No more typing reviews! Try our Samantha, our new voice AI agent.

Checkmarx One vs DataDome comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Checkmarx One
Ranking in AI Security
1st
Average Rating
7.8
Reviews Sentiment
6.6
Number of Reviews
81
Ranking in other categories
Application Security Tools (2nd), Static Application Security Testing (SAST) (2nd), Vulnerability Management (16th), Container Security (15th), Static Code Analysis (2nd), API Security (4th), Dynamic Application Security Testing (DAST) (2nd), DevSecOps (2nd), Risk-Based Vulnerability Management (10th), Application Security Posture Management (ASPM) (3rd)
DataDome
Ranking in AI Security
19th
Average Rating
8.0
Reviews Sentiment
4.4
Number of Reviews
2
Ranking in other categories
Bot Management (4th)
 

Mindshare comparison

As of May 2026, in the AI Security category, the mindshare of Checkmarx One is 2.0%, down from 14.3% compared to the previous year. The mindshare of DataDome is 0.6%. It is calculated based on PeerSpot user engagement data.
AI Security Mindshare Distribution
ProductMindshare (%)
Checkmarx One2.0%
DataDome0.6%
Other97.4%
AI Security
 

Featured Reviews

Shahzad Shahzad - PeerSpot reviewer
Senior Solution Architect | L3+ Systems & Cloud Engineer | SRE Specialist at Canada Cloud Solution
Enable secure development workflows while identifying opportunities for faster scans and improved AI guidance
Checkmarx One is a very strong platform, but there are several areas where it can improve to support modern DevSecOps workflows even better. For example, better real-time developer guidance is needed. The IDE plugin should offer richer AI-powered auto-fixes similar to SNYK Code or GitHub Copilot Security, as current guidance is good but not deeply contextual for large-scale enterprise codebases. This matters because it reduces developer friction and accelerates shift-left adoption. More transparency control over the correlation engines is another need. The correlation engine is powerful but not fully transparent. Users want to understand why vulnerabilities were correlated or de-prioritized, which helps AppSec teams trust the prioritization logic. Faster SAST scan and more language coverage is needed since SAST scan can still be slow for very large mono-repos and there is limited deep support for new language frameworks like Rust and Go, along with advanced coverage for serverless-specific frameworks. This matters because large organizations want sub-minute scans in CI/CD as cloud-native ecosystems evolve fast. A strong API security module is another area for enhancement. API security scanning could be improved with active testing, API discovery, full Swagger, OpenAPI, drift detection, and schema-based fuzzing. This is important as API attacks are one of the biggest AppSec risks in 2025. Checkmarx One is strong, but I see a few areas for improvement including faster SAST scanning for large mono-repos, deeper language framework support, more transparent correlation logic, and stronger API security that includes discovery and runtime context. The IDE plugin could offer more AI-assisted fixes, and the SBOM lifecycle tracking can evolve further. Enhancing integration with SIEM and SOAR would also make enterprise adoption smoother, and these improvements would help developers and AppSec teams move faster with more accuracy.
AM
Sr. Executive Engineer at a tech services company with 51-200 employees
Automated bot detection has protected logins and preserved accurate analytics insights
The best features in DataDome include AI-powered bot detection, which is crucial for real-time protection and high accuracy with low friction. It offers protection against multiple attack types, full visibility, and an analytics dashboard that supports scalability and performance. The AI-powered real-time bot detection feature is relied upon daily as it eliminates the need for constant manual intervention, saving us from manually digging through logs and writing custom rules to address sudden traffic spikes, login failures, and slower response times. With fewer security incidents, reduced infrastructure load, and cleaner analytics, I noticed an improved user experience and time saved across teams during high-risk times.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Checkmarx pinpoints the vulnerability in the code and also presents the flow of malicious input across the application."
"Checkmarx is a powerful scanning tool, and it’s essential to have one of these products to build a safe and stable application when it comes to inviting customers to use your online services."
"Checkmarx One has positively impacted the organization, and since replacing the previous tool, SAST and SCA scans are conducted in a couple of minutes instead of hours or days, saving time and increasing speed to market by reducing the timeline from three or four days to one day only."
"After scanning, it shows in-depth code of where actual vulnerabilities are, which helps us to analyze them."
"Checkmarx has helped us deliver more secure products. We are able to do static code analysis with the tool before shipping our code to production. When the integration is in the pipeline, this tool gives us early notifications on code fixes."
"The reports are very good because they include details on the code level, and make suggestions about how to fix the problems."
"The main thing we find valuable about Checkmarx is the ease of use, as it's easy to initiate scans and triage defects."
"We are using Checkmarx for analyzing threats."
"The biggest positive impact of using DataDome has been stability, efficiency, and trust in our traffic all at the same time."
"The most valuable feature of DataDome is the traffic analysis."
 

