CAST Highlight vs Checkmarx Software Composition Analysis comparison

Cancel
You must select at least 2 products to compare!
CAST Logo
444 views|322 comparisons
100% willing to recommend
Checkmarx Logo
1,653 views|1,240 comparisons
100% willing to recommend
Comparison Buyer's Guide
Executive Summary

We performed a comparison between CAST Highlight and Checkmarx Software Composition Analysis based on real PeerSpot user reviews.

Find out in this report how the two Software Composition Analysis (SCA) solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
To learn more, read our detailed CAST Highlight vs. Checkmarx Software Composition Analysis Report (Updated: March 2024).
770,924 professionals have used our research since 2012.
Featured Review
Quotes From Members
We asked business professionals to review the solutions they use.
Here are some excerpts of what they said:
Pros
"The most valuable features of the CAST Highlight are the interface and there are three notations that are very simple to understand and communicate with.""The way it tells you which codebase is more ready for the cloud and which codebase is less ready is very valuable. It works seamlessly with most languages.""It offers good performance.""The most valuable features of CAST Highlight are automation and speed.""CAST Highlight is easy to use and has a good dashboard."

More CAST Highlight Pros →

"One of the strong points of this solution is that it allows you to incorporate it into a CICB pipeline. It has the ability to do incremental scans. If you scan a very large application, it might take two hours to do the initial scan. The subsequent scans, as people are making changes to the app, scan the Delta and are very fast. That's a really nice implementation. The way they have incorporated the functionality of the incremental scans is something to be aware of. It is quite good. It has been very solid. We haven't really had any issues, and it does what it advertises to do very nicely.""The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all libraries that are vulnerable and the extent of their vulnerability.""Checkmarx unifies all the features in its service.""What's most valuable in Checkmarx Software Composition Analysis is that it provides security from the start. In the traditional approach, an enterprise or company validates the solution before launching to a production environment, but in the modern approach, security must be checked and provided from the beginning and from the design, and this is where Checkmarx Software Composition Analysis comes in. The solution helps you make sure that every open-source application that you use is secure, and that there's no vulnerability inside that open-source application.""It is very easy and user friendly. It never requires any kind of technical support. You can do everything on your own.""I appreciate the user-friendly interface. The GUI is excellent, providing detailed information on outdated versions, including version numbers and the flow of library calls. This allows me to plan and prioritize library changes based on potential vulnerabilities, even if the affected library is indirectly used in my project. The tool offers specific guidance on addressing these issues.""It is a stable solution...It is a scalable solution.""The customer service and support were good."

More Checkmarx Software Composition Analysis Pros →

Cons
"There's a bit of a learning curve at the outset.""The reports that describe the issues of concern are rather abstract and the issues should be more clearly described to the user.""The ease of configuration and customization could be improved in CAST Highlight.""Its price should be better. It is a pretty costly tool. They have two products: CAST Highlight and CAST AIP. I would expect CAST Highlight to have the Help dashboard and the Engineering dashboard. These dashboards are currently a part of CAST AIP, and if these are made available in CAST Highlight, customers won't have to use two different products all the time.""CAST Highlight could improve to allow us to comment and do a deep analysis by ourselves."

More CAST Highlight Cons →

"Parts of the implementation process could improve by making it more user-friendly.""Checkmarx Software Composition Analysis should improve dynamic analysis.""In terms of areas for improvement, what could be improved in Checkmarx Software Composition Analysis is pricing because customers always compare the pricing among secure DevOps solutions in the market. Checkmarx Software Composition Analysis has a lot of competitors yet its features aren't much different. Pricing is the first thing customers consider, and from a partner perspective, if you can offer affordable pricing to your customers, it's more likely you'll have a winning deal. The performance of Checkmarx Software Composition Analysis also needs improvement because sometimes, it's slow, and in particular, scanning could take several hours.""Its pricing can be improved. It is a little bit high priced. It would be better if it was a little less expensive. It is a good tool, and we're still figuring out how to fully leverage it. There are some questions regarding whether it can scan the MuleSoft code. We don't know if this is a gap in the tool or something else. This is one thing that we're just working through right now, and I am not ready to conclude that there is a weakness there. MuleSoft is kind of its own beast, and we're trying to see how we get it to work with Checkmarx.""API security is an area with shortcomings that needs improvement.""Instant updates for end users to identify vulnerabilities as soon as possible will make Checkmarx Software Composition Analysis better. The UI of the solution could also be improved.""I have received complaints from my customers that the pricing could be improved.""It can have better licensing models."

More Checkmarx Software Composition Analysis Cons →

Pricing and Cost Advice
  • "CAST Highlight is an expensive solution. However, CAST Highlight is less expensive than the CAST AIP, but it remains too expensive and the professional services from CAST are also too expensive. The high price is part of the problem with the CAST solutions."
  • "It is a pretty costly tool. A lot of customers are resistant to using it."
  • "Basic support is included with the standard licensing feed but it can be upgraded for an additional cost."
  • "CAST Highlight is an expensive solution."
  • More CAST Highlight Pricing and Cost Advice →

