
The product’s price is a bit higher compared to other solutions. However, the tool provides good vulnerability and da...
What needs improvement with Veracode?
Veracode Greenlight scans the code while the developer writes it. It will be beneficial for developers if Veracode Gr...
 

Also Known As

CAST AIP
Sonar
Crashtest Security , Veracode Detect
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Steria, T-Systems MMS, Atos Origin, Accenture, Capgemini
Information Not Available
Manhattan Associates, Azalea Health, Sabre, QAD, Floor & Decor, Prophecy International, SchoolCNXT, Keap, Rekner, Cox Automotive, Automation Anywhere, State of Missouri and others.
Find out what your peers are saying about CAST Application Intelligence Platform vs. SonarQube Server (formerly SonarQube) and other solutions. Updated: June 2025.
862,077 professionals have used our research since 2012.