Cons

"We can run only one project at a time."
"The product's reporting feature could be better. The feature works well for developers, but reports generated to be shared with external parties are poor, it lacks the details one gets when viewing the results directly from the Checkmarx One platform."
"The tool is currently quite static in terms of finding security vulnerabilities. It would be great if it was more dynamic and we had even more tools at our disposal to keep us safe."
"It would be really helpful if the level of confidence was included, with respect to identified issues."
"Checkmarx could improve the speed of the scans."
"The pricing can get a bit expensive, depending on the company's size."
"They should make it more container-friendly and optimized for the CI pipeline. They should make it a little less heavy."
"Their licensing fees are rigid and this causes two main issues. One is a restriction in terms of scaling the product at an enterprise level."
"Needed improvements could focus on specific aspects that impact my workflow, enabling even more streamlined processes."
"DataDome does not catch legitimate IPs during traffic analysis, even when the traffic exceeds the threshold value."
 

Pricing and Cost Advice

"The solution is costly."
"Be cautious of the one-year subscription date. Once it expires, your price will go up."
"Checkmarx is comparatively costlier than other products, which is why some of the customers feel reluctant to go for it, though performance-wise, Checkmarx can compete with other products."
"Most of my customers opted for a perpetual license. They prefer to pay the highest amount up front for the perpetual license and then pay for additional support annually."
"Before implementing the product I would evaluate if it is really necessary to scan so many different languages and frameworks. If not, I think there must be a cheaper solution for scanning Java-only applications (which are 90% of our applications)."
"The interface used to create custom rules comes at an additional cost."
"The solution's price is high and you pay based on the number of users."
"For around 250 users or committers, the cost is approximately $500,000."
Information not available
report
Use our free recommendation engine to learn which AI Security solutions are best for your needs.
894,738 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
17%
Manufacturing Company
9%
Computer Software Company
8%
Government
5%
Computer Software Company
9%
Financial Services Firm
9%
University
9%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business32
Midsize Enterprise9
Large Enterprise46
No data available
 

Questions from the Community

What alternatives are there for Fortify WebInspect and Fortify SCA?
I would like to recommend Checkmarx. With Checkmarx, you are able to have an all in one solution for SAST and SCA as well. Veracode is only a cloud solution. Hope this helps.
What is your experience regarding pricing and costs for Checkmarx?
Checkmarx One is a premium solution, so budget accordingly. Make sure you understand how licensing scales with additional applications and users. I advise negotiating multi-year contracts or bundle...
What needs improvement with Checkmarx?
One way Checkmarx One could be improved is if it could automatically run scans every month after implementation. If it is possible to set it in the SAST portal to scan the repositories automaticall...
What needs improvement with DataDome?
The solution catches and perfectly blocks traffic from malicious IPs. DataDome does not catch legitimate IPs during traffic analysis, even when the traffic exceeds the threshold value.
What is your primary use case for DataDome?
We are DataDome in SOC for cybersecurity. We use the solution to perform traffic analysis on any website or server to see whether there is a lot or little traffic.
What advice do you have for others considering DataDome?
Using the solution depends on your purpose. DataDome is a good tool for analyzing traffic in a SOC project. It is easy for a new user to learn to use the solution for the first time. Overall, I rat...
 

Comparisons

 

Also Known As

No data available
DataDome Bot Protect with Agent Trust
 

Overview

 

Sample Customers

YIT, Salesforce, Coca-Cola, SAP, U.S. Army, Liveperson, Playtech Case Study: Liveperson Implements Innovative Secure SDLC
Rakuten, TripAdvisor, Adevinta, Classmates, BlaBlaCar, Veepee, ...
Find out what your peers are saying about Checkmarx, TrendAI, Orca Security and others in AI Security. Updated: May 2026.
894,738 professionals have used our research since 2012.