No more typing reviews! Try our Samantha, our new voice AI agent.

Checkmarx One vs CucumberStudio comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in Dynamic Application Security Testing (DAST)
2nd
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
81
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Vulnerability Management (12th), Container Security (14th), Static Code Analysis (2nd), API Security (4th), DevSecOps (3rd), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd), AI Security (3rd)
CucumberStudio
Ranking in Dynamic Application Security Testing (DAST)
12th
Average Rating
8.0
Reviews Sentiment
7.1
Number of Reviews
12
Ranking in other categories
Rapid Application Development Software (25th)
 

Mindshare comparison

As of August 2026, in the Dynamic Application Security Testing (DAST) category, the mindshare of Checkmarx One is 13.9%, down from 22.3% compared to the previous year. The mindshare of CucumberStudio is 1.6%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Dynamic Application Security Testing (DAST) Mindshare Distribution
ProductMindshare (%)
Checkmarx One13.9%
CucumberStudio1.6%
Other84.5%
Dynamic Application Security Testing (DAST)
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
Walter Wirch - PeerSpot reviewer
Technical Expert at Bertelsmann SE & Co.
Facilitates integration of test scenarios while needing modernization of components
CucumberStudio is primarily used for designing test scenarios and automating testing. We have implemented it in conjunction with our own routines for integration into our infrastructure CucumberStudio aligns with our strategy for data-driven testing. It supports our product owners in designing…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Security can be part of the SDLC and reduce the cost of vulnerability remediation."
"Checkmarx One has positively impacted my organization, especially in our CI/CD integration, where when we try to build any feature, they are always scanned by Checkmarx before they get released."
"The visibility the solution gives you is great; it really gives you the ability to see what the root issues in the code actually are."
"The only thing I like is that Checkmarx does not need to compile."
"Compared to the solutions we used previously, Checkmarx has reduced our workload by almost 75%."
"The best thing about Checkmarx is the amount of vulnerabilities that it can find compared to other free tools."
"Overall, I use Checkmarx One as a strategic control point to improve developer velocity while strengthening application security across the full software lifecycle."
"In summary, this is a good application that you can use to scan every code language."
"CucumberStudio has a very user-friendly interface."
"The best thing is that a person without knowledge about the program can easily understand what happened in our testing process."
"Hiptest is a great test management tool for agile teams."
"The data table that helps in converting a single script to multiple test cases is very helpful."
"The power of Hiptest is its test cases and campaign management."
"Hiptest allowed us to clean up our test campaigns and standardize the way we write test cases and structure our BDD approach."
"CucumberStudio aligns with our strategy for data-driven testing."
"The URL is very useful, and it has a very good UI for deploying information of the scenarios created."
 

Cons

"In terms of dashboarding, the solution could provide a little more flexibility in terms of creating more dashboards. It has some of its own dashboards that come out of the box. However, if I have to implement my own dashboards that are aligned to my organization's requirements, that dashboarding feature has limited capability right now."
"Checkmarx could be improved with more integration with third-party software."
"Dynamic testing. If it had that feature I would have liked to see more consideration of framework validations that we don't have to duplicate. These flags are false positives."
"When we have many applications to check, I need to wait a long time in the queue."
"Their licensing fees are rigid and this causes two main issues. One is a restriction in terms of scaling the product at an enterprise level."
"The accessibility for customized Checkmarx rules is currently limited and should be improved."
"We have received some feedback from our customers who are receiving a large number of false positives."
"We felt like we were the extended quality organization for Checkmarx as they frequently released poor quality patches that broke the existing functionality."
"The reporting aspect can be improved."
"It needs some improvement when exporting scenarios into automation code, to make it easier to manage the repeatable action words and tests."
"I would like to see better customer support."
"More tutorials and examples."
"Support with In-App chat is great. However, it would be awesome to have real time support also for PT timezone."
"The reporting and metrics can be improved. E.g.: If we wanted to have metrics across all projects."
"CucumberStudio's API integration could be improved both in terms of reliability and design."
"A key area for improvement is to revamp outdated components such as HipTest publisher."
 

Pricing and Cost Advice

"I would rate the solution’s pricing an eight out of ten. The tool’s pricing is higher than others and it is for the license alone."
"The pricing was not very good. This is just a framework which shouldn’t cost so much."
"We're using a commercial version of Checkmarx, and we paid for the solution for one year. The price is high and could be reduced."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"The number of users and coverage for languages will have an impact on the cost of the license."
"It is the right price for quality delivery."
"It is an expensive solution."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
Information not available
report
Use our free recommendation engine to learn which Dynamic Application Security Testing (DAST) solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
16%
Manufacturing Company
9%
Computer Software Company
7%
Outsourcing Company
6%
Manufacturing Company
16%
Construction Company
16%
Comms Service Provider
12%
Financial Services Firm
11%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise4
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What is the biggest difference between Veracode and Checkmarx?
According to my experience of using both the tools in different organizations Veracode is a Cloud-native, managed AppSec platform with strong focus on ease of use, it is SaaS delivery, and provide...
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
What needs improvement with Hiptest?
CucumberStudio's API integration could be improved both in terms of reliability and design. The API requires data to be sent in a specific format, which takes time to build. Additionally, the repor...
What is your primary use case for Hiptest?
I use CucumberStudio as a test case repository. All of our test cases are stored there. It is also part of our test planning process. For every sprint, we plan the test cases in CucumberStudio and ...
What advice do you have for others considering Hiptest?
For teams following a BDD style software development approach, CucumberStudio is a great collaborative tool that covers all the basic requirements of a test management tool. I would rate CucumberSt...
 

Also Known As

No data available
Hiptest
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Cisco, Cardinal Health, Intuit, Smartbox, Accenture, Deliveroo
Find out what your peers are saying about Checkmarx One vs. CucumberStudio and other solutions. Updated: June 2026.
909,725 professionals have used our research since 2012.