Checkmarx One vs Coverity comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Checkmarx One
Ranking in Static Application Security Testing (SAST)
3rd
Average Rating
7.6
Number of Reviews
68
Ranking in other categories
Application Security Tools (3rd), Vulnerability Management (12th), Static Code Analysis (2nd), API Security (4th), DevSecOps (2nd), Risk-Based Vulnerability Management (5th)
Coverity
Ranking in Static Application Security Testing (SAST)
4th
Average Rating
7.8
Number of Reviews
36
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2024, in the Static Application Security Testing (SAST) category, the mindshare of Checkmarx One is 11.1%, down from 14.3% compared to the previous year. The mindshare of Coverity is 8.2%, up from 6.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Static Application Security Testing (SAST)
Unique Categories:
Application Security Tools
13.0%
Vulnerability Management
0.6%
No other categories found
 

Featured Reviews

PG
Sep 10, 2022
A good compliance solution that is best suited to small scale applications, and suffers from stability issues
Our main uses of this solution are to ensure our required compliance policies are met, and that we are applying best practice This solution helps to remediate the compliance requirements we have.  The product also increases the quality of the code the developers are able to implement.  The main…
Estefania Ramirez - PeerSpot reviewer
May 18, 2022
Great app analysis, support, and pricing
We use the product only as a solution for defect code, to find more build liabilities in the code The product allows us to find vulnerabilities while testing our apps.  The app analysis is the most valuable feature as I know other solutions don't have that. It's a good tool. The interface,…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The tool's valuable features include integrating GPT and Copilot. Additionally, the UI web representation is very user-friendly, making navigation easy. GPT has made several improvements to my security code."
"The ability to track the vulnerabilities inside the code (origin and destination of weak variables or functions)."
"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"The setup is fairly easy. We didn't struggle with the process at all."
"It allows for SAST scanning of uncompiled code. Further, it natively integrates with all key repos formats (Git, TFS, SVN, Perforce, etc)."
"The solution communicates where to fix the issue for the purpose of less iterations."
"The most valuable feature of Checkmarx is the user interface, it is very easy to use. We do not need to configure anything, we only have to scan to see the results."
"The setup is very easy. There is a lot of information in the documents which makes the install not difficult at all."
"In my opinion, the most effective Coverity feature for identifying critical vulnerabilities is the extra checks, which offers deep analysis."
"The solution has improved our code quality and security very well."
"The reporting feature is up to the mark."
"Provides software security, and helps to find potential security bugs or defects."
"The app analysis is the most valuable feature as I know other solutions don't have that."
"One of the most valuable features is Contributing Events. That particular feature helps the developer understand the root cause of a defect. So you can locate the starting point of the defect and figure out exactly how it is being exploited."
"The product is easy to use."
"I encountered a bug with Coverity, and I opened a ticket. Support provided me with a workaround. So it's working at the moment, or at least it seems to be."
 

Cons

"There is nothing particular that I don't like in this solution. It can have more integrations, but the integrations that we would like are in the roadmap anyway, and they just need to deliver the roadmap. What I like about the roadmap is that it is going where it needs to go. If I were to look at the roadmap, there is nothing that is jumping out there that says to me, "Yeah. I'd like something else on the roadmap." What they're looking to deliver is what I would expect and forecast them to deliver."
"We can run only one project at a time."
"C, C++, VB and T-SQL are not supported by this product. Although, C and C++ were advertised as being supported."
"We are trying to find out if there is a way to identify the run-time null values. I am analyzing different tools to check if there is any tool that supports run-time null value identification, but I don't think any of the tools in the market currently supports this feature. It would be helpful if Checkmarx can identify and throw an exception for a null value at the run time. It would make things a lot easier if there is a way for Checkmarx to identify nullable fields or hard-coded values in the code. The accessibility for customized Checkmarx rules is currently limited and should be improved. In addition, it would be great if Checkmarx can do static code and dynamic code validation. It does a lot of security-related scanning, and it should also do static code and dynamic code validation. Currently, for security-related validation, we are using Checkmarx, and for static code and dynamic code validation, we are using some other tools. We are spending money on different tools. We can pay a little extra money and use Checkmarx for everything."
"Its user interface could be improved and made more friendly."
"I would like the product to include more debugging and developed tools. It needs to also add enhancements on the coding side."
"As the solution becomes more complex and feature rich, it takes more time to debug and resolve problems. Feature-wise, we have no complaints, but Checkmarx becomes harder to maintain as the product becomes more complex. When I talk to support, it takes them longer to fix the problem than it used to."
"Updating and debugging of queries is not very convenient."
"The product lacks sufficient customization options."
"The product could be enhanced by providing video troubleshooting guides, making issue resolution more accessible. Troubleshooting without visual guides can be time-consuming."
"The product should include more customization options. The analytics is not as deep as compared to SonarQube."
"It should be easier to specify your own validation routines and sanitation routines."
"The reporting tool integration process is sometimes slow."
"Reporting engine needs to be more robust."
"We'd like it to be faster."
"SCM integration is very poor in Coverity."
 

Pricing and Cost Advice

"​Checkmarx is not a cheap scanning tool, but none of the security tools are cheap. Checkmarx is a powerful scanning tool, and it’s essential to have one of these products."
"The average deal size was usually anywhere between $120K to $175K on an annual basis, which could be divided across 12 months."
"It is a good product but a little overpriced."
"The interface used to create custom rules comes at an additional cost."
"The number of users and coverage for languages will have an impact on the cost of the license."
"The tool's pricing is fine."
"The solution's price is high and you pay based on the number of users."
"The license has a vague language around P1 issues and the associated support. Make sure to review these in order to align them with your organizational policies."
"The solution is affordable."
"The pricing is very reasonable compared to other platforms. It is based on a three year license."
"Coverity is very expensive."
"The pricing is on the expensive side, and we are paying for a couple of items."
"I would rate the tool's pricing a one out of ten."
"Coverity’s price is on the higher side. It should be lower."
"I would rate Coverity's pricing as a nine out of ten. It's already very expensive, and it's a problem for us to get more licenses due to the price. The pricing model has some good aspects - for example, a personal license gives access to all languages without code limitations, which is better than some competitors. However, it's still a lot of money for us to spend."
"The tool was fairly priced."
report
Use our free recommendation engine to learn which Static Application Security Testing (SAST) solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
21%
Computer Software Company
15%
Manufacturing Company
10%
Government
5%
Manufacturing Company
31%
Computer Software Company
16%
Financial Services Firm
7%
Government
4%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What do you like most about Checkmarx?
Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%.
How would you decide between Coverity and Sonarqube?
We researched Coverity, but in the end, we chose SonarQube. SonarQube is a tool for reviewing code quality and security. It helps to guide our development teams during code reviews by providing rem...
What do you like most about Coverity?
The solution has improved our code quality and security very well.
 

Comparisons

 

Also Known As

No data available
Synopsys Static Analysis
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
SAP, Mega International, Thales Alenia Space
Find out what your peers are saying about Checkmarx One vs. Coverity and other solutions. Updated: July 2024.
793,295 professionals have used our research since 2012.