  • "It is a little bit high priced. It would be better if it was a little less expensive."
  • "Pricing for Checkmarx Software Composition Analysis needs to be competitive."
  • "The license model is somewhat perplexing as it comprises multiple aspects that can be confusing for customers. The model is determined by the number of registered users and the number of projects being scanned, along with a third component that adds to the complexity."
  • "My customers need to pay for the licensing part, and they need to opt for an annual subscription."
  • "We don't have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage."
  • More Checkmarx Software Composition Analysis Pricing and Cost Advice →

    report
    Use our free recommendation engine to learn which Software Composition Analysis (SCA) solutions are best for your needs.
    770,924 professionals have used our research since 2012.
    Questions from the Community
    Top Answer:The most valuable features of CAST Highlight are automation and speed.
    Top Answer:CAST Highlight is an expensive solution. On a scale from one to ten, where one is cheap, and ten is expensive, I rate the solution's pricing an eight or nine out of ten.
    Top Answer:The ease of configuration and customization could be improved in CAST Highlight.
    Top Answer:The tool's visual scan analysis shows me all the libraries' vulnerabilities and license types. It helps identify the most complex issues with licenses. It provides good visibility. SCA shows me all… more »
    Top Answer:We have a license. The usage is limited to one, two, three, five, or ten people. It is currently used for all projects, and there are plans to increase its usage.
    Top Answer:Checkmarx Software Composition Analysis should improve dynamic analysis.
    Ranking
    Views
    444
    Comparisons
    322
    Reviews
    5
    Average Words per Review
    567
    Rating
    7.8
    Views
    1,653
    Comparisons
    1,240
    Reviews
    9
    Average Words per Review
    460
    Rating
    9.1
    Comparisons
    Also Known As
    CxSCA
    Learn More
    Overview

    CAST Highlight is a SaaS software intelligence product for performing rapid application portfolio analysis. It automatically analyzes source code of hundreds of applications in a week for Cloud Readiness, Software Composition Analysis (Open Source risks), Resiliency, and Technical Debt. Objective software insights from automated source code analysis combined with built-in qualitative surveys for business context enable more informed decision-making about application portfolios.

    CAST is the software intelligence category leader. CAST technology can see inside custom applications with MRI-like precision, automatically generating intelligence about their inner workings - composition, architecture, transaction flows, cloud readiness, structural flaws, legal and security risks. It’s becoming essential for faster modernization for cloud, raising the speed and efficiency of Software Engineering, better open source risk control, and accurate technical due diligence. CAST operates globally with offices in North America, Europe, India, China. Visit www.castsoftware.com.

    Checkmarx Software Composition Analysis (SCA) helps organizations manage the risks associated with open source and third-party components in their software applications. While leveraging open source libraries and third-party dependencies is common practice, it can also introduce security vulnerabilities and license risks.


    Checkmarx SCA offers a multifaceted approach to managing these risks by:


    • Automatically scanning project repositories, build configurations, and manifests to create a comprehensive inventory of all components, including version information and associated licenses.

    • Performing vulnerability assessments on each component, including identifying and prioritizing actual exploitable or reachable vulnerabilities.

    • Protecting organizations from software supply chain attacks involving malicious packages, such as the XZ Utils backdoor.

    • Identifying licenses associated and providing insights into license obligations, restrictions, and potential conflicts.

    • Integrating seamlessly into existing development workflows and CI/CD pipelines.

    • Providing actionable remediation guidance to help organizations address identified vulnerabilities and compliance issues effectively.

    Sample Customers
    Wells Fargo, Bank of NY Mellon, Northern Trust, Microsoft, Amazon, IBM, BMW, AT&T, US Army, US Air Force, US Navy, John Hancock, Marsh & McLennan, Ernst & Young, PwC, Volkswagen, Boston Consulting Group, London Stock Exchange, Telefonica, Saur France, Total Energies France, SNCF
    AXA, Liveperson, Aaron's, Playtech, Morningstar
    Top Industries
    VISITORS READING REVIEWS
    Financial Services Firm19%
    Computer Software Company17%
    Insurance Company10%
    Manufacturing Company9%
    REVIEWERS
    Energy/Utilities Company22%
    Manufacturing Company22%
    Outsourcing Company11%
    Financial Services Firm11%
    VISITORS READING REVIEWS
    Financial Services Firm38%
    Manufacturing Company13%
    Computer Software Company12%
    Healthcare Company4%
    Company Size
    VISITORS READING REVIEWS
    Small Business12%
    Midsize Enterprise14%
    Large Enterprise74%
    REVIEWERS
    Small Business57%
    Large Enterprise43%
    VISITORS READING REVIEWS
    Small Business13%
    Midsize Enterprise8%
    Large Enterprise79%
    Buyer's Guide
    CAST Highlight vs. Checkmarx Software Composition Analysis
    March 2024
    Find out what your peers are saying about CAST Highlight vs. Checkmarx Software Composition Analysis and other solutions. Updated: March 2024.
    770,924 professionals have used our research since 2012.

    CAST Highlight is ranked 10th in Software Composition Analysis (SCA) with 5 reviews while Checkmarx Software Composition Analysis is ranked 8th in Software Composition Analysis (SCA) with 12 reviews. CAST Highlight is rated 7.8, while Checkmarx Software Composition Analysis is rated 9.2. The top reviewer of CAST Highlight writes "Easy to set up with optimized and automated insights". On the other hand, the top reviewer of Checkmarx Software Composition Analysis writes "Comprehensive security scan, helpful support, and high availability". CAST Highlight is most compared with SonarQube, Snyk, Veracode, Checkmarx One and Black Duck, whereas Checkmarx Software Composition Analysis is most compared with Black Duck, JFrog Xray, Semgrep Supply Chain, Fortify Static Code Analyzer and Mend.io. See our CAST Highlight vs. Checkmarx Software Composition Analysis report.

    See our list of best Software Composition Analysis (SCA) vendors.

    We monitor all Software Composition Analysis (SCA) